Course menu

Module 4: Routing and SD-WANLesson 4.3 (3 of 4 in this module)17 of 18 in the FortiGate Administrator course

SD-WAN basics

Members and zones, performance SLAs that measure each link, SD-WAN rules that steer applications, and what happens when a link degrades.

Intermediate · 14 min read

What you will learn

After this lesson, you can put two Internet links into an SD-WAN zone, measure them with a performance SLA, steer an application with an SD-WAN rule, and verify the decisions.

  • Members and zones
  • Performance SLA
  • SD-WAN rules
  • Verification

SD-WAN (software-defined WAN) on a FortiGate groups several WAN links into a zone and chooses the link for each new session using rules. Performance SLAs continuously measure each link's latency, jitter and packet loss to target servers, so rules can send each application over the link that currently meets its needs, and move it when a link degrades.

In simple terms: Two Internet connections are treated as one pool. The FortiGate keeps testing how good each one is and sends each kind of traffic down the best link right now.

A real-life situation

FGT1 has a fibre link (port1) and a cheaper broadband link (port4). With plain static routes, port4 sits idle as a backup and only takes over when port1 fails completely. Users complain that video calls stutter in the afternoon, when the fibre provider is congested but still "up". SD-WAN measures both links all the time and can move calls to whichever link is healthier.

port2port1port4PC1LAN · 10.0.1.10FGT1SD-WAN zoneISP1fibre · gw 203.0.113.1ISP2broadband · gw 192.0.2.1
  1. 1. Best quality: Calls use whichever member has the lowest latency and meets the SLA.
  2. 2. Other traffic: Bulk traffic can be sent to the cheaper link, or shared between both.

Step 1: members and zone

config system sdwan set status enable config zone edit "virtual-wan-link" next end config members edit 1 set interface "port1" set zone "virtual-wan-link" set gateway 203.0.113.1 next edit 2 set interface "port4" set zone "virtual-wan-link" set gateway 192.0.2.1 next end end

Remove any policies and static routes that reference port1 or port4 first. Each member carries its own gateway, so the separate default routes aren't needed any more.

Step 2: a route and a policy using the zone

config router static edit 1 set sdwan-zone "virtual-wan-link" next end config firewall policy edit 3 set name "LAN-to-Internet" set srcintf "port2" set dstintf "virtual-wan-link" set srcaddr "LAN-subnet" set dstaddr "all" set action accept set schedule "always" set service "HTTP" "HTTPS" "DNS" set nat enable set logtraffic all next end

One default route points at the zone and expands to a route through each member. The policy's outgoing interface is the zone, so it covers both links; NAT uses whichever member's address the session leaves from.

Step 3: measure the links

config system sdwan config health-check edit "Internet-SLA" set server "8.8.8.8" "1.1.1.1" set protocol ping set interval 500 set failtime 5 set recoverytime 5 set members 1 2 config sla edit 1 set latency-threshold 150 set jitter-threshold 30 set packetloss-threshold 2 next end next end end

Each member pings two servers every 500 ms. A member that fails 5 probes in a row is marked dead. SLA 1 is met while latency is under 150 ms, jitter under 30 ms and loss under 2%.

Step 4: steer traffic with a rule

config system sdwan config service edit 1 set name "Video-calls" set mode sla set internet-service enable set internet-service-name "Zoom-Zoom.Meeting" config sla edit "Internet-SLA" set id 1 next end set priority-members 1 2 next end end

Rules are checked top-down like policies. Strategy sla (Lowest Cost (SLA) in the GUI) uses the first member in priority-members that meets SLA 1: port1 normally, port4 when port1 misses the SLA. Traffic matching no rule follows the implicit rule, which load-balances by source IP by default. The Internet Service name shown is an example; pick the one for your application from the list.

Strategy (GUI name)Chooses
ManualA fixed member (or members in order), regardless of quality
Best QualityThe member with the best measured value: lowest latency, jitter or loss
Lowest Cost (SLA)The first preferred member that meets the SLA (cost or order breaks ties)
Maximize Bandwidth (SLA)Shares sessions across all members that meet the SLA

Verify

Example output · based on Fortinet documentation; exact format varies by model and FortiOS version
FGT1 # diagnose sys sdwan health-check
Health Check(Internet-SLA):
Seq(1 port1): state(alive), packet-loss(0.000%) latency(186.402), jitter(12.115), sla_map=0x0
Seq(2 port4): state(alive), packet-loss(0.000%) latency(24.871), jitter(1.902), sla_map=0x1
Both members are alive, but port1's latency (186 ms) breaks the 150 ms threshold, so its sla_map is 0x0 (SLA 1 not met). port4 meets it (0x1). (Example output.)
Example output · based on Fortinet documentation; exact format varies by model and FortiOS version
FGT1 # diagnose sys sdwan service
Service(1): Address Mode(IPV4) flags=0x200 ...
  Gen(3), TOS(0x0/0x0), Protocol(0): src(1->65535):dst(1->65535), Mode(sla), sla-compare-order
  Members(2):
    1: Seq_num(2 port4), alive, sla(0x1), gid(0), cfg_order(1), cost(0), selected
    2: Seq_num(1 port1), alive, sla(0x0), gid(0), cfg_order(0), cost(0), selected
  Internet Service(1): Zoom-Zoom.Meeting(...)
The rule now lists port4 first: new video calls go to port4 until port1 meets the SLA again. (Example output, trimmed.)

Why it works this way

A link can be "up" and still useless for a video call. Measuring every link continuously turns link choice into a decision about quality, not just availability. Grouping the links into a zone keeps routes and policies simple: they point at the zone once, and SD-WAN rules decide the member for each session.

Common mistakes

  • Trying to add an interface still used in a policy or route as a member.
  • Forgetting the static route to the SD-WAN zone, so nothing is routed through it.
  • Health-check servers that block ping, so both members look dead.
  • Putting a broad rule above a specific one, as with firewall policies.

Key takeaways

✅ Key takeaways
  • Members (with gateways) are grouped in a zone; routes and policies use the zone.
  • Performance SLAs measure latency, jitter and loss per member against thresholds.
  • SD-WAN rules match traffic top-down and pick a member by strategy; unmatched traffic follows the implicit rule.
  • diagnose sys sdwan health-check and service show what SD-WAN measured and chose.

Check yourself

Predict · scenario 1

A Lowest Cost (SLA) rule prefers port1 then port4. port1 is up but misses the SLA; port4 meets it. Where do new matching sessions go?

Predict · scenario 2

After enabling SD-WAN, nothing reaches the Internet. Members, health check and policy to virtual-wan-link exist. What is missing?

Predict · scenario 3

Which traffic follows the implicit rule?

FAQ

Why must I remove port1 from policies before adding it to SD-WAN?
An SD-WAN member is referenced through its zone. While policies or static routes still name port1 directly, FortiOS won't add it as a member. Delete or change those references, add the member, then write policies and routes against the zone.
Does SD-WAN move a session that is already running?
Normally no: the link is chosen when a session starts. New sessions follow the rule's current choice, so when a link degrades, new connections move straight away and existing ones finish on the old link (or fail if it is down).