Topic Thread

Next Generation Firewall (NGFW)

 View Only
Expand all | Collapse all

SDWAN and internet breakout

  • 1.  SDWAN and internet breakout

    Posted 08-06-2019 07:45
    I have two direct internet connections provisioned for a branch site. I have configured the SDWAN using IPSEC tunnels to link the branch back to the HQ. Currently all internet traffic is routed via HQ over the SDWAN interface.

    Is it possible to allow local internet breakout without adding additional links? And where is this configured? I can't find this scenario in the cookbook.

    Cheers


  • 2.  RE: SDWAN and internet breakout

    Posted 08-06-2019 14:52
    Hi Sean,

    Like with anything else on the FortiGate there are various ways to accomplish this.
    However, if you want the local breakout traffic to leverage the SD-WAN controller, I suggest adding the parent physical interfaces of those two IPSEC tunnels (for example WAN1 & WAN2) as SD-WAN members. Next, create Performance SLAs to reachable targets on the Internet with these two interfaces as participating members. Finally, create explicit SD-WAN rules with those two interfaces as part of the rule. Hope this helps.


  • 3.  RE: SDWAN and internet breakout

    Posted 08-07-2019 00:50
    Thanks Peter, I think that makes sense. I will give it a go.


  • 4.  RE: SDWAN and internet breakout

    Posted 27 days ago
    Did this ever work for you? I am building out Internet Breakout as well now, and have tried Peter's suggestions but still must be missing something. Also, I assume you are making this work with NAT on the policy as well?



  • 5.  RE: SDWAN and internet breakout

    Posted 27 days ago
    You may need two different sets of LAN -> SD-WAN policies (Policy & Objects -> IPv4 Policy). One for the underlay WAN links with NAT and two (VPN in and VPN out) for the overlay VPN tunnels going to an internal address range without NAT.




  • 6.  RE: SDWAN and internet breakout

    Posted 27 days ago

    Thanks Peter for the quick reply. I have separate IPV4 policy rules for SDWAN vs. local internet breakout. There is something basic missing here. I'll do some digging and update if I find anything.

     

    Chris

     

     






  • 7.  RE: SDWAN and internet breakout

    Posted 27 days ago
    What issue are you currently seeing?


  • 8.  RE: SDWAN and internet breakout

    Posted 27 days ago

    I am trying to ping a local WAN gateway via underlay from the Fortigate LAN interface through WAN interface ( to emulate local LAN traffic). Ping is not working. Basically:

     

     

    LAN-----[FG1,NAT]---------underlay-[WAN Gateway]

                   

           

    Pretty simple, SDWAN tunnels are up.

     

     






  • 9.  RE: SDWAN and internet breakout

    Posted 27 days ago
    If you policies are in place, then the next thing I'd look at would be the routing and then SD-WAN rules.
    It's possible that due to SD-WAN rules the pings are trying to go out the overlay tunnels which would probably be a no go.

    Good luck.


  • 10.  RE: SDWAN and internet breakout

    Posted 27 days ago

    That's where I'm heading. Thanks, I'll keep you posted.

     

    Chris Sieber | NFV Services

    NTT Global Networks

    m: +1.303.828.7549

    o: +1.720.475.4107

    csieber@...