Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mlehr077
New Contributor

Wan Failover and IPSec

Hello,

  I have configured Wan fail over for win1 and wan 2. I have IPSec configs for both wans. Normal operation on wan1 site-to-site IPSec tunnels are working fine. When wan 1 goes down wan 2 kicks in and IPSec site-2-site tunnels

kick in and work fine. BUT when wan 1 comes back up the site-2-site tunnels do not come back up and or they show "up" in IPSec monitoring but they do not pass traffic.

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

How exactly did you configure two parallel static routes (config router static) and link-monitor (config sys link-monitor)? Did you make the static route via wan1-ipsec preferred. And the link-monitor is removing the preferred static route? When you check the routing-table (get router info routing-t all) when wan1 has come back up you could find why it doesn't fail-back. 

sw2090
Honored Contributor

If it helps: I here do this with routing priorities. I.e. I have a static route for every ipsec point to point tunnel to every subnet I need. Every Site has two redundant IPsec tunnels on two diffeent wans.

So I just set the route for the first tunnel to have a lower prio than the route for the 2nd.

FGT then primarily uses the first tunnel and if that goes down it switches to the 2nd. If the first ne comes back up again it switches back due to priority.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors