FortiWAN Tunnel Routing – Benchmark

Routing Rules
Source   Destination Service   Group Fail-Over
Any Address   192.168.2.0/255.255.255.0 Any   HQ-Branch2 No-Action
Any Address   192.168.1.0/255.255.255.0 Any   HQ-Branch1 No-Action

Auto Routing Settings

Policies
Label Algorithm Parameter
WAN4 Fixed Tick the check box “4”
Default Policy By Downstream Traffic Tick the check boxes “1”, “2”, “3”, “4” …
Filters
Source Destination Service Routing Policy Fail-Over
Tunnel WAN Any WAN4 No-Action
Any Address WAN Any Default Policy No-Action

The settings for the branch1

Set the field Local Host ID as Branch1

Local Host ID: Branch1

Tunnel Group
Group Name Remote Host

ID

Algorithm Tunnels

Local IP

Remote IP Weight
Branch1-HQ HQ Round-Robin 1.1.1.1 3.3.3.3 1
Routing Rules
Source   Destination Service Group Fail-Over
Any Address   WAN Any Branch1-HQ No-Action

The settings for the branch2

Set the field Local Host ID as Branch2

Local Host ID: Branch2

Tunnel Group
Group Name Remote Host

ID

Algorithm Tunnels

Local IP

Remote IP Weight
Branch2-HQ HQ Round-Robin 2.2.2.2 3.3.3.3 1
Routing Rules
Source Destination Service   Group Fail-Over
192.168.2.0/255.255.255.0 192.168.1.0/255.255.255.0 Any   Branch2-HQ No-Action

Auto Routing Settings

Policies
Label Algorithm Parameter
WAN5 Fixed Tick the check box “5”
Default Policy By Downstream Traffic Tick the check boxes “1”, “2”, “3”, “4” …
Filters
Source Destination Service Routing Policy Fail-Over
Any Address WAN Any WAN5 Tunnel:

Branch2-HQ

Any Address WAN Any Default Policy No-Action

See also

Tunnel Routing

How the Tunnel Routing Works

Tunnel Routing – Setting

How to set up routing rules for Tunnel Routing

Tunnel Routing – Benchmark

This entry was posted in Administration Guides, FortiWAN on by .

About Mike

Michael Pruett, CISSP has a wide range of cyber-security and network engineering expertise. The plethora of vendors that resell hardware but have zero engineering knowledge resulting in the wrong hardware or configuration being deployed is a major pet peeve of Michael's. This site was started in an effort to spread information while providing the option of quality consulting services at a much lower price than Fortinet Professional Services. Owns PacketLlama.Com (Fortinet Hardware Sales) and Office Of The CISO, LLC (Cybersecurity consulting firm).

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.