WatchGuard - WAN Link Fail-Over

Edited

WAN Link Fail-Over Configuration:

To configure Link Failover you need to use Policy Manager

Select Network > Configuration

1.png

 

Configure Link Monitoring

Step 1

Select the "Link Monitor" tab first then select the external interface you wish to use for failover and click "Add"

2.png

 

Step 2

Change the "Type" to DNS and enter a public DNS server and public domain to query.

It is recommended to not use Google or CloudFlare DNS servers as they have started to not respond to ping responses from the same IP Address which is probing at a set interval.

WatchGuard has its own DNS Servers which can be used. (34.251.171.117, 34.240.115.208)

 

3.png

Repeat the above steps for the other interface which you wish to use for failover, however, use a different DNS server IP Address and query a different domain.

 

Configure SD-WAN Policy

Step 1

Select the "SD-WAN" tab and click "Add"

4.png

Step 2

Select the interfaces to be included and choose which one is to be the primary interface using the "Move Up" and "Move Down" buttons.

5.png

It is advised that the following are set to these values:

  • Loss Rate = 10%

  • Latency = 40ms

  • Jitter = 20ms

6.png

Set the fallback options to one of the following - most commonly used is "Immediate fallback"

7.png

Assign to a Firewall Policy

From the main policy, window select the policy which you wish to utilise failover in the event of a WAN failure. If multiple policies require failover this must be applied to each one.

Enable "Route outbound traffic using" and select the option "SD-WAN Based Routing" then select the "SD-WAN Action" which relates to the policy you created earlier.

8.png

 

Was this article helpful?

Sorry about that! Care to tell us more?

Thanks for the feedback!

There was an issue submitting your feedback
Please check your connection and try again.