Configuring SD WAN Load balancing for Multiple ISP Links
Configuring SD WAN Load balancing for Multiple ISP Links
A. Topology:
LAN1 10.10.1.0/24
LAN2 10.10.2.0/24
ISP1
LAN3 10.10.3.0/24
ISP3
WAN port4 95.95.95.108
ISP4
Below is the network setup on which we will configure FortiGate SD-WAN for the above scenarios.
LAN1 10.10.1.0/24
ISP2
LAN2 10.10.2.0/24
LAN3 10.10.3.0/24
LAN4 10.10.4.0/24
ISP3
ISP4
a) 1. Enable SD-WAN feature in FortiGate
Go to Feature Visibility option and select SD-WAN Interface. You must enable this feature to
configure SD-WAN interfaces in the firewall.
•
b) 2. Create SD-WAN Zone
• SD-WAN->Select SD-WAN-ZONE
• Create New ->SD-WAN-Member
• Add ISP-1 Values
• Interface-> ISP1 (port1)
• SD-WAN-Zone-> SD-WAN-ZONE
• Gateway-> 192.168.0.1
• Cost-> 0
• Status-> Enable
• OK
In a similar way add ISP2 in SD-WAN-Zone member
• Interface->ISP2(port2)
• SD-WAN-ZONE (Zone must be same in both member 1 and member 2)
• Gateway-> 14.140.40.109
• Cost-> 0
• Status -> Enable
• OK
• Interface->ISP3(port3)
• SD-WAN-ZONE (Zone must be same in both member 1 and member 2)
• Gateway-> 85.85.85.109
• Cost-> 0
• Status -> Enable
• OK
• Interface->ISP4(port4)
• SD-WAN-ZONE (Zone must be same in both member 1 and member 2)
• Gateway-> 95.95.95.109
• Cost-> 0
• Status -> Enable
• OK
c) 3. Configure Performance SLA
d) SLA Targets
• Latency Threshold -> maximum latency a link can manage to make decision
• Jitter Threshold ->Jitter for SLA to make the decisions
• Packet Loss Threshold->how much packet can loss when SD-WAN select SLA
Performance SLA shown in below diagram which contains values of both ISP1 and ISP2
We will not create any new rules and we will use the implicit rule
Implicit rule
SD-WAN rules define specific policy routing options to route traffic to an SD-WAN member.
When no explicit SD-WAN rules are defined, or if none of the rules are matched, then the
default implicit rule is used.
In an SD-WAN configuration, the default route usually points to the SD-WAN interface, so each
active member's gateway is added to the routing table's default route. FortiOS uses equal-cost
multipath (ECMP) to balance traffic between the interfaces. One of five load balancing
algorithms can be selected:
Now, it’s turn to configure static routes for the destination subnet. Here we have configured
static routes from all internal subnets by SD-WAN interface.
Main
Backup 1 ISP1
Backup 2
Backup 3
LAN1 10.10.1.0/24
ISP2
ISP3
ISP4
Main
Backup 1 ISP1
Backup 2
Backup 3
LAN2 10.10.2.0/24
ISP2
ISP3
ISP4
a) 1. Enable SD-WAN feature in FortiGate
Go to Feature Visibility option and select SD-WAN Interface. You must enable this feature to
configure SD-WAN interfaces in the firewall.
•
b) 2. Create SD-WAN Zone
• SD-WAN->Select SD-WAN-ZONE
• Create New ->SD-WAN-Member
• Add ISP-1 Values
• Interface-> ISP1 (port1)
• SD-WAN-Zone-> SD-WAN-ZONE
• Gateway-> 192.168.0.1
• Cost-> 0
• Status-> Enable
• OK
In a similar way add ISP2 in SD-WAN-Zone member
• Interface->ISP2(port2)
• SD-WAN-ZONE (Zone must be same in both member 1 and member 2)
• Gateway-> 14.140.40.109
• Cost-> 0
• Status -> Enable
• OK
• Interface->ISP3(port3)
• SD-WAN-ZONE (Zone must be same in both member 1 and member 2)
• Gateway-> 85.85.85.109
• Cost-> 0
• Status -> Enable
• OK
• Interface->ISP4(port4)
• SD-WAN-ZONE (Zone must be same in both member 1 and member 2)
• Gateway-> 95.95.95.109
• Cost-> 0
• Status -> Enable
• OK
c) 3. Configure Performance SLA
d) SLA Targets
• Latency Threshold -> maximum latency a link can manage to make decision
• Jitter Threshold ->Jitter for SLA to make the decisions
• Packet Loss Threshold->how much packet can loss when SD-WAN select SLA
Performance SLA shown in below diagram which contains values of both ISP1 and ISP2
Manual: We can manually send traffic to any specific interface and provide preference to that
particular WAN interface. However only one WAN interface can take part in Performance SLA
and another WAN interface (example -WAN2) act as a backup link.
ISP1 main ISP2 first backup ISP3 second backup ISP4 third backup
• Interface Preferences -> Select this order ISP1, ISP2, ISP3 and ISP4 as the order here is
very important
• Status -> Enable
• OK
Manual: We can manually send traffic to any specific interface and provide preference to that
particular WAN interface. However only one WAN interface can take part in Performance SLA
and another WAN interface (example -WAN2) act as a backup link.
ISP3 main ISP4 first backup ISP1 second backup ISP2 third backup
• Interface Preferences -> Select this order ISP3, ISP4, ISP1 and ISP2 as the order here is
very important
• Status -> Enable
• OK
f) 5. Configure Static Routes
Now, it’s turn to configure static routes for the destination subnet. Here we have configured
static routes from all internal subnets by SD-WAN interface.
Main
Main
ISP1
Backup 1
Backup 2
ISP3
ISP4
Main
Main
ISP1
Backup 1
Backup 2
ISP3
ISP4
a) 1. Enable SD-WAN feature in FortiGate
Go to Feature Visibility option and select SD-WAN Interface. You must enable this feature to
configure SD-WAN interfaces in the firewall.
•
b) 2. Create SD-WAN Zone
• SD-WAN->Select SD-WAN-ZONE
• Create New ->SD-WAN-Member
• Add ISP-1 Values
• Interface-> ISP1 (port1)
• SD-WAN-Zone-> SD-WAN-ZONE
• Gateway-> 192.168.0.1
• Cost-> 0
• Status-> Enable
• OK
In a similar way add ISP2 in SD-WAN-Zone member
• Interface->ISP2(port2)
• SD-WAN-ZONE (Zone must be same in both member 1 and member 2)
• Gateway-> 14.140.40.109
• Cost-> 0
• Status -> Enable
• OK
• Interface->ISP3(port3)
• SD-WAN-ZONE (Zone must be same in both member 1 and member 2)
• Gateway-> 85.85.85.109
• Cost-> 0
• Status -> Enable
• OK
• Interface->ISP4(port4)
• SD-WAN-ZONE (Zone must be same in both member 1 and member 2)
• Gateway-> 95.95.95.109
• Cost-> 0
• Status -> Enable
• OK
c) 3. Configure Performance SLA
d) SLA Targets
• Latency Threshold -> maximum latency a link can manage to make decision
• Jitter Threshold ->Jitter for SLA to make the decisions
• Packet Loss Threshold->how much packet can loss when SD-WAN select SLA
We will create another Performance SLA to be used in the SD-WAN rules called LoadBalance
• Name: LoadBalance
• Participants: All SD-WAN Memebers
• Server: 8.8.8.8
• Latency Threshold -> 100 MS
• Jitter Threshold ->100 MS
e) 4. Configure SD-WAN Rules
We will create four rules, two for LAN1 and two for LAN2 and also we will create Performance
SLA LoadBalance
(LAN3 → ISP1 main ISP2 main ISP3 first backup ISP4 second backup )
(LAN4→ ISP3 main ISP4 main ISP1 first backup ISP2 second backup )
3- Rule 1 LAN3 with strategy: Maximise Bandwidth (SLA) and with members
(ISP1, ISP2)
4- Rule 2 LAN3 with strategy: Manual and with members order (ISP3, ISP4)
5- Rule 3 LAN4 with strategy: Maximise Bandwidth (SLA) and with members
(ISP3, ISP4)
6- Rule 4 LAN4 with strategy: Manual and with members order (ISP1, ISP2)
Rule 1 for LAN3:
Maximise Bandwidth (SLA): Traffic distributed among the available links however, load-
balancing and transfer of traffic takes place after matching Latency parameter of link. By default,
it uses the Round-Robin method.
(LAN3 → ISP1 main ISP2 main ISP3 first backup ISP4 second backup )
(LAN4→ ISP3 main ISP4 main ISP1 first backup ISP2 second backup )
Manual: We can manually send traffic to any specific interface and provide preference to that
particular WAN interface. However only one WAN interface can take part in Performance SLA
and another WAN interface (example -WAN2) act as a backup link.
(LAN3 → ISP1 main ISP2 main ISP3 first backup ISP4 second backup )
(LAN4→ ISP3 main ISP4 main ISP1 first backup ISP2 second backup )
• Interface Preferences -> Select this order ISP3, ISP4 as the order here is very important
• Status -> Enable
• OK
Maximise Bandwidth (SLA): Traffic distributed among the available links however, load-
balancing and transfer of traffic takes place after matching Latency parameter of link. By default,
it uses the Round-Robin method.
(LAN3 → ISP1 main ISP2 main ISP3 first backup ISP4 second backup )
(LAN4→ ISP3 main ISP4 main ISP1 first backup ISP2 second backup )
Manual: We can manually send traffic to any specific interface and provide preference to that
particular WAN interface. However only one WAN interface can take part in Performance SLA
and another WAN interface (example -WAN2) act as a backup link.
(LAN3 → ISP1 main ISP2 main ISP3 first backup ISP4 second backup )
(LAN4→ ISP3 main ISP4 main ISP1 first backup ISP2 second backup )
• Interface Preferences -> Select this order ISP1, ISP2 as the order here is very important
• Status -> Enable
• OK
f) 5. Configure Static Routes
Now, it’s turn to configure static routes for the destination subnet. Here we have configured
static routes from all internal subnets by SD-WAN interface.
g) 6. Firewall Policy