Fortigate SDWAN

 1. Configure WAN interface IP addresses, remove all other interface related configurations,  ref should shows "0".

2. There is a default SDWAN zone called "virtual-wan-link" (older version called SD-WAN interface), navigate to Network > SD-WAN Zones , Create New > SDWAN Member






















Verification:
Network > SD-WAN Zones








Verification:
Network > Interfaces






2. (optional) SDWAN load balancing mode

SD-WAN Implicit Rules


3. Set default route using SD-WAN interface.












4. Add firewall policy
























5. Verify routing:

Local-FortiGate # get router info routing-table all
...

Routing table for VRF=0
S*      0.0.0.0/0 [1/0] via 10.200.1.254, port1
                  [1/0] via 10.200.2.254, port2
C       10.0.1.0/24 is directly connected, port3


Dashboard > Network > Routing







6. Create SD-WAN rules
     Manual
     Manually assign outgoing interfaces.
Best Quality
The interface with the best measured performance is selected.
Lowest Cost (SLA)
The interface that meets SLA targets is selected. When there is a tie, the interface with the lowest assigned cost is selected.
Maximize Bandwidth (SLA)
Traffic is load balanced among interfaces that meet SLA targets.
   Also need set Interface Preference. 


7. Performance SLA

Create or pickup a pre-defined SLA, assign it SD-WAN members
Set target server and the protocol used to probe the server

For Lowest Cost and Maximize Bandwidth SD-WAN rules, SLA Target is required.









Comments

Popular posts from this blog

Firepower FMC and FTD troubleshooting

ASA IKEv1 VPN troubleshooting Steps and Tips

Firepower 2100/1100 FTD/ASA initial setup, reimage, upgrade.