A real-life situation
FGT1 has a fibre link (port1) and a cheaper broadband link (port4). With plain static routes, port4 sits idle as a backup and only takes over when port1 fails completely. Users complain that video calls stutter in the afternoon, when the fibre provider is congested but still "up". SD-WAN measures both links all the time and can move calls to whichever link is healthier.
- 1. Best quality: Calls use whichever member has the lowest latency and meets the SLA.
- 2. Other traffic: Bulk traffic can be sent to the cheaper link, or shared between both.
Step 1: members and zone
config system sdwan
set status enable
config zone
edit "virtual-wan-link"
next
end
config members
edit 1
set interface "port1"
set zone "virtual-wan-link"
set gateway 203.0.113.1
next
edit 2
set interface "port4"
set zone "virtual-wan-link"
set gateway 192.0.2.1
next
end
endRemove any policies and static routes that reference port1 or port4 first. Each member carries its own gateway, so the separate default routes aren't needed any more.
Step 2: a route and a policy using the zone
config router static
edit 1
set sdwan-zone "virtual-wan-link"
next
end
config firewall policy
edit 3
set name "LAN-to-Internet"
set srcintf "port2"
set dstintf "virtual-wan-link"
set srcaddr "LAN-subnet"
set dstaddr "all"
set action accept
set schedule "always"
set service "HTTP" "HTTPS" "DNS"
set nat enable
set logtraffic all
next
endOne default route points at the zone and expands to a route through each member. The policy's outgoing interface is the zone, so it covers both links; NAT uses whichever member's address the session leaves from.
Step 3: measure the links
config system sdwan
config health-check
edit "Internet-SLA"
set server "8.8.8.8" "1.1.1.1"
set protocol ping
set interval 500
set failtime 5
set recoverytime 5
set members 1 2
config sla
edit 1
set latency-threshold 150
set jitter-threshold 30
set packetloss-threshold 2
next
end
next
end
endEach member pings two servers every 500 ms. A member that fails 5 probes in a row is marked dead. SLA 1 is met while latency is under 150 ms, jitter under 30 ms and loss under 2%.
Step 4: steer traffic with a rule
config system sdwan
config service
edit 1
set name "Video-calls"
set mode sla
set internet-service enable
set internet-service-name "Zoom-Zoom.Meeting"
config sla
edit "Internet-SLA"
set id 1
next
end
set priority-members 1 2
next
end
endRules are checked top-down like policies. Strategy sla (Lowest Cost (SLA) in the GUI) uses the first member in priority-members that meets SLA 1: port1 normally, port4 when port1 misses the SLA. Traffic matching no rule follows the implicit rule, which load-balances by source IP by default. The Internet Service name shown is an example; pick the one for your application from the list.
| Strategy (GUI name) | Chooses |
|---|---|
| Manual | A fixed member (or members in order), regardless of quality |
| Best Quality | The member with the best measured value: lowest latency, jitter or loss |
| Lowest Cost (SLA) | The first preferred member that meets the SLA (cost or order breaks ties) |
| Maximize Bandwidth (SLA) | Shares sessions across all members that meet the SLA |
Verify
FGT1 # diagnose sys sdwan health-check Health Check(Internet-SLA): Seq(1 port1): state(alive), packet-loss(0.000%) latency(186.402), jitter(12.115), sla_map=0x0 Seq(2 port4): state(alive), packet-loss(0.000%) latency(24.871), jitter(1.902), sla_map=0x1
FGT1 # diagnose sys sdwan service Service(1): Address Mode(IPV4) flags=0x200 ... Gen(3), TOS(0x0/0x0), Protocol(0): src(1->65535):dst(1->65535), Mode(sla), sla-compare-order Members(2): 1: Seq_num(2 port4), alive, sla(0x1), gid(0), cfg_order(1), cost(0), selected 2: Seq_num(1 port1), alive, sla(0x0), gid(0), cfg_order(0), cost(0), selected Internet Service(1): Zoom-Zoom.Meeting(...)
Why it works this way
A link can be "up" and still useless for a video call. Measuring every link continuously turns link choice into a decision about quality, not just availability. Grouping the links into a zone keeps routes and policies simple: they point at the zone once, and SD-WAN rules decide the member for each session.
Common mistakes
- Trying to add an interface still used in a policy or route as a member.
- Forgetting the static route to the SD-WAN zone, so nothing is routed through it.
- Health-check servers that block ping, so both members look dead.
- Putting a broad rule above a specific one, as with firewall policies.
Key takeaways
- Members (with gateways) are grouped in a zone; routes and policies use the zone.
- Performance SLAs measure latency, jitter and loss per member against thresholds.
- SD-WAN rules match traffic top-down and pick a member by strategy; unmatched traffic follows the implicit rule.
- diagnose sys sdwan health-check and service show what SD-WAN measured and chose.
Check yourself
A Lowest Cost (SLA) rule prefers port1 then port4. port1 is up but misses the SLA; port4 meets it. Where do new matching sessions go?
After enabling SD-WAN, nothing reaches the Internet. Members, health check and policy to virtual-wan-link exist. What is missing?
Which traffic follows the implicit rule?