Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Darkstar
New Contributor

sd-wan manual mode

Hi,

not much about this in internet so i'll take a shot to ask here. Let me be clear that I didnt test this in production, only in GNS3, forti image 6.4.

I'm trying to build a failover link in lan (dont ask why), basicly a link-failover like nqa track in cisco, which is on the other side. I know that forti has that option and its pretty simple, ive tested it, it works. :) But I want to achieve this with gui - sd-wan.

The setup is simple, two vlans connecting cisco and forti via switch:

                                 <cisco1-track.ip_10.101.1.254>               <10.101.1.1_forti-SD.WAN>

192.168.1.1 <switch>                 |HA|                        <switch>                   |HA|

                                 <cisco2-track.ip_10.102.1.254>               <10.102.1.1_forti-SD.WAN>

 

What I came up with, is setting lowest cost SLA with 100% packet loss as the failover trigger. Vlan 10.101.1.x with lower priority (0) than the second 10.102.1.x (priority 2) - that way traffic isnt load balanced. SLA tracked serwer is gateway on cisco vlan 101 - 10.101.1.254, whatever happens to that link - both cisco and forti failover to the other link.

Lets say this works, but I cant figure out the option with manual mode instead of sla mode. If lets say I didnt pick the 100% packet loss, only ping over 100ms - that wont work, cisco would not know that the first link isnt properly routed and still would send traffic to it as the main gateway right?

I tried to pick the manual mode and vlan 102 as the first on list of interfaces, it gets picked up as the primary in theory (the marked check), but when I do tracert the traffic still goes through the vlan 101? It makes kinda sense as static routes say it should go there, even if I do the same cost (0) for both intefaces it still goes in vlan 101.

Im writing all this as my goal was to me simple - choose two interfaces without some SLA option, only link state  (here Im not that sure what this means, is it connection to the gateway ?). I would be happy if in manual mode it worked like in sla - "if there is a tie, pick the one with lowest priority".

0 REPLIES 0
Labels
Top Kudoed Authors