Single ISP connections introduce a critical single point of failure for enterprise branch offices. When an ISP outage occurs, cloud application access, SaaS tools, and VoIP communications stall instantly. Implementing a proper FortiGate SD-WAN configuration solves this problem by combining multiple WAN links into a unified virtual interface. This architecture delivers automated link monitoring, dynamic path selection, and graceful failover.

In this comprehensive guide, you will configure a dual-ISP FortiGate SD-WAN deployment. You will set up performance SLA health checks, custom routing rules, and dynamic failover parameters using both FortiOS GUI and CLI methods.

Real-Life Scenario

Apex Logistics operates a regional distribution branch. The site depends heavily on cloud ERP applications and cloud-hosted VoIP services. A WAN outage immediately halts warehouse fulfillment operations.

To eliminate single-point-of-failure risks, Apex Logistics contracted two distinct internet service providers:

  • ISP-1 (Primary Fiber): Dedicated 200 Mbps symmetric fiber connection with low latency.
  • ISP-2 (Secondary Cable): Asymmetric 500/50 Mbps broadband connection with variable latency.

The business requirements specify:

  1. Business-critical cloud traffic must prefer ISP-1 as long as latency stays under 50ms and packet loss stays below 1%.
  2. If ISP-1 breaches SLA thresholds or fails completely, critical traffic must seamlessly switch to ISP-2.
  3. General web browsing must load balance across both ISP links to optimize total bandwidth utilization.

Lab Topology

The following ASCII diagram illustrates the physical and logical layout of the branch network.

                        +--------------------+
                        |  Internet Probes   |
                        | 203.0.113.1 / .2   |
                        +---------+----------+
                                  |
               +------------------+------------------+
               |                                     |
        [ Primary ISP-1 ]                     [ Secondary ISP-2 ]
         GW: 192.0.2.1                         GW: 198.51.100.1
               |                                     |
        192.0.2.2/24                          198.51.100.2/24
        +------+-------------------------------------+------+
        | port1                                       port2 |
        |                                                   |
        |              FortiGate Firewall                   |
        |              (SD-WAN Controller)                  |
        |                                                   |
        |                      port3                        |
        +------------------------+--------------------------+
                                 |
                            10.0.1.1/24
                                 |
                        +--------+---------+
                        |   Branch LAN    |
                        |  10.0.1.0/24    |
                        +-----------------+

Example Addressing and Objects

The network parameters below are used throughout this tutorial. All public IPv4 addresses use RFC 5737 test address ranges. Replace these values with your actual production ISP parameters.

Object / Interface Identifier / Value Purpose
ISP-1 Interface port1 Primary WAN interface (Fiber)
ISP-1 IP / Gateway 192.0.2.2/24 / 192.0.2.1 LAB/EXAMPLE Primary WAN addressing
ISP-2 Interface port2 Secondary WAN interface (Cable)
ISP-2 IP / Gateway 198.51.100.2/24 / 198.51.100.1 LAB/EXAMPLE Secondary WAN addressing
LAN Interface port3 Branch local network gateway (10.0.1.1/24)
SD-WAN Zone Virtual-WAN-Link (or Internet-Zone) Logical grouping object for WAN interfaces
Health Check Targets 203.0.113.1, 203.0.113.2 LAB/EXAMPLE external SLA probe servers
LAN Subnet Object LAN_Subnet (10.0.1.0/24) Firewall address object representing internal clients

Prerequisites

Before configuring SD-WAN in FortiOS, verify that your environment meets the following conditions:

  • Interface Disassociation: Egress interfaces (port1 and port2) must not be referenced in existing static routes, security policies, virtual IPs, or IPsec tunnels. FortiOS prevents adding interfaces to an SD-WAN zone if active dependencies exist.
  • System Version: FortiOS 7.0 or higher is installed. GUI menu paths and CLI structures in this article reflect FortiOS 7.x standards.
  • Administrative Access: You possess Super Admin privileges via Read-Write CLI and Web UI access.

Step-by-Step GUI FortiGate SD-WAN Configuration

Step 1: Create the SD-WAN Zone and Add Members

In modern FortiOS releases, SD-WAN members reside inside SD-WAN zones. Grouping links into zones simplifies policy creation and centralizes interface management.

  1. Navigate to Network > SD-WAN.
  2. Select the SD-WAN Zones tab and click Create New > SD-WAN Zone.
  3. Enter Internet-Zone in the Name field and click OK.
  4. Select the SD-WAN Members tab and click Create New.
  5. Set Interface to port1.
  6. Set SD-WAN Zone to Internet-Zone.
  7. Set Gateway to 192.0.2.1.
  8. Click OK.
  9. Click Create New again to add the secondary member:
    • Set Interface to port2.
    • Set SD-WAN Zone to Internet-Zone.
    • Set Gateway to 198.51.100.1.
    • Click OK.

Step 2: Configure Performance SLA (Health Check)

Performance SLAs send active probe packets to target destinations over all SD-WAN members. The FortiGate measures latency, jitter, and packet loss to determine if a link meets operational requirements.

  1. Navigate to Network > SD-WAN and select the Performance SLA tab.
  2. Click Create New.
  3. Name the SLA object SLA_Internet_Check.
  4. Set Protocol to Ping (or HTTP based on application requirements).
  5. In the Server fields, add probe IP addresses: 203.0.113.1 and 203.0.113.2.
  6. Under Participants, choose All SD-WAN Members.
  7. Enable SLA Targets and click Create New:
    • Set Latency Threshold to 50 ms.
    • Set Jitter Threshold to 10 ms.
    • Set Packet Loss Threshold to 1 %.
  8. Enable Update static route. This setting removes dead links from the routing table automatically when probes fail.
  9. Click OK.

Step 3: Create SD-WAN Steering Rules

SD-WAN Rules dictate how FortiOS evaluates outbound network sessions and selects member interfaces.

  1. Navigate to Network > SD-WAN and select the SD-WAN Rules tab.
  2. Click Create New to build the primary SLA-driven rule:
    • Rule Name: Critical_SaaS_Traffic
    • Source: Address object LAN_Subnet
    • Destination: Select specific SaaS addresses or all
    • Strategy: Select Lowest Cost (SLA) or Best Quality
    • Interface Preference: Select port1 first, then port2
    • Required SLA Target: Select SLA_Internet_Check with target #1
  3. Click OK.

Note: FortiOS processes SD-WAN rules from top to bottom. If traffic does not match a custom rule, it falls back to the default implicit strategy rule.

Step 4: Configure the Default Static Route

A static default route must point traffic to the unified SD-WAN Zone instead of individual physical interfaces.

  1. Navigate to Network > Static Routes.
  2. Click Create New.
  3. Set Destination to 0.0.0.0/0.
  4. Set Interface to Internet-Zone.
  5. Leave Gateway Address blank (gateways were already defined inside SD-WAN member properties).
  6. Click OK.

Step 5: Define Egress Firewall Policy

A single firewall policy handles traffic passing from internal networks out through the SD-WAN zone.

  1. Navigate to Policy & Objects > Firewall Policy.
  2. Click Create New.
  3. Name the policy LAN_To_SDWAN_Internet.
  4. Set Incoming Interface to port3 (LAN).
  5. Set Outgoing Interface to Internet-Zone.
  6. Set Source to LAN_Subnet.
  7. Set Destination to all.
  8. Set Service to ALL.
  9. Ensure NAT is enabled and set to Use Outgoing Interface Address.
  10. Click OK.

FortiOS CLI Configuration

For automated deployments or CLI-focused administrators, the following commands execute the exact equivalent configuration.

1. Define SD-WAN Zone and Members

config system sdwan
    set status enable
    config zone
        edit "Internet-Zone"
    next
    end
    config members
        edit 1
            set interface "port1"
            set zone "Internet-Zone"
            set gateway 192.0.2.1
        next
        edit 2
            set interface "port2"
            set zone "Internet-Zone"
            set gateway 198.51.100.1
        next
    end
end

2. Configure Performance SLA Health Check

config system sdwan
    config health-check
        edit "SLA_Internet_Check"
            set server "203.0.113.1" "203.0.113.2"
            set members 1 2
            config sla
                edit 1
                    set latency-threshold 50
                    set jitter-threshold 10
                    set packetloss-threshold 1
                next
            end
        next
    end
end

3. Create Service Rules (Traffic Steering)

config system sdwan
    config service
        edit 1
            set name "Critical_SaaS_Traffic"
            set mode priority
            set src "LAN_Subnet"
            set dst "all"
            set health-check "SLA_Internet_Check"
            set sla-compare-method latency
            set priority-members 1 2
        next
    end
end

4. Configure Static Default Route

config router static
    edit 1
        set sdwan-zone "Internet-Zone"
    next
end

5. Configure Firewall Policy and Address Objects

config firewall address
    edit "LAN_Subnet"
        set subnet 10.0.1.0 255.255.255.0
    next
end

config firewall policy
    edit 1
        set name "LAN_To_SDWAN_Internet"
        set srcintf "port3"
        set dstintf "Internet-Zone"
        set action accept
        set srcaddr "LAN_Subnet"
        set dstaddr "all"
        set schedule "always"
        set service "ALL"
        set nat enable
    next
end

How the Traffic Flows

Understanding internal packet handling ensures accurate design and efficient troubleshooting. FortiOS processes outbound internet traffic through distinct operational stages:

  1. Ingress Interface Evaluation: A frame arrives on port3 from an internal IP address (e.g., 10.0.1.50).
  2. Routing Table Route Lookup: FortiOS inspects its FIB (Forwarding Information Base) and identifies the matching static route 0.0.0.0/0 pointing to Internet-Zone.
  3. SD-WAN Service Rule Evaluation: The firewall scans SD-WAN rules sequentially starting at rule ID 1:
    • If parameters match rule criteria (source LAN_Subnet, destination all), FortiOS evaluates member health.
    • The SD-WAN engine checks the live state of SLA_Internet_Check.
    • If port1 meets the latency target (<50ms) and packet loss target (<1%), FortiOS assigns port1 as the outbound egress interface.
    • If port1 violates SLA targets or suffers a link outage, FortiOS automatically routes the session via port2.
  4. Firewall Policy Matching: FortiOS matches the session against firewall policy ID 1 (port3 to Internet-Zone).
  5. Source NAT Application: FortiOS translates the source IP from 10.0.1.50 to the public interface IP of the egress member (e.g., 192.0.2.2 for port1 or 198.51.100.2 for port2).
  6. Session Creation: FortiOS writes the connection into the state table. Existing established flows remain anchored until closed, while new sessions immediately follow updated steering decisions.

Verification

After completing your configuration, execute the following diagnostic commands from the FortiGate CLI to verify operational states.

1. Verify Member Interface Status

Check the status and status flag values of physical SD-WAN links:

diagnose sys sdwan member

Expected Output Proves: Confirms whether port1 and port2 are logically active, displays gateway health, and validates assigned zone memberships.

2. Verify Performance SLA State

Inspect active probing statistics for latency, jitter, packet loss, and SLA pass/fail status:

diagnose sys sdwan health-check

Expected Output Proves: Verifies probe response times from 203.0.113.1 and displays whether links pass or fail defined SLA criteria.

3. Verify SD-WAN Rule Steering Decisions

Confirm which WAN interface is selected for specific rules:

diagnose sys sdwan service

Expected Output Proves: Displays real-time interface rankings for rules, ensuring the primary link receives primary flow assignments.

Troubleshooting

Use a structured, repeatable troubleshooting workflow when link failovers do not execute cleanly:

  [ Check Link & Gateway ] ---> [ Inspect Health Check SLA ] ---> [ Debug Packet Flow Engine ]

Step 1: Check Egress Gateway Reachability

Determine if physical interface links can ping their respective default gateways directly:

execute ping-options source 192.0.2.2
execute ping 192.0.2.1

execute ping-options source 198.51.100.2
execute ping 198.51.100.1

Step 2: Trace Active Session Pathing

When sessions do not pick the proper WAN path, execute packet trace debugging directly within the firewall engine.

CAUTION: Interactive flow traces create CPU overhead. Always set restrictive source address filters and stop trace logs immediately after capturing traffic.

diagnose debug reset
diagnose debug flow filter saddr 10.0.1.50
diagnose debug flow show function-name enable
diagnose debug flow trace start 10
diagnose debug enable

Review the trace output to identify matching policy IDs, SD-WAN rules, and final egress selection.

Cleanup Commands (Required):

diagnose debug disable
diagnose debug reset

Symptom Matrix

Observed Symptom Likely Cause Recommended Action
Traffic uses only port1 even when port1 goes down. A legacy static route bound directly to port1 remains active in the routing table. Delete direct interface static routes in Network > Static Routes. Ensure default route points to the SD-WAN Zone.
Traffic drops instantly when port1 fails. Firewall policy lists port1 explicitly as Outgoing Interface instead of the SD-WAN Zone. Edit Policy ID 1 and set destination interface to Internet-Zone.
Performance SLA reports 100% loss across all links. Upstream firewalls or probe targets (203.0.113.1) block ICMP pings. Change SLA probe protocol from Ping to HTTP/HTTPS or update target IP addresses to public DNS servers.

Common Mistakes

  • Leaving Direct Static Routes Active: Retaining old static routes assigned to physical interfaces overrides SD-WAN decisions. Static default routes must target the SD-WAN zone exclusively.
  • Forgetting Outgoing NAT: Unchecked NAT settings on outgoing firewall policies cause packets with internal private addresses (e.g., 10.0.1.50) to reach public networks, where upstream ISPs drop them.
  • Using Unreliable SLA Target Hosts: Using single target targets for health checks risks unnecessary failover if that target host reboots. Always list at least two distinct public probe targets.
  • Overly Aggressive Probe Thresholds: Setting health check thresholds too tight (e.g., 5ms latency threshold) triggers continuous route flapping during minor network fluctuations.

Production Considerations

When deploying FortiGate SD-WAN in enterprise environments, account for these critical production practices:

  • Probing Overhead & Target Choice: Select redundant, highly available public target IP addresses (such as tier-1 DNS providers or enterprise infrastructure hosts). Ensure targets support continuous ICMP or HTTP probes without rate limiting.
  • Session Bouncing & Hold Down Timers: Configure flap-guard and hold-down timers inside SLA health checks to prevent link instability from cycling sessions back and forth repeatedly.
  • Overlay Bandwidth Configuration: Enter accurate inbound and outbound bandwidth values under SD-WAN member interface settings to allow proper percentage-based dynamic load balancing.
  • Adaptation of Values: Public IP addresses, interface names, thresholds, and routing objects shown in tutorials are for lab demonstration. Always adapt IP subnets and physical member designs to your real network landscape.

Related FortiGate Guides

Summary

A properly executed FortiGate SD-WAN configuration transforms redundant internet connections into an intelligent, high-availability network asset. By placing ISP interfaces inside a single SD-WAN zone, establishing proactive Performance SLAs, and steering application traffic based on latency and loss thresholds, you guarantee link failure resilience and optimize user access to cloud resources.