Network and Telecom

FortiGate SD-WAN, Dual WAN Failover and ZTNA in Istanbul

When a line drops, phone calls, the ERP and branch links should move to the other line without anyone noticing. That is what we build FortiGate SD-WAN to do, measuring and testing as we go.

CybUP TeamLast updated: 6 min read

In short

FortiGate SD-WAN is a FortiOS feature that manages several internet lines as one logical connection and steers traffic according to line quality. It is used in offices with two lines, multi-branch companies and wherever voice and ERP traffic cannot tolerate outages. CybUp defines the lines with SLA measurements, writes the failover or load-balancing rules, and sets up branch tunnels and, where needed, ZTNA access.

What is FortiGate SD-WAN, and why use it for dual WAN?

FortiGate SD-WAN is a FortiOS feature that groups two or more internet connections into one SD-WAN zone and uses rules to decide which traffic leaves over which line. The traditional approach is two default routes, one of which drops out after a crude ping check. With SD-WAN every line is measured continuously, and decisions are based on latency, jitter and packet loss.

The setup we see most often in Türkiye is a fibre line plus a second line from another provider; sometimes the second line is a mobile (4.5G/5G) modem. Physical diversity matters here too. If two providers’ fibre comes into the building through the same duct, one set of roadworks can cut both. We ask about this when the lines are being chosen.

Dual WAN: should you set up failover or load balancing?

In most offices the right answer is a mix of the two: critical traffic goes over whichever line is performing best at that moment, everything else is shared across both, and when one line fails, everything moves to the remaining line. FortiOS SD-WAN rules offer several strategies for this: manual priority, Best Quality, Lowest Cost (SLA), which picks the cheapest line that meets the SLA, and Maximize Bandwidth (SLA).

Load balancing works per session. A single file download will not run at the combined speed of both lines, but a hundred users’ sessions will be spread across them. Applications that drop the session when the source IP changes, such as online banking and government portals, we pin to one line.

Take an 80-person logistics office with an IP PBX and a cloud ERP. Voice and ERP get a Best Quality rule, Microsoft 365 and general web traffic are spread across both lines, and backup and update traffic gets a rule that prefers the second line. If one line starts to degrade during the day, calls slide across to the other; users notice no more than a very brief stutter.

How are performance SLAs and line health measured?

FortiGate tracks each line’s latency, jitter and packet loss, either by sending regular probes to a target over that line or by passively measuring the sessions that pass through security policies. If a line fails all its health checks, its routes are removed from SD-WAN and traffic moves to the other lines; once the line meets its SLA again, the routes come back (Fortinet: Performance SLA).

The part most often got wrong is the probe target. Pinging only the provider’s first gateway will show the line as “healthy” even when the provider’s backbone has gone down. For each line we use several targets in different parts of the internet and set thresholds per application: tight latency and jitter limits for voice, looser ones for general web. On projects that run alongside an IP PBX installation, we test the voice quality thresholds together with the PBX side.

How do branches connect over FortiGate SD-WAN?

Branches usually connect to head office with a separate IPsec tunnel over each internet line, and those tunnels become SD-WAN members as well. If one of a branch’s lines drops, its connection to head office carries on through the other tunnel. Running BGP over the tunnels makes routing much easier to manage as the number of branches grows.

Where branches need to talk to each other directly (say two branches swap a lot of files and video calls), Fortinet’s ADVPN lets that traffic take the short path between them instead of going round through head office. For branches running other vendors’ equipment we build standard IPsec tunnels; the details are on our VPN server setup page.

What is ZTNA, and does it replace VPN?

ZTNA (Zero Trust Network Access) is an access model that, rather than putting the user on the whole internal network, connects them only to the application they are allowed to use, after checking the device’s security posture at that moment. On the FortiGate this means setting up a FortiClient EMS connector, a ZTNA server (access proxy) and a ZTNA policy; posture tags sent by EMS, such as “disk encrypted” or “antivirus up to date”, feed into the access decision (Fortinet: Basic ZTNA configuration).

ZTNA does not replace VPN in every case. It is a very good fit for web applications, RDP and SSH, but legacy applications that need broad network-layer access may still need IPsec remote access. ZTNA is also not supported on FortiGate models with 2 GB of RAM, and it needs a FortiClient EMS licence. So we first map out who reaches which application from which device, and only then decide whether ZTNA is worth recommending.

“Zero trust (ZT) is the term for an evolving set of cybersecurity paradigms that move defenses from static, network-based perimeters to focus on users, assets, and resources.”

— NIST — SP 800-207 Zero Trust Architecture

FortiGate SSL VPN tunnel mode has been removed: what now?

FortiOS 7.6.3 removed SSL VPN tunnel mode and replaced it with standards-based IPsec VPN. Old SSL VPN tunnel settings are not carried across to the new version, so remote access has to be moved to IPsec by hand before you upgrade. Where UDP ports 500 and 4500 are blocked, IPsec can also run over TCP 443; that needs FortiOS 7.4.2 and FortiClient 7.4.1 or later. SSL VPN web mode lives on under the name “Agentless VPN” (Fortinet: Migrating from SSL VPN tunnel mode to IPsec).

It makes sense to fold this migration into the SD-WAN project: remote access tunnels are then no longer tied to one line, and users connect over whichever line is up. We split the migration by user group and start with a small pilot group.

Can SD-WAN and HA be used together?

Yes. In an HA cluster of two FortiGates the SD-WAN configuration is synchronised too, and the line rules work exactly the same when the standby unit takes over (Fortinet: SD-WAN with FGCP HA). The thing to watch is that both internet lines can reach both units; if the provider’s modem has only one port, you need a switch or a VLAN arrangement in between. We cover the HA build itself on our FortiGate installation page.

What you receive

  • Line inventory and physical diversity assessment
  • Performance SLA definitions, probe targets and thresholds
  • Application-based SD-WAN rules (voice, ERP, cloud, general web)
  • Branch IPsec tunnels and, where needed, BGP routing
  • Remote access migration from SSL VPN to IPsec
  • ZTNA suitability assessment and setup (where needed)
  • Handover document including the line failure test results

How we work

  1. 1

    Line and traffic analysis

    We look at your current lines, providers, building entry routes and how much traffic each application generates. The review is free.

  2. 2

    Rule design

    We write down which traffic prefers which line, the SLA thresholds and the branch topology, and put them to you for sign-off.

  3. 3

    Configuration

    We bring the SD-WAN zone, SLA measurements, rules and tunnels live out of hours.

  4. 4

    Failover testing

    We physically unplug each line in turn and measure how phone calls, ERP sessions and branch access behave.

  5. 5

    Monitoring and tuning

    Over the first few weeks we watch the SLA history and fine-tune the thresholds to how the lines actually behave.

Frequently asked questions

Do we need an extra device for SD-WAN?

No. SD-WAN is a feature of FortiOS, the FortiGate operating system, and is configured on the unit you already have. You only need one free WAN port per line, or a VLAN arrangement that does the same job.

Will a phone call drop when traffic switches lines?

If a line goes down completely, a call in progress may break up briefly or drop, and new calls are set up over the other line. If a line degrades gradually, the SLA thresholds usually move traffic across before anything drops.

Do two internet lines double our speed?

Total capacity goes up because sessions are spread across both lines, but any single download or video call is limited to the speed of one line.

Can a mobile connection be used as a backup line?

Yes. A 4.5G/5G modem, or a modem the FortiGate supports, can be the second line. We then write rules that use the mobile line purely as backup and keep update and backup traffic off it.

What licences does FortiGate ZTNA need?

On top of the FortiGate configuration, you need FortiClient EMS (on-premises or cloud) and FortiClient on the endpoints. We list each licence item separately in the quote, based on your user count; the review is free.

How long does a FortiGate SD-WAN setup take?

Dual WAN SD-WAN at a single site goes live in a maintenance window of a few hours; with design and testing, it adds up to a few working days. More branches and a wider ZTNA scope take longer.

Our branches use another vendor’s equipment. Is that a problem?

Not if the branch device supports IPsec: it can connect to head office over a standard tunnel, with SLA measurement and routing handled at head office. Features such as direct branch-to-branch shortcuts (ADVPN), however, need a FortiGate at both ends.

Sources and official documentation

CybUP Team

Written and reviewed by the CybUP technical team in Istanbul. Last updated: 10 October 2026.

Request a free review for this service

Fill in the form and we will get back to you as soon as possible. For urgent matters, WhatsApp or phone is faster.

Message on WhatsApp

Cookie preferences

Strictly necessary

Required for the core functions of the site and to remember your choices. Cannot be turned off.

Analytics

Lets us measure which pages are visited, anonymously (Google Analytics via Google Tag Manager).

Marketing

Used for advertising measurement and personalisation.