?
Solved

Fortigate 200B Failover connection

Posted on 2010-11-23
6
Medium Priority
?
2,798 Views
Last Modified: 2012-05-10
Hi. we're having an issue setting up failover connection for fortigate 200B firewall.

Currently we have 2 broadband connections which are connected to fortigate and we'd like to use our primary connection but if it fails, then fortigate would automatically switch to secondary connection. Problem is that even we have set correct priorities for connection, Fortigate uses automatically wrong connection as primary (dsl line with lower capacity) if both lines are connected.
0
Comment
Question by:wractale
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 4

Expert Comment

by:iworks-uworks
ID: 34205413
What firmware version are you running? Which connection do you have in each port? How do have the fail over setup?
0
 
LVL 2

Author Comment

by:wractale
ID: 34205480
Firmware: v4.0,build0291,100824 (MR2 Patch 2)

Currently main connection (fibre broadband) is connected to port 14
and ADSL (failover) is connected to port 9

We have 2 static routes, one for primary connection and one for secondary, primary has lower priority than secondary.

Is that right way to do failover for fortigate or?
0
 
LVL 4

Accepted Solution

by:
iworks-uworks earned 2000 total points
ID: 34205758
Does your setup include the settings in both of these screen shots? What are you using on your WAN1 and WAN2 ports?
Failover1.PNG
Failover2.PNG
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 
LVL 2

Author Comment

by:wractale
ID: 34205844
Currently detect interface status for gateway isn't enabled. Should that be enabled for only primary connection?

Currently if we add both connections to forti, primary and secondary, it'll use secondary as default even if priority of its static route is larger.

Thanks.
0
 
LVL 4

Expert Comment

by:iworks-uworks
ID: 34206066
That is strange. Do you have anything using your WAN1 and WAN2? I've never tried a failover using other ports (while for most things it doesn't matter what ports you use), but are you able to change your main connection port to something lower than 9 to see if that is making a difference?

As for detecting the interface status, yes, check that box and maybe that will make the difference.
Make sure your ping server is reliable like a gateway IP.
0
 
LVL 2

Author Comment

by:wractale
ID: 34215391
Adding that detect interface status seemed to do it! Thanks!
0

Featured Post

Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month11 days, 15 hours left to enroll

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question