Configuring SD-WAN rules on a spoke FortiGate
On each spoke, the Fabric Overlay Orchestrator automatically creates a performance SLA that corresponds to the hub FortiGate. An SD-WAN rule must be configured on the spoke FortiGates to direct traffic to the hub FortiGate using this performance SLA.
To configure SD-WAN rules on a spoke FortiGate:
-
Go to Network > SD-WAN, select the SD-WAN Rules tab, and click Create New.
-
Enter a name (such as LAN-to-HUB).
-
In the Source section, set the Address to the local subnet of the spoke.
-
Configure the following in the Destination section:
-
Set the Address to the local subnet of the hub. If an address object does not exist yet, click Create in the slide-out pane and configure the address.
-
Set the Protocol number as needed (default = ANY).
-
-
Configure the following in the Outgoing Interfaces section:
-
Set the Interface selection strategy to Lowest cost (SLA).
-
Set the Interface preference to the SD-WAN members.
-
Set Required SLA target to the corresponding performance SLA created by the Fabric Overlay Orchestrator, which is named FABRIC_VPN_HUB#1 by default.
-
-
Click OK.
If you need to disable the Fabric Overlay Orchestrator on a spoke FortiGate by setting the Status to Disabled, you must first delete any SD-WAN rules on the spoke FortiGate created using this procedure to ensure the added configuration does not block the clean-up process. |