![Fortinet FortiWAN Скачать руководство пользователя страница 146](http://html1.mh-extra.com/html/fortinet/fortiwan/fortiwan_handbook_2322088146.webp)
Load Balancing & Fault Tolerance
Tunnel Routing
See also
How to set up routing rules for Tunnel Routing
How to set up routing rules for Tunnel Routing
To perform Tunnel Routing, symmetric FortiWAN deployment is a basic requirement. Therefore, symmetric routing
rules are also required for two-way data transmission. A routing rule here contains three basic elements that are
What is the traffic to be transferred by Tunnel Routing?
Tunnel Routing filter traffic by
Source
,
Destination
and
Service
.
Which Tunnel Group is employed to transfer the traffic?
Apply a predefined tunnel group to the specified traffic,
then it will be transferred according to the how the tunnel group is defined; the balancing algorithm, the tunnels, the
weight, the encryption and DSCP.
What to do if the Tunnel Group fails?
A failed tunnel group means all the tunnels defined in the tunnel group are
disconnected (detected by Tunnel Routing's tunnel healthy detection mechanism). Therefore, it is necessary to specify
another way for the traffic. Note that as long as one tunnel in a tunnel group remains connected, Tunnel Routing keeps
employing the tunnel group for transmission.
Next we introduce the two ways,
Routing Rule
and
Default Rule
, to establish the routing rules for Tunnel Routing.
Routing Rules
This is the general way to set routing rules for Tunnel Routing. A routing rule contains the three basic elements above,
which evaluates traffic by Source, Destination, Service, (Tunnel) Group and Fail-Over. Note that a routing rule sat on a
FortiWAN site is required symmetrically for the opposite FortiWAN site, so that the bidirectional transmission is
achieved.
Add
:
Click the Add button to add a new rule.
Source
:
The source of the connection (See "
").
IPv4 Address, IPv4 Range and IPv4 Subnet:
To filter out the traffic coming from
the specified IPv4 Address, IPv4 Range or IPv4 Subnet.
LAN:
To filter out the traffic coming from LAN area.
DMZ:
To filter out the traffic coming from DMZ area.
Any Address:
To filter out the traffic coming from any IP address
146
FortiWAN Handbook
Fortinet Technologies Inc.
Содержание FortiWAN
Страница 1: ...FortiWAN Handbook VERSION 4 2 1...