Fortinet white logo
Fortinet white logo

Administration Guide

SD-WAN rules

SD-WAN rules

Configure SD-WAN rules for WAN links by specifying the required network parameters. The SD-WAN rules are applied to the FortiGate device when the SD-WAN template is applied.

To create a new SD-WAN rule:
  1. If using ADOMs, ensure that you are in the correct ADOM.
  2. Go to SD-WAN Manager > Rules .

    The SD-WAN templates are displayed in the content pane.

  3. Double-click an SD-WAN template to open it for editing, or click Create New in the toolbar.

    The SD-WAN template opens.

  4. In the SD-WAN Rules toolbar, click Create New. The Create New SD-WAN Rule dialog-box opens.

  5. Enter the following information, then click OK to create the new SD-WAN rule:

    Name

    Enter the name of the rule.

    IP Version

    Select either IPv4 or IPv6.

    Source

    Source Address

    Add one or more address from the dropdown.

    User Group

    Add one or more users or user groups from the dropdown.

    Destination

    Address

    Select addresses or address groups from the dropdown list. You can click the add icon to create new entries.

    Protocol

    Select the protocol, or specify the protocol number.

    Port Range

    Enter the port range. This option is only available when the protocol is TCP or UDP.

    Type of Service

    Specify the type of service and bit mask. This option is only available when the protocol is Specify.

    Internet Service

    Select internet services, internet service groups, custom internet services, or custom internet service groups from the dropdown list. You can click the add icon to create new entries.

    Application

    Select applications, application categories, and application groups from the dropdown list. You can click the add icon to create application groups.

    Outgoing Interface

    Strategy

    Select one of the following to specify how the traffic flows through the outgoing interface:

    • Manual to specify what outgoing interface members to use.
    • Best Quality to identify outgoing interface members and have traffic flow based on quality status.
    • Lowest Cost (SLA) to identify outgoing interface members and have traffic flow based on the lowest cost.

    Interface Preference

    For the selected strategy, specify what interfaces you would like to be used. The top of the list is the highest priority, if SLA targets are met.

    Zone Preference

    Select the zone preference. This option is only available when Strategy is Lowest Cost (SLA) or Maximize Bandwidth (SLA).

    Measured SLA

    Select the SLA measurement for the selected strategy. This option is only available when Strategy is Best Quality.

    Required SLA Target

    Select the required SLA target. This option is only available when Strategy is Lowest Cost (SLA) or Maximize Bandwidth (SLA).

    Advanced Options

    Expand to display the advanced options.

    Hover the mouse over each advanced option to view a description of the option.

    Set the options as desired.

SD-WAN rules

SD-WAN rules

Configure SD-WAN rules for WAN links by specifying the required network parameters. The SD-WAN rules are applied to the FortiGate device when the SD-WAN template is applied.

To create a new SD-WAN rule:
  1. If using ADOMs, ensure that you are in the correct ADOM.
  2. Go to SD-WAN Manager > Rules .

    The SD-WAN templates are displayed in the content pane.

  3. Double-click an SD-WAN template to open it for editing, or click Create New in the toolbar.

    The SD-WAN template opens.

  4. In the SD-WAN Rules toolbar, click Create New. The Create New SD-WAN Rule dialog-box opens.

  5. Enter the following information, then click OK to create the new SD-WAN rule:

    Name

    Enter the name of the rule.

    IP Version

    Select either IPv4 or IPv6.

    Source

    Source Address

    Add one or more address from the dropdown.

    User Group

    Add one or more users or user groups from the dropdown.

    Destination

    Address

    Select addresses or address groups from the dropdown list. You can click the add icon to create new entries.

    Protocol

    Select the protocol, or specify the protocol number.

    Port Range

    Enter the port range. This option is only available when the protocol is TCP or UDP.

    Type of Service

    Specify the type of service and bit mask. This option is only available when the protocol is Specify.

    Internet Service

    Select internet services, internet service groups, custom internet services, or custom internet service groups from the dropdown list. You can click the add icon to create new entries.

    Application

    Select applications, application categories, and application groups from the dropdown list. You can click the add icon to create application groups.

    Outgoing Interface

    Strategy

    Select one of the following to specify how the traffic flows through the outgoing interface:

    • Manual to specify what outgoing interface members to use.
    • Best Quality to identify outgoing interface members and have traffic flow based on quality status.
    • Lowest Cost (SLA) to identify outgoing interface members and have traffic flow based on the lowest cost.

    Interface Preference

    For the selected strategy, specify what interfaces you would like to be used. The top of the list is the highest priority, if SLA targets are met.

    Zone Preference

    Select the zone preference. This option is only available when Strategy is Lowest Cost (SLA) or Maximize Bandwidth (SLA).

    Measured SLA

    Select the SLA measurement for the selected strategy. This option is only available when Strategy is Best Quality.

    Required SLA Target

    Select the required SLA target. This option is only available when Strategy is Lowest Cost (SLA) or Maximize Bandwidth (SLA).

    Advanced Options

    Expand to display the advanced options.

    Hover the mouse over each advanced option to view a description of the option.

    Set the options as desired.