SD-WAN Configuration for Internet Failover With Two Connections | WAN1 & WAN2 | FortiGate 80D

  Рет қаралды 53,400

KBTrainings

KBTrainings

Күн бұрын

Пікірлер: 96
@Dakerino-fz3rk
@Dakerino-fz3rk 3 жыл бұрын
Bro, your way of explaining and the way your videos are shot, i dont even see them in channels with 1M subscribers. people are sleeping on you. i hope you get the recognition you deserve. Keep going my brother
@KBTrainings
@KBTrainings 3 жыл бұрын
Thank you bro! I appreciate it!
@GiveThanks-54
@GiveThanks-54 3 жыл бұрын
Right! Very professional!
@charlesforcha4441
@charlesforcha4441 19 күн бұрын
Thanks for the video, well explained. Just to add, in a production environment where your fortigate is already setup for one provider and you need to add another provider, instead of deleting all firewall rules using the current WAN interface(to allow that interface to be added to a SD-WAN Zone as a member, enable and configure another port on your firewall, and edit all current firewall rules using the current WAN to now use the newly provisioned WAN interface(Called it Dummy WAN). When you are all done, go back to your firewall rules and edit the rules from the assigned Dummy WAN to your configured SD-WAN interface. It saves you the headache of recreating rules all over.
@siyabongamntambo1092
@siyabongamntambo1092 2 ай бұрын
Thanks man, that was straightforward
@MarlonTrujillo-lh5xt
@MarlonTrujillo-lh5xt 6 ай бұрын
Thank you for this! I have to configure SD-WAN at a few of our locations and after watching this I am pretty confident about getting it done!
@insightsmundoafora
@insightsmundoafora Жыл бұрын
Hi mate, how I didn't know your channel before. I missed I lot of very good contents. Thanks for sharing and now I'm subscribed.
@KBTrainings
@KBTrainings Жыл бұрын
Thanks for the sub! I appreciate it and welcome to the fam!
@NetworkBruh
@NetworkBruh 3 жыл бұрын
Man this is an awesome video Guy!!! Backup connection for your home internet connection. And you video quality is top notch man. I need to step my game up lol
@KBTrainings
@KBTrainings 3 жыл бұрын
Thank you brother! 😀
@868_4_Life
@868_4_Life 2 жыл бұрын
Been in IT for a while. Currently going for my NSE4 certification but I needed to figure out how to do this NOW. Your presentation is crisp, on point and well researched. Thumbs up and SUBSCRIBED. Keep going Brother. Take it to the next!!!!
@KBTrainings
@KBTrainings 2 жыл бұрын
Glad to read this! 🙏 Thank you and All the best to you too!
@VucciManeLaFlare
@VucciManeLaFlare 3 жыл бұрын
Keep working bro. It feels good to see a another black man that is knowledgeable and skilled in the craft of computer networking. Looking forward to future content 💪🏾💪🏾🔥🔥
@KBTrainings
@KBTrainings 3 жыл бұрын
Glad to read this bro! I appreciate it. More to come!
@tafsirdiallo
@tafsirdiallo 2 жыл бұрын
Very clear explanation, in french too! Merci monsieur. Subscribed!
@KBTrainings
@KBTrainings 2 жыл бұрын
Thank you sir!
@chrissampson2017
@chrissampson2017 Жыл бұрын
Love your content! Very helpful explanations
@abealasto9043
@abealasto9043 2 жыл бұрын
You are just awesome bro!
@KBTrainings
@KBTrainings 2 жыл бұрын
Thank you so much 😀
@gumby7212
@gumby7212 2 жыл бұрын
I would like to say how fantastic this video is and how clear your explanations are. I did this and pulled WAN1 with no real downtime. The question I do have is that when WAN1 comes back online, I'm not switching back automatically. What have I missed?
@KBTrainings
@KBTrainings 2 жыл бұрын
Glad to know you like the contents. I think that might have to do with priority or preference. Make sure that WAN has a higher priority and lower cost compared to WAN2 per the SD WAN rules. docs.fortinet.com/document/fortigate/6.4.1/administration-guide/342836/sd-wan-rules-lowest-cost-sla
@spankybighead7135
@spankybighead7135 Жыл бұрын
With the Fortinet you have to select a primary and secondary if going "manual". Not manual in the sense of you manually switching it at the CLI but there is a "Manual"- Manually assign outgoing interfaces option for SD-WAN rules. Make sure you have WAN 1 and WAN 2 added to the Interface preference. Whichever one you prefer is the one that will be selected first. Then select the back second. When you save you will see the priority with a check. If you primary service fails but is restored it will fail back to the primary.
@idowunmadabuchukwu9500
@idowunmadabuchukwu9500 3 жыл бұрын
Your video is amazing and awesome. Keep up the great job.
@discgolfamateur2175
@discgolfamateur2175 Жыл бұрын
Useful, nice and clear.
@2cool4-FS
@2cool4-FS 3 жыл бұрын
Top video, simple and easy explanation .. Great job bru.
@DonaldsonClan
@DonaldsonClan 2 жыл бұрын
Excellent tutorial.
@Janik2370
@Janik2370 3 жыл бұрын
Good work broda 👍🏼
@KBTrainings
@KBTrainings 3 жыл бұрын
Thank you for the support 🙏
@hariprasad-uw2yn
@hariprasad-uw2yn 3 жыл бұрын
Brother Hope you will get 100K soon.
@KBTrainings
@KBTrainings 3 жыл бұрын
Thanks bro 🙏🙂
@starplatinum47
@starplatinum47 Жыл бұрын
amazing work!
@concept_la
@concept_la 2 жыл бұрын
Excellent information, thank you.
@jorgevilla7751
@jorgevilla7751 Жыл бұрын
Great video!Thanks
@audreympp9305
@audreympp9305 3 жыл бұрын
Well explained, and very helpful video
@KBTrainings
@KBTrainings 3 жыл бұрын
Glad you liked it. Thank you!
@saifemran4528
@saifemran4528 3 жыл бұрын
Thank you, great video!
@KBTrainings
@KBTrainings 3 жыл бұрын
You're welcome!
@digiground7613
@digiground7613 3 жыл бұрын
Bonne vidéo Guy. helpfull
@KBTrainings
@KBTrainings 3 жыл бұрын
Good to know! Merci!
@xander_9812
@xander_9812 3 жыл бұрын
Very informative. Thanks a ton!
@Sabs761010
@Sabs761010 Жыл бұрын
@KBTrainings , hi, do you have some videos about to add VPN client to site and site to site with failover feature in Cisco?
@jackmauleon
@jackmauleon 2 жыл бұрын
May i ask How many seconds in real time does it failover when you disconnect WAN 2? 16:40 mark of your video.. 3 to 4 DHU and one RTO there right?
@KBTrainings
@KBTrainings 2 жыл бұрын
I just tried the failover again to have an answer for you. I launched 100 pings from the FortiGate and timed how long it takes. It is literally instantaneous both directions, I only notice the change in the TTL.
@jackmauleon
@jackmauleon 2 жыл бұрын
@@KBTrainings thank you so much for your reply. I really appreciate your testing. So if the ping came from the fortigate itself, its instant and split second.. what if the ping came from one computer from the LAN? Is it the same? I just want to make sure before I buy FG 60F model..
@ajibolayusuf2057
@ajibolayusuf2057 2 жыл бұрын
Great video again! Love your videos bro! Do you have videos for FortiManager and FortiAnalyzer?
@KBTrainings
@KBTrainings 2 жыл бұрын
Thank you Ajibola. No videos on the FortiManager yet.
@gustavogomez89
@gustavogomez89 Жыл бұрын
Hi! great video!! What version of FortiOS are you running on your fortigate 80D, I have a Fortigate90D and I need to do exactly the same configuration on my network. Thanks in advance. Bye!
@himora3804
@himora3804 Жыл бұрын
Excellent video! 1 question for a beginner, the router's for each wan has to be in bridge mode?
@letsworktogether-qq4jv
@letsworktogether-qq4jv 8 ай бұрын
what did you use to design the diagram in the video
@MulomboPatient
@MulomboPatient 3 жыл бұрын
Hi big bro, thanks!!! 💪
@KBTrainings
@KBTrainings 3 жыл бұрын
Thank you for watching.
@shanemallard-n1i
@shanemallard-n1i Жыл бұрын
what program did yo use for your documentation drawing?
@RonEnderland
@RonEnderland 10 ай бұрын
Dumb question. When sessions switch from one WAN to another, do their externally visible IP addresses change?
@KBTrainings
@KBTrainings 10 ай бұрын
Yes, their external IP will change. To avoid this, you can set an IP-Pool and route via dynamic peer.
@JaZzDeOliveira
@JaZzDeOliveira 3 ай бұрын
If I have Fixed IP addresses on both my WAN ports and we have a failure take place , will my inbound servers to my DMZ still work to each of the WAN ports?
@gonfreeccss
@gonfreeccss 2 жыл бұрын
is the WAN load balancing limited up to 2 ISP?
@Nsadheo
@Nsadheo 2 жыл бұрын
Why would the traffic drop when unplugged WAN2 when SD-WAN rule "PreferCenturyLink" only has WAN(WAN) as a member?
@idrisapatira172
@idrisapatira172 3 жыл бұрын
Nice video, very clear and precise but pls one question, how do I have the secondary link mapped to my Public DNS? and how will devices natted to my primary also be linked to my secondary link. I hope this is clear.
@KBTrainings
@KBTrainings 3 жыл бұрын
Hi Idris, If you update your DNS manually, you can link it to the secondary link without any problem. But if you use an agent on the device for DDNS, make sure the configurations point to the secondary link. About NAT, I don't think there is a way to change the NAT translation tables... Not sure if I get the question... 😀
@walterloco
@walterloco 2 жыл бұрын
If there is a loss in WAN 1 and your on a video call or audio call over internet would you loose the call while the switch over occurs even if its 3-4 milliseconds? Basically I am looking for a good solution to not lose voice if there is a cut on either WAN.
@KBTrainings
@KBTrainings 2 жыл бұрын
You may loose a few packets but that is fine still. Voice is real-time, so the people on the phone can repeat.
@walterloco
@walterloco 2 жыл бұрын
@@KBTrainings so your thought is that there will not be loss of voice at all if there is a hard cut on WAN 1 when it fails over to WAN 2?
@zarifaminnnen
@zarifaminnnen 2 жыл бұрын
static route configuration for what?
@KBTrainings
@KBTrainings 2 жыл бұрын
Because it works. You can also try without it.
@zarifaminnnen
@zarifaminnnen 2 жыл бұрын
@@KBTrainings tq
@davidcameron927
@davidcameron927 3 жыл бұрын
Thanks for the video, it was very informative. One question for you though. How does traffic flow to the internet when there is no Gateway set for either WAN? Thanks for your help in understanding!
@KBTrainings
@KBTrainings 3 жыл бұрын
I'll need to double-check for WAN2... But because WAN1 is a PPPoE (Point to Point), the egress interface is all we need because there is only one device on the other end.
@johnnyfernandez994
@johnnyfernandez994 2 жыл бұрын
Hello! Question, do we need license for using SD WAN on Fortigate?
@KBTrainings
@KBTrainings 2 жыл бұрын
Hello, No license needed for SD WAN
@chinhpham7392
@chinhpham7392 3 жыл бұрын
Videos are very helpful. Let me ask more. Fortinet 60D and 50E, about how many internet access devices can these 2 types bear?
@josephjefferson6368
@josephjefferson6368 10 ай бұрын
Are these configurations done in conjunction through a conventional ISP or are you paying through a cloud provider? Can SD WAN only be done through the cloud?
@amitsangwan7896
@amitsangwan7896 2 жыл бұрын
i have two ISP and i configured SD-WAN on my fortigate 50E. i have SAP server at my Corporate office. now what i want is my SAP works on ISP 1 and rest internet activity will use ISP2.
@gastonhitw720
@gastonhitw720 Жыл бұрын
hi do i need to have a licensed fortigate in order to do this? let's say i can buy in facebook marketplace a fortigate device, a d model for example, and it's registered to a company or a person, i know you could contact fortigate to ask them to register your device to your name if the previous owner helps you, but even like that the device will be unlicensed and hardware limited, will sd-wan work anyways?
@poladrianbinas2156
@poladrianbinas2156 3 жыл бұрын
Sir my 2 isp have different gateway how should i address, this since i try leaving it like in your video but it displays "empty values is not allowed" error.
@FabricioCarvalho
@FabricioCarvalho Жыл бұрын
just a hint: If you have to use IP pool, you should consider to specify the associated nic to the ip: config firewall ippool edit "snat1-ippool-name" set associated-interface wan1 end then associate with your policy
@aaronvelasco8792
@aaronvelasco8792 Жыл бұрын
can you please help me to this configuration to my 100d... willing to pay
@eddyshieh
@eddyshieh 3 жыл бұрын
Like your video
@KBTrainings
@KBTrainings 3 жыл бұрын
Thanks Ed!
@estebangomez1823
@estebangomez1823 3 жыл бұрын
What if you instead of disconnected WAN2, disconnected WAN1, would have moved all the traffic to WAN2? and if so, how ?
@danysaifuddin
@danysaifuddin Жыл бұрын
How to configure it on bridge?
@KBTrainings
@KBTrainings Жыл бұрын
FortiGate documentation can help: docs.fortinet.com/product/fortigate/7.4
@saudarellano5659
@saudarellano5659 3 жыл бұрын
Is it possible to use SDwan to VPN?
@KBTrainings
@KBTrainings 3 жыл бұрын
Yes, Check this out: community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-FortiGate-SD-WAN-with-an-IPSEC-VPN/ta-p/190756?externalID=FD41297
@joellemorris5684
@joellemorris5684 3 жыл бұрын
Thanks for the video! Can you say that your WAN1 and WAN2 are bonded together (in opposition load balancing) or could we set up WAN1 and WAN2 to be bond together with the Fortinet 80D?
@spankybighead7135
@spankybighead7135 Жыл бұрын
I asked the same when selecting the FortiGate. I think the answer is still no. Its load balancing tcp or udp session for session.
@cliffordiwobi3728
@cliffordiwobi3728 3 жыл бұрын
Very good video. Great and simple explanation of how the Fortigate SD-WAN works, though what's not clear to me is the reason why you have created one performance sla rule per connection instead of creating a single performance sla rule checking on both ISP. Is there a specific reason for that?
@2cool4-FS
@2cool4-FS 3 жыл бұрын
I presume he did that because he is using different thresh holds to monitor the 2 WAN connections.
@lowellguzman7249
@lowellguzman7249 2 жыл бұрын
So you're paying for two separate Internet services?
@KBTrainings
@KBTrainings 2 жыл бұрын
Yes, that is correct sir.
@lowellguzman7249
@lowellguzman7249 2 жыл бұрын
@@KBTrainings Thanks for replying. Got another question...could you tell me how to move the configuration from a 60D to a 60F? Is there much to it? Do you have a video on how to do that? This is for an upgrade of the devices at an office from a 60D to a 60F.
@joaquimtchipa4428
@joaquimtchipa4428 Жыл бұрын
Guy Congratulations for the Video, it was super. Look Guy, I have a concern. I have two internet links, Link 1 and Link 2. But I would like to make sure that, if one of the links goes down, the other link should takes over AUTOMATICALLY (source ip). I don't mean balancing or failover. I am referring to the physical link of one of the providers, in case one is off ou goes down, the other must take over automatically. Could you please help on that particular issue please? Thanks
@tlxreed
@tlxreed Жыл бұрын
This is interesting. I've been watching failover Internet videos for awhile. In a small business sense, once you failover to the 2nd WAN connection, your Internet facing IP is different, perhaps a dynamic IP. Any inbound connections or DNS routing now fails unless the traffic is virtualized in some way, perhaps DDNS or Zerotier. I haven't got that one figured out yet. The failover scenario seems relatively straightforward, it's the switchover to a new network range the the routing of cloud services that is the tough nut to crack.
@spankybighead7135
@spankybighead7135 Жыл бұрын
At first guess...BGP is the right way to go but most small business cannot qualify for a full /24 range nor do they want to use BGP. But assigned ARIN segment advertised via BGP would do the trick. For my situation without BGP I just give them both PAT's but letting them know the connection would break if one of my ISP's goes down temporarily.
Арыстанның айқасы, Тәуіржанның шайқасы!
25:51
QosLike / ҚосЛайк / Косылайық
Рет қаралды 700 М.
UFC 310 : Рахмонов VS Мачадо Гэрри
05:00
Setanta Sports UFC
Рет қаралды 1,2 МЛН
We Attempted The Impossible 😱
00:54
Topper Guild
Рет қаралды 56 МЛН
OpenLoop Network: Step-by-Step Guide to Get Started!
9:22
Zarx Crypto
Рет қаралды 46 М.
My FortiGate SDWAN Configuration and Some Use Cases
16:25
Fortinet Guru
Рет қаралды 53 М.
Fortinet Secure SD-WAN 7.2 Demo | SD-WAN
19:17
Fortinet
Рет қаралды 67 М.
DO NOT design your network like this!! // FREE CCNA // EP 6
19:36
NetworkChuck
Рет қаралды 3,4 МЛН
How to configure SD-WAN in FortiGate Firewall
15:48
IgoroTech Official
Рет қаралды 37 М.
THE UNTOLD STORY: How the PIX Firewall and NAT Saved the Internet
21:50
The Serial Port
Рет қаралды 428 М.