Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pg_ns
New Contributor

2 WAN but only allow certain subnet to use WAN 1, certain subnet to use WAN 2

I am having 2 WAN with 2 different Telco on 60E. I have try to use policy to only allow subnet A to use WAN 1 to access internet by Telco A and subnet B to use WAN 2 to access the internet by Telco B. But I am not able to do that due to the static route of 0.0.0.0 /0.0.0.0 is route to WAN 2. Please advise is there a way, thanks

3 REPLIES 3
sw2090
Honored Contributor

maybe setting up a 2nd defaut route for wan1 with different metric/prio might help?

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
lobstercreed
Valued Contributor

Hi pg.ns,

 

Unfortunately Sebastian's suggestion won't work the way you want...it would only help in a failure of one ISP.

 

You need to use policy routing to achieve what you're looking for.  However, it's important to note that you may black hole a subnet if that subnet's respective ISP fails without taking the link physically down.  That may be fine with you, but just keep that in mind.

 

Here are some links that may help you:

 

https://kb.fortinet.com/kb/viewContent.do?externalId=FD31240

 

https://kb.fortinet.com/kb/documentLink.do?externalID=100116

 

https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-advanced-routing-54/Routing_Advanced...

 

- Daniel Hamilton

sw2090
Honored Contributor

well maybe I was too unclear :)

 

I meant that additionally. Of course you also need a policy that allows traffic from out this subnet to internet only via corresponding wan.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors