Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Fullmoon
Contributor III

service or ports redirection sdwan 6.0

hi fellas,

 

FGT 501E FOS 6.0.8.

 

I'm trying to swing my outgoing traffic to my multiple wan links.

For example my http/https traffic through wan1 and other ports/services via wan2. Before I was able to achieve this with 1 of my deployment via PBR rules using older FOS.

 

Now with FOS 6.0, Under SD WAN rules you can define only source, Internet Service or Applications and the Outgoing interface.

Upon exploring TS Policy, somehow you can craft the source, service and outgoing interface. Does my idea will work without Traffic Shaper in place in the TS Policy? 

 

Any hint is much appreciated.

 

Fortigate Newbie

Fortigate Newbie
1 REPLY 1
Yurisk
SuperUser
SuperUser

Well, my 2c on this would be:  

[ol]
  • PBR is still available, and seems most suitable for the job
  • SD-WAN rules indeed do not allow services, but if taking risk is OK there is App(Control) signatures to be used for a match and there is HTTP.BROWSER signature that would match browsers but not applications working on http/https ports.
  • Traffic Shaping Policy rules list the "Outgoing interface" as a requirements in "then" (like action) section but to me seems like a misnomer - did a test now and it did NOT forced traffic to the specified interface, but instead used the interface for matching. So if you try to force some traffic via a specific interface only, TS policy doesn't seem to do that. [/ol]
  • Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
    Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
    Labels
    Top Kudoed Authors