A FortiGate is configured with SD-WAN and has two WAN members: Member1 (ISP1) with priority 10, and Member2 (ISP2) with priority 5. The SD-WAN rule for traffic from the internal network uses the 'best quality' strategy. During normal operation, traffic flows through Member1. After a link failure on Member1, traffic correctly fails over to Member2. However, when Member1 is restored, traffic does not fail back. What is the most likely cause?
Trap 1: The static route for Member1 has a higher administrative distance…
SD-WAN member selection does not rely on static route distance; it uses SD-WAN rules and health-check status.
Trap 2: The SD-WAN rule is configured with 'set fallback' disabled.
There is no 'fallback' setting in SD-WAN rules; fallback is controlled by health-check and route updates.
Trap 3: The priority of Member2 is higher than Member1.
Member1 has higher priority (10 > 5), so it should be preferred when available; this is not the cause.
- A
The static route for Member1 has a higher administrative distance than Member2.
Why it fails: SD-WAN member selection does not rely on static route distance; it uses SD-WAN rules and health-check status.
- B
The health-check for Member1 is configured with 'set probe-mode passive' and 'set update-static-route disable'.
Passive monitoring does not trigger fallback; update-static-route must be enabled for the route to be reinstated when the link recovers.
- C
The SD-WAN rule is configured with 'set fallback' disabled.
Why it fails: There is no 'fallback' setting in SD-WAN rules; fallback is controlled by health-check and route updates.
- D
The priority of Member2 is higher than Member1.
Why it fails: Member1 has higher priority (10 > 5), so it should be preferred when available; this is not the cause.