Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mjozo8
New Contributor

FTP service problem on SD-WAN rules

Hy,

I have setup SD-WAN on my Fortigate 80E (6.2.0 version).

I have two WAN with gateway and same cost and on implicit rule I setup Spillover.

My WAN1 have 30/30Mbps, WAN2 50/4Mbps.

I want put all my FTP traffic over WAN1 and when I create SD-WAN rule (source all, destination application (all with FTP), manual outgoing interface WAN1) it wont work thought WAN1. But when i put (source all, destination all on port range 21, manual outgoing interface WAN1) it works fine.

Is there some problem with Fortigate build In service?

1 REPLY 1
Stephenzhang_FTNT

Hi Mjozo8,

 

Thank you for the message.

1, When you using application in SD-WAN service rules, you need enable application-control in firewall policy as following:

config firewall policy edit 1      set utm-status enable      set application-list "g-default" end

 

2, Then the SD-WAN service rule will check the traffic and look for the application. for the 1st occurrence of the traffic, it may use implicit rule to forward. the 2nd time, same traffic come, it will use the configured service rule. you can use the following command to check which IPs the SD-WAN has learnt for application-control.

diagnose sys virtual-wan-link internet-service-app-ctrl-list

 

Hope this answer can help you fix the problem, Stephen

 

Labels
Top Kudoed Authors