Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CITS
New Contributor

Dual WAN, Dual LAN

Hi Everyone, 

 

I have a 200E deployed and we have two separate static ISP connections coming in from the same provider, utilizing the same GW.

 

I have two LANS set up, with identical static routes

[ul]
  • 0.0.0.0/0 - GW - WAN1
  • 0.0.0.0/0 - GW - WAN2[/ul]

    And IPV4 policies

    [ul]
  • Lan1 - Wan1 - all -all -always -all -accept -NAT - Use Outgoing Interface
  • Lan2 - Wan2 - all -all -always -all -accept -NAT - Use Outgoing Interface[/ul]

     

    Issue is that  I can only get to the internet on one of LAN1-WAN1 network, the secondary LAN wont connect/ping to the internet.

  • 1 Solution
    bmorris
    New Contributor III

    I would suspect that only one of the default routes is entered into the routing table that is why lan1-wan1 works. Likely what is happening is that the firewall wants to forward traffic from lan2 out of wan1 but there is no policy to allow this so it is dropped. You will need to configure either of these two features:

     

    - SD-WAN

    - Policy routing

     

    With SD-WAN you can put both WAN interfaces into a logical 'SD-WAN' interface then create a rule that says anyone coming from lan2 only goes out via wan2.

     

    With policy routing you can create a rule that forces all lan2 traffic to go out of wan2 instead of wan1. You will need to have both default routes in the static routing table for this, but one will need a higher metric.

     

    View solution in original post

    1 REPLY 1
    bmorris
    New Contributor III

    I would suspect that only one of the default routes is entered into the routing table that is why lan1-wan1 works. Likely what is happening is that the firewall wants to forward traffic from lan2 out of wan1 but there is no policy to allow this so it is dropped. You will need to configure either of these two features:

     

    - SD-WAN

    - Policy routing

     

    With SD-WAN you can put both WAN interfaces into a logical 'SD-WAN' interface then create a rule that says anyone coming from lan2 only goes out via wan2.

     

    With policy routing you can create a rule that forces all lan2 traffic to go out of wan2 instead of wan1. You will need to have both default routes in the static routing table for this, but one will need a higher metric.

     

    Labels
    Top Kudoed Authors