Health check options
Health checks include several protocols and protocol specific options.
The health check protocol options include:
ping |
Use PING to test the link with the server. |
tcp-echo |
Use TCP echo to test the link with the server. |
udp-echo |
Use UDP echo to test the link with the server. |
http |
Use HTTP-GET to test the link with the server. |
twamp |
Use TWAMP to test the link with the server. |
dns |
Use DNS query to test the link with the server. The FortiGate sends a DNS query for an A Record and the response matches the expected IP address. |
tcp-connect |
Use a full TCP connection to test the link with the server. The method to measure the quality of the TCP connection can be:
|
ftp |
Use FTP to test the link with the server. The FTP mode can be:
|
SD-WAN health checks can generate traffic that becomes quite high as deployments grow. Please take this into consideration when setting DoS policy thresholds. For details on setting DoS policy thresholds, refer to DoS protection. |
To use UDP-echo and TCP-echo as health checks:
config system sdwan set status enable config health-check edit "h4_udp1" set protocol udp-echo set port 7 set server <server> next edit "h4_tcp1" set protocol tcp-echo set port 7 set server <server> next edit "h6_udp1" set addr-mode ipv6 set server "2032::12" set protocol udp-echo set port 7 next end end
To use DNS as a health check, and define the IP address that the response must match:
config system sdwan set status enable config health-check edit "h4_dns1" set protocol dns set dns-request-domain "ip41.forti2.com" set dns-match-ip 1.1.1.1 next edit "h6_dns1" set addr-mode ipv6 set server "2000::15.1.1.4" set protocol dns set port 53 set dns-request-domain "ip61.xxx.com" next end end
To use TCP Open (SYN/SYN-ACK) and TCP Close (FIN/FIN-ACK) to verify connections:
config system sdwan set status enable config health-check edit "h4_tcpconnect1" set protocol tcp-connect set port 443 set quality-measured-method {half-open | half-close} set server <server> next edit "h6_tcpconnect1" set addr-mode ipv6 set server "2032::13" set protocol tcp-connect set port 444 set quality-measured-method {half-open | half-close} next end end
To use active or passive mode FTP to verify connections:
config system sdwan set status enable config health-check edit "h4_ftp1" set protocol ftp set port 21 set user "root" set password *********** set ftp-mode {passive | port} set ftp-file "1.txt" set server <server> next edit "h6_ftp1" set addr-mode ipv6 set server "2032::11" set protocol ftp set port 21 set user "root" set password *********** set ftp-mode {passive | port} set ftp-file "2.txt" next end end