Fortinet black logo

Administration Guide

Additional fields for configuring WAN intelligence

Additional fields for configuring WAN intelligence

This topic describes the fields in an SD-WAN rule used for configuring WAN intelligence for egress traffic:

For information about accessing fields for configuring WAN intelligence, see Fields for configuring WAN intelligence .

Forward and/or reverse differentiated services code point (DSCP)

The FortiGate differentiated services feature can be used to change the DSCP value for all packets accepted by a policy.

The packet's DSCP field for traffic initiating a session (forward) or for reply traffic (reverse) can be changed and enabled in each direction separately by configuring it in the firewall policy using the Forward DSCP and Reverse DSCP fields.

From the CLI:

config system sdwan
    config service
        edit <ID>
            ...
            set dscp-forward enable            
            ...
        next        
    end
end

set dscp-forward enable

Enable use of forward DSCP tag.

set dscp-forward-tag 000000

Forward traffic DSCP tag.

set dscp-reverse enable

Enable use of reverse DSCP tag.

set dscp-reverse-tag 000000

Reverse traffic DSCP tag.

Default and gateway options

Following are additional gateway options that can be set only in the CLI:

config system sdwan
    config service
        edit <ID>
            ...
            set default enable
            ...
        next        
    end
end

set default [enable|disable]

Enable or disable use of SD-WAN as default service.

set gateway [enable|disable]

Enable or disable SD-WAN service gateway.

By default, these settings are set to disable.

These two commands help adjust FortiGate route selection by affecting how the FortiGate consults the Forward Information Base (FIB).

In order to decide whether an SD-WAN policy-route can be matched, FortiGate performs the following FIB lookups:

  • FIB best match for the destination must return an SD-WAN member.
  • FIB route to the destination must exist over the desired SD-WAN member.

When set default enable is used with set gateway enable, FortiGate bypasses the FIB checks, and instead routes any matching traffic of the SD-WAN rule to the chosen SD-WAN member using the member’s configured gateway. SD-WAN members must have a gateway configured.

When set default disable is used with set gateway enable, FortiGate keeps the first rule in effect but causes the second rule to change to:

  • FIB route to the gateway IP address must exist over any interface.

See also Fields for configuring WAN intelligence .

Additional fields for configuring WAN intelligence

This topic describes the fields in an SD-WAN rule used for configuring WAN intelligence for egress traffic:

For information about accessing fields for configuring WAN intelligence, see Fields for configuring WAN intelligence .

Forward and/or reverse differentiated services code point (DSCP)

The FortiGate differentiated services feature can be used to change the DSCP value for all packets accepted by a policy.

The packet's DSCP field for traffic initiating a session (forward) or for reply traffic (reverse) can be changed and enabled in each direction separately by configuring it in the firewall policy using the Forward DSCP and Reverse DSCP fields.

From the CLI:

config system sdwan
    config service
        edit <ID>
            ...
            set dscp-forward enable            
            ...
        next        
    end
end

set dscp-forward enable

Enable use of forward DSCP tag.

set dscp-forward-tag 000000

Forward traffic DSCP tag.

set dscp-reverse enable

Enable use of reverse DSCP tag.

set dscp-reverse-tag 000000

Reverse traffic DSCP tag.

Default and gateway options

Following are additional gateway options that can be set only in the CLI:

config system sdwan
    config service
        edit <ID>
            ...
            set default enable
            ...
        next        
    end
end

set default [enable|disable]

Enable or disable use of SD-WAN as default service.

set gateway [enable|disable]

Enable or disable SD-WAN service gateway.

By default, these settings are set to disable.

These two commands help adjust FortiGate route selection by affecting how the FortiGate consults the Forward Information Base (FIB).

In order to decide whether an SD-WAN policy-route can be matched, FortiGate performs the following FIB lookups:

  • FIB best match for the destination must return an SD-WAN member.
  • FIB route to the destination must exist over the desired SD-WAN member.

When set default enable is used with set gateway enable, FortiGate bypasses the FIB checks, and instead routes any matching traffic of the SD-WAN rule to the chosen SD-WAN member using the member’s configured gateway. SD-WAN members must have a gateway configured.

When set default disable is used with set gateway enable, FortiGate keeps the first rule in effect but causes the second rule to change to:

  • FIB route to the gateway IP address must exist over any interface.

See also Fields for configuring WAN intelligence .