Page actions
The following actions are available on the Configuration tab:
-
Add—Select to create new SD-WAN Templates, Interface Members, Performance SLA, and SD-WAN Rules.
-
Edit—Select to edit an SD-WAN template, interface member, performance SLA, and SD-WAN rule.
-
Delete—Select to delete an SD-WAN template, interface member, performance SLA, and SD-WAN rule.
-
Assign to Device—Assign an SD-WAN template to a device.
-
Move—Move an SD-WAN rule.
-
Search—Enter text to search in the content pane.
-
Sort—Some columns in the content pane have a sorting feature, allowing you to sort data in ascending or descending order.
A dropdown list at the bottom allows for selecting the number of entries to display per page.
SD-WAN Templates
Select SD-WAN Templates from the dropdown in the SD-WAN > Configuration tab to define an SD-WAN for an ADOM.
To add an SD-WAN Template:
- Select Configuration in SD-WAN.
- Ensure that a device under Central Management is selected.
- Select SD-WAN Templates in the dropdown.
- Select Add.
- Enter values in the relevant fields.
Settings
Guidelines
Name
Enter a name for the new template.
Description
Enter a description for the new template.
Status
Select enable to enable the SD-WAN status.
Interface Members
Define which physical FortiPortal interfaces belong to the SD-WAN. See Interfaces belonging to the SD-WAN template.
Performance SLA
Define a new performance service level agreement (SLA). See Define a performance SLA.
SD-WAN Rule
Define SD-WAN rules to control how sessions are distributed to physical interfaces in the SD-WAN. See Define SD-WAN rules.
- Click Submit.
Interfaces belonging to the SD-WAN template
SD-WAN interfaces are the ports and interfaces that are used to run traffic. At least one interface must be configured for the SD-WAN to function; up to 255 member interfaces can be configured.
In the Interface Members pane in SD-WAN > Configuration > SD-WAN Template, the following actions are available:
-
Add—define a new interface member or SD-WAN zone
-
Edit—edit an interface member or SD-WAN zone
-
Delete—delete an interface member or SD-WAN zone
To define which physical interfaces belong to the SD-WAN template:
- After step 4 in To add an SD-WAN Template:, in the Interface Members pane, select SD-WAN Member from the Add dropdown.
- In the Create New SD-WAN Interface Members dialog, enter values in the relevant fields.
Settings
Guidelines
Sequence Number
Member sequence number. The range is 0-4294967295.
Interface Member
Enter a name for the interface member.
SD-WAN Zone
From the dropdown, select an SD-WAN zone.
Gateway IP
Enter the IPv4 address of the default gateway for this interface.
Cost
More traffic is directed to interfaces with higher costs. The cost field must be 0 or more.
Status
Toggle On or Off to enable or disable the SD-WAN status.
Priority
Assign interfaces a priority based on the priority assigned to the interface.
- Click Submit.
To create a new SD-WAN zone:
- After step 4 in To add an SD-WAN Template:, in the Interface Members pane, select SD-WAN Zone from the Add dropdown.
- In the Create New SD-WAN Zone dialog:
- Enter a name for the SD-WAN zone.
- Add interface members to it from the Interface Members dropdown.
- Click Submit.
Define a performance SLA
Use the Performance SLA pane in SD-WAN > Configuration > SD-WAN Template to configure SLA management.
In the Performance SLA pane, the following actions are available:
-
Add—define a new performance SLA
-
Edit—edit an existing performance SLA
-
Delete—delete an existing performance SLA
To add a new performance SLA:
- After step 4 in To add an SD-WAN Template:, select Add in the Performance SLA pane.
- In the Create New Performance SLA dialog, enter values in the relevant fields.
Settings
Guidelines
Name
Enter a name for the performance SLA.
IP Version
From the dropdown, select either IPv4 or IPv6.
Probe Mode
Select Active, Passive, or Prefer Passive probe mode.
Protocol
Protocol used to determine if the FortiPortal unit can communicate with the server. Select HTTP, Ping, TCP ECHO, TWAMP, or UDP ECHO.
Health Check Server
Select a health check server.
Participants
All SD-WAN Members or Specify the SD-WAN members.
Enable Probe Packets
Toggle On or Off sending probe packets.
SLA
Select Add, enter values in the relevant fields, and click Submit.
Latency Threshold
Latency for SLA to make decision in milliseconds. The default is 5; the range is 0 - 10000000.
Jitter Threshold
Jitter for SLA to make decision in milliseconds. The default is 5; the range is 0 -10000000.
Packet Loss Threshold
Packet loss for SLA to make decision in percentage. The default is 0; the range is 0 -100.
Link Status
Interval
Status check interval, which is the time between attempting to connect to the server, in seconds (1 - 3600, default = 5).
Failure Before Inactive
Number of failures before server is considered lost (1 - 10, default = 5).
Restore Link After
Number of successful responses received before the server is considered recovered (1 - 10, default = 5).
Action When Inactive
Update Static Route
Toggle On or Off updating the static route.
Update Cascade Interface
Toggle On or Off updating the cascade interface.
- Click Submit.
Define SD-WAN rules
Use the SD-WAN Rule pane in SD-WAN > Configuration > SD-WAN Template to configure SD-WAN rules or priority rules to control how sessions are distributed to physical interfaces in the SD-WAN.
In the SD-WAN Rule pane, the following actions are available:
-
Add—define an SD-WAN rule
-
Edit—edit an existing SD-WAN rule
-
Delete—delete an existing SD-WAN rule
-
Move—move an SD-WAN rule
To add a new SD-WAN rule:
- After step 4 in To add an SD-WAN Template:, select Add in the SD-WAN Rule pane.
- In the Create New SD-WAN Rules dialog, enter values in the relevant fields.
Settings
Guidelines
Name
Enter a priority rule name.
IP Version
From the dropdown, select either IPv4 or IPv6.
Source
Source Address
Select the source addresses from the list.
User(s)
Select the users from the list.
User Groups
Select the user groups from the list.
Destination
Select Address to use destination addresses or select Internet Service to use destination Internet services.
Address
Available if Destination is set to Address. Select the destination addresses from the list.
Route Tag
Available if Destination is set to Address. Available when route tags are defined for BGP route-map.
Protocol
Available if Destination is set to Address. Select TCP, UDP, ANY, or Specify. If you select Specify, enter the protocol number, type of service, and bit mask.
Type of Service Bit Mask
Type of service evaluated bits. This value determines which bits in the IP header’s TOS field are significant.
Type of Service
Type of service bit pattern.
Internet Service
Available if Destination is set to Internet Service. Select the Internet services from the list.
Internet Service Group
Available if Destination is set to Internet Service. Select the Internet service groups from the list.
Custom Internet Service
Available if Destination is set to Internet Service. Select the custom Internet services from the list.
Application
Available if Destination is set to Internet Service. Select the applications from the list.
Application Group
Available if Destination is set to Internet Service. Select the application groups from the list.
Outgoing Interfaces
Strategy
Select Manual, Best Quality, Lowest Cost (SLA), or Maximize Bandwidth (SLA).
Interface Preference
Set interface preference order when multiple eligible links have the same cost.
- Click Submit.
Per Device Interface Members
Select Interface Members from the dropdown in the SD-WAN > Configuration tab to define which physical FortiPortal interfaces belong to the SD-WAN.
To add a new interface member per device:
- Select Configuration in SD-WAN.
- Ensure that a device under Per Device is selected.
- Select Interface Members from the dropdown.
- In Add, select SD-WAN Member or SD-WAN Zone.
- Enter values in the relevant fields in To define which physical interfaces belong to the SD-WAN template:for SD-WAN Member and inTo create a new SD-WAN zone:for SD-WAN Zone.
- Click Save.
Per Device Performance SLA
To add a new performance SLA per device:
- Select Configuration in SD-WAN.
- Ensure that a device under Per Device is selected.
- Select Performance SLA from the dropdown.
- Select Add.
- Enter values in the relevant fields in To add a new performance SLA:.
- Click Save.
Per Device SD-WAN Rules
To add a new SD-WAN rule:
- Select Configuration in SD-WAN.
- Ensure that a device under Per Device is selected.
- Select SD-WAN Rules from the dropdown.
- Select Add.
- Enter values in the relevant fields in To add a new SD-WAN rule:.
- Click Save.