Single ISP connections introduce a critical single point of failure for enterprise branch offices. When an ISP outage occurs, cloud application access, SaaS tools, and VoIP communications stall instantly. Implementing a proper FortiGate SD-WAN configuration solves this problem by combining multiple WAN links into a unified virtual interface. This architecture delivers automated link monitoring, dynamic path selection, and graceful failover.
In this comprehensive guide, you will configure a dual-ISP FortiGate SD-WAN deployment. You will set up performance SLA health checks, custom routing rules, and dynamic failover parameters using both FortiOS GUI and CLI methods.
Real-Life Scenario
Apex Logistics operates a regional distribution branch. The site depends heavily on cloud ERP applications and cloud-hosted VoIP services. A WAN outage immediately halts warehouse fulfillment operations.
To eliminate single-point-of-failure risks, Apex Logistics contracted two distinct internet service providers:
- ISP-1 (Primary Fiber): Dedicated 200 Mbps symmetric fiber connection with low latency.
- ISP-2 (Secondary Cable): Asymmetric 500/50 Mbps broadband connection with variable latency.
The business requirements specify:
- Business-critical cloud traffic must prefer ISP-1 as long as latency stays under 50ms and packet loss stays below 1%.
- If ISP-1 breaches SLA thresholds or fails completely, critical traffic must seamlessly switch to ISP-2.
- General web browsing must load balance across both ISP links to optimize total bandwidth utilization.
Lab Topology
The following ASCII diagram illustrates the physical and logical layout of the branch network.
+--------------------+
| Internet Probes |
| 203.0.113.1 / .2 |
+---------+----------+
|
+------------------+------------------+
| |
[ Primary ISP-1 ] [ Secondary ISP-2 ]
GW: 192.0.2.1 GW: 198.51.100.1
| |
192.0.2.2/24 198.51.100.2/24
+------+-------------------------------------+------+
| port1 port2 |
| |
| FortiGate Firewall |
| (SD-WAN Controller) |
| |
| port3 |
+------------------------+--------------------------+
|
10.0.1.1/24
|
+--------+---------+
| Branch LAN |
| 10.0.1.0/24 |
+-----------------+
Example Addressing and Objects
The network parameters below are used throughout this tutorial. All public IPv4 addresses use RFC 5737 test address ranges. Replace these values with your actual production ISP parameters.
| Object / Interface | Identifier / Value | Purpose |
|---|---|---|
| ISP-1 Interface | port1 |
Primary WAN interface (Fiber) |
| ISP-1 IP / Gateway | 192.0.2.2/24 / 192.0.2.1 |
LAB/EXAMPLE Primary WAN addressing |
| ISP-2 Interface | port2 |
Secondary WAN interface (Cable) |
| ISP-2 IP / Gateway | 198.51.100.2/24 / 198.51.100.1 |
LAB/EXAMPLE Secondary WAN addressing |
| LAN Interface | port3 |
Branch local network gateway (10.0.1.1/24) |
| SD-WAN Zone | Virtual-WAN-Link (or Internet-Zone) |
Logical grouping object for WAN interfaces |
| Health Check Targets | 203.0.113.1, 203.0.113.2 |
LAB/EXAMPLE external SLA probe servers |
| LAN Subnet Object | LAN_Subnet (10.0.1.0/24) |
Firewall address object representing internal clients |
Prerequisites
Before configuring SD-WAN in FortiOS, verify that your environment meets the following conditions:
- Interface Disassociation: Egress interfaces (
port1andport2) must not be referenced in existing static routes, security policies, virtual IPs, or IPsec tunnels. FortiOS prevents adding interfaces to an SD-WAN zone if active dependencies exist. - System Version: FortiOS 7.0 or higher is installed. GUI menu paths and CLI structures in this article reflect FortiOS 7.x standards.
- Administrative Access: You possess Super Admin privileges via Read-Write CLI and Web UI access.
Step-by-Step GUI FortiGate SD-WAN Configuration
Step 1: Create the SD-WAN Zone and Add Members
In modern FortiOS releases, SD-WAN members reside inside SD-WAN zones. Grouping links into zones simplifies policy creation and centralizes interface management.
- Navigate to Network > SD-WAN.
- Select the SD-WAN Zones tab and click Create New > SD-WAN Zone.
- Enter
Internet-Zonein the Name field and click OK. - Select the SD-WAN Members tab and click Create New.
- Set Interface to
port1. - Set SD-WAN Zone to
Internet-Zone. - Set Gateway to
192.0.2.1. - Click OK.
- Click Create New again to add the secondary member:
- Set Interface to
port2. - Set SD-WAN Zone to
Internet-Zone. - Set Gateway to
198.51.100.1. - Click OK.
- Set Interface to
Step 2: Configure Performance SLA (Health Check)
Performance SLAs send active probe packets to target destinations over all SD-WAN members. The FortiGate measures latency, jitter, and packet loss to determine if a link meets operational requirements.
- Navigate to Network > SD-WAN and select the Performance SLA tab.
- Click Create New.
- Name the SLA object
SLA_Internet_Check. - Set Protocol to
Ping(orHTTPbased on application requirements). - In the Server fields, add probe IP addresses:
203.0.113.1and203.0.113.2. - Under Participants, choose All SD-WAN Members.
- Enable SLA Targets and click Create New:
- Set Latency Threshold to
50ms. - Set Jitter Threshold to
10ms. - Set Packet Loss Threshold to
1%.
- Set Latency Threshold to
- Enable Update static route. This setting removes dead links from the routing table automatically when probes fail.
- Click OK.
Step 3: Create SD-WAN Steering Rules
SD-WAN Rules dictate how FortiOS evaluates outbound network sessions and selects member interfaces.
- Navigate to Network > SD-WAN and select the SD-WAN Rules tab.
- Click Create New to build the primary SLA-driven rule:
- Rule Name:
Critical_SaaS_Traffic - Source: Address object
LAN_Subnet - Destination: Select specific SaaS addresses or
all - Strategy: Select Lowest Cost (SLA) or Best Quality
- Interface Preference: Select
port1first, thenport2 - Required SLA Target: Select
SLA_Internet_Checkwith target#1
- Rule Name:
- Click OK.
Note: FortiOS processes SD-WAN rules from top to bottom. If traffic does not match a custom rule, it falls back to the default implicit strategy rule.
Step 4: Configure the Default Static Route
A static default route must point traffic to the unified SD-WAN Zone instead of individual physical interfaces.
- Navigate to Network > Static Routes.
- Click Create New.
- Set Destination to
0.0.0.0/0. - Set Interface to
Internet-Zone. - Leave Gateway Address blank (gateways were already defined inside SD-WAN member properties).
- Click OK.
Step 5: Define Egress Firewall Policy
A single firewall policy handles traffic passing from internal networks out through the SD-WAN zone.
- Navigate to Policy & Objects > Firewall Policy.
- Click Create New.
- Name the policy
LAN_To_SDWAN_Internet. - Set Incoming Interface to
port3(LAN). - Set Outgoing Interface to
Internet-Zone. - Set Source to
LAN_Subnet. - Set Destination to
all. - Set Service to
ALL. - Ensure NAT is enabled and set to Use Outgoing Interface Address.
- Click OK.
FortiOS CLI Configuration
For automated deployments or CLI-focused administrators, the following commands execute the exact equivalent configuration.
1. Define SD-WAN Zone and Members
config system sdwan
set status enable
config zone
edit "Internet-Zone"
next
end
config members
edit 1
set interface "port1"
set zone "Internet-Zone"
set gateway 192.0.2.1
next
edit 2
set interface "port2"
set zone "Internet-Zone"
set gateway 198.51.100.1
next
end
end
2. Configure Performance SLA Health Check
config system sdwan
config health-check
edit "SLA_Internet_Check"
set server "203.0.113.1" "203.0.113.2"
set members 1 2
config sla
edit 1
set latency-threshold 50
set jitter-threshold 10
set packetloss-threshold 1
next
end
next
end
end
3. Create Service Rules (Traffic Steering)
config system sdwan
config service
edit 1
set name "Critical_SaaS_Traffic"
set mode priority
set src "LAN_Subnet"
set dst "all"
set health-check "SLA_Internet_Check"
set sla-compare-method latency
set priority-members 1 2
next
end
end
4. Configure Static Default Route
config router static
edit 1
set sdwan-zone "Internet-Zone"
next
end
5. Configure Firewall Policy and Address Objects
config firewall address
edit "LAN_Subnet"
set subnet 10.0.1.0 255.255.255.0
next
end
config firewall policy
edit 1
set name "LAN_To_SDWAN_Internet"
set srcintf "port3"
set dstintf "Internet-Zone"
set action accept
set srcaddr "LAN_Subnet"
set dstaddr "all"
set schedule "always"
set service "ALL"
set nat enable
next
end
How the Traffic Flows
Understanding internal packet handling ensures accurate design and efficient troubleshooting. FortiOS processes outbound internet traffic through distinct operational stages:
- Ingress Interface Evaluation: A frame arrives on
port3from an internal IP address (e.g.,10.0.1.50). - Routing Table Route Lookup: FortiOS inspects its FIB (Forwarding Information Base) and identifies the matching static route
0.0.0.0/0pointing toInternet-Zone. - SD-WAN Service Rule Evaluation: The firewall scans SD-WAN rules sequentially starting at rule ID 1:
- If parameters match rule criteria (source
LAN_Subnet, destinationall), FortiOS evaluates member health. - The SD-WAN engine checks the live state of
SLA_Internet_Check. - If
port1meets the latency target (<50ms) and packet loss target (<1%), FortiOS assignsport1as the outbound egress interface. - If
port1violates SLA targets or suffers a link outage, FortiOS automatically routes the session viaport2.
- If parameters match rule criteria (source
- Firewall Policy Matching: FortiOS matches the session against firewall policy ID 1 (
port3toInternet-Zone). - Source NAT Application: FortiOS translates the source IP from
10.0.1.50to the public interface IP of the egress member (e.g.,192.0.2.2forport1or198.51.100.2forport2). - Session Creation: FortiOS writes the connection into the state table. Existing established flows remain anchored until closed, while new sessions immediately follow updated steering decisions.
Verification
After completing your configuration, execute the following diagnostic commands from the FortiGate CLI to verify operational states.
1. Verify Member Interface Status
Check the status and status flag values of physical SD-WAN links:
diagnose sys sdwan member
Expected Output Proves: Confirms whether port1 and port2 are logically active, displays gateway health, and validates assigned zone memberships.
2. Verify Performance SLA State
Inspect active probing statistics for latency, jitter, packet loss, and SLA pass/fail status:
diagnose sys sdwan health-check
Expected Output Proves: Verifies probe response times from 203.0.113.1 and displays whether links pass or fail defined SLA criteria.
3. Verify SD-WAN Rule Steering Decisions
Confirm which WAN interface is selected for specific rules:
diagnose sys sdwan service
Expected Output Proves: Displays real-time interface rankings for rules, ensuring the primary link receives primary flow assignments.
Troubleshooting
Use a structured, repeatable troubleshooting workflow when link failovers do not execute cleanly:
[ Check Link & Gateway ] ---> [ Inspect Health Check SLA ] ---> [ Debug Packet Flow Engine ]
Step 1: Check Egress Gateway Reachability
Determine if physical interface links can ping their respective default gateways directly:
execute ping-options source 192.0.2.2
execute ping 192.0.2.1
execute ping-options source 198.51.100.2
execute ping 198.51.100.1
Step 2: Trace Active Session Pathing
When sessions do not pick the proper WAN path, execute packet trace debugging directly within the firewall engine.
CAUTION: Interactive flow traces create CPU overhead. Always set restrictive source address filters and stop trace logs immediately after capturing traffic.
diagnose debug reset
diagnose debug flow filter saddr 10.0.1.50
diagnose debug flow show function-name enable
diagnose debug flow trace start 10
diagnose debug enable
Review the trace output to identify matching policy IDs, SD-WAN rules, and final egress selection.
Cleanup Commands (Required):
diagnose debug disable
diagnose debug reset
Symptom Matrix
| Observed Symptom | Likely Cause | Recommended Action |
|---|---|---|
Traffic uses only port1 even when port1 goes down. |
A legacy static route bound directly to port1 remains active in the routing table. |
Delete direct interface static routes in Network > Static Routes. Ensure default route points to the SD-WAN Zone. |
Traffic drops instantly when port1 fails. |
Firewall policy lists port1 explicitly as Outgoing Interface instead of the SD-WAN Zone. |
Edit Policy ID 1 and set destination interface to Internet-Zone. |
| Performance SLA reports 100% loss across all links. | Upstream firewalls or probe targets (203.0.113.1) block ICMP pings. |
Change SLA probe protocol from Ping to HTTP/HTTPS or update target IP addresses to public DNS servers. |
Common Mistakes
- Leaving Direct Static Routes Active: Retaining old static routes assigned to physical interfaces overrides SD-WAN decisions. Static default routes must target the SD-WAN zone exclusively.
- Forgetting Outgoing NAT: Unchecked NAT settings on outgoing firewall policies cause packets with internal private addresses (e.g.,
10.0.1.50) to reach public networks, where upstream ISPs drop them. - Using Unreliable SLA Target Hosts: Using single target targets for health checks risks unnecessary failover if that target host reboots. Always list at least two distinct public probe targets.
- Overly Aggressive Probe Thresholds: Setting health check thresholds too tight (e.g., 5ms latency threshold) triggers continuous route flapping during minor network fluctuations.
Production Considerations
When deploying FortiGate SD-WAN in enterprise environments, account for these critical production practices:
- Probing Overhead & Target Choice: Select redundant, highly available public target IP addresses (such as tier-1 DNS providers or enterprise infrastructure hosts). Ensure targets support continuous ICMP or HTTP probes without rate limiting.
- Session Bouncing & Hold Down Timers: Configure flap-guard and hold-down timers inside SLA health checks to prevent link instability from cycling sessions back and forth repeatedly.
- Overlay Bandwidth Configuration: Enter accurate inbound and outbound bandwidth values under SD-WAN member interface settings to allow proper percentage-based dynamic load balancing.
- Adaptation of Values: Public IP addresses, interface names, thresholds, and routing objects shown in tutorials are for lab demonstration. Always adapt IP subnets and physical member designs to your real network landscape.
Related FortiGate Guides
- FortiGate policy routing with dual ISP examples
- FortiGate HA configuration and failover testing
- FortiGate session troubleshooting
- FortiGate LDAP with Active Directory
Summary
A properly executed FortiGate SD-WAN configuration transforms redundant internet connections into an intelligent, high-availability network asset. By placing ISP interfaces inside a single SD-WAN zone, establishing proactive Performance SLAs, and steering application traffic based on latency and loss thresholds, you guarantee link failure resilience and optimize user access to cloud resources.