![Fortinet FortiWAN Handbook Download Page 147](http://html1.mh-extra.com/html/fortinet/fortiwan/fortiwan_handbook_2322088147.webp)
Tunnel Routing
Load Balancing & Fault Tolerance
Destination
:
The destination of the connection (See "
").
IPv4 Address, IPv4 Range and IPv4 Subnet:
To filter out the traffic going to the
specified IPv4 Address, IPv4 Range or IPv4 Subnet.
WAN:
To filter out the traffic going to WAN area.
Service
:
The TCP/UDP service type to be matched. The default is "Any". Administrators can select
from the publicly known service types (e.g. FTP), or can choose the port number in
TCP/UDP packet. To specify a range of port numbers, type starting port number plus
hyphen "-" and then end port number. e.g. "TCP@123-234" (See "
").
Group
:
The
tunnel group
used to transfer the specified traffic (filtered by Source, Destination
and Service). The balancing algorithm and tunnels for distributing the traffic are defined in
the tunnel group.
Fail-Over
:
This field defines the fail-over policy for situation that all the WAN links (tunnels) of
the specified tunnel group in the routing rule fail. Possible options are:
NO-ACTION:
Traffic will not be diverted when the tunnel group get failed, and
transmission will get failed.
Auto Routing:
Traffic will be re-evaluated against Auto Routing's rules and
transferred according to the Auto Routing policies. Transmission gets failed if there is
no rule matches.
Tunnel: [Group Name]:
All the defined tunnel groups are listed for options. Traffic
will be diverted to the specified tunnel group here, however, the diverted traffic will
not be diverted again if the beck-up tunnel group is also failed. Note: it takes the
same action as "NO-ACTION" if a tunnel group that is the same as what specified in
field "Group" is selected as back-up for fail-over here.
Default Rule
Default Rule provides a semiautomatic way to establish symmetric routing rules, while Routing Rule is a fully-manual
way. Default Rule is a simple and efficient way to configure symmetric routing rules for tunnel transmission between
FortiWANs. Although Default Rule is a simplified way to set routing rules up, it still contains the three basic elements
that we introduced above. Default Rule filters traffic by Source and Destination while ignoring the Service (Service =
Any). To set the default rules up, only the source IP addresses need to be specified on both FortiWAN units that a
tunnel group connects. Then the symmetric FortiWAN units
automatically negotiate
for the destinations; One’s
source in a default rule will become to the destination in the default rule on the opposite unit. In other words, Default
Rule is the fully-connected association established by specified sources on local and remote units.
A Default Rule is attached to a Tunnel Group. The configurations of a tunnel group contains items for its default rules,
so that traffic filtered out by the default rule would be transferred via this tunnel group, which is the second element for
a tunnel routing rule we introduced above.Every default rule contains fail-over policy for transmission when the tunnel
group fails; this is the third element for a tunnel routing rule.
Add
:
Click the Add button to add a new rule.
E
:
Check to enable the rule.
FortiWAN Handbook
Fortinet Technologies Inc.
147