FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Not applicable
Article Id 193582
Article
Description How to set up a ping server and dead gateway detection on a FortiGate unit.
Components All FortiGate units.
Steps or Commands

Use a ping server in conjunction with dead gateway detection, and a redundant internet connection. If the primary connection fails, the redundant connection (for example a modem on a FortiGate-60M) replaces the down connection.The Ping Server automatically pings an IP address on the next hop router to verify when the connection is up and active again. The FortiGate unit will automatically switch back to the primary Internet connection.

Adding a Ping server

To add a ping server to an interface

  1. Go to System > Network > Interface.
  2. Choose an interface and select Edit.
  3. Set Ping Server to the IP address of the next hop router on the network connected to the interface.
  4. Select the Enable check box.
  5. Select OK to save the changes.

Dead gateway detection

The FortiGate unit uses dead gateway detection to ping the Ping Server IP address to make sure the FortiGate unit can connect to that IP address. Modify the dead gateway detection to control how the FortiGate unit confirms connectivity with a ping server added to an interface configuration.

To modify dead gateway detection

  1. Go to System > Network > Options.
  2. For Detection Interval, type a number in seconds to specify how often the FortiGate unit tests the connection to the ping target.
  3. For Fail-over Detection, type a number of times the connection test fails before the FortiGate unit assumes the gateway is no longer functioning.
  4. Select Apply.

 


Related Articles

Technical Note: Detecting a link failure using Dead Gateway Detection (ping server) to ensure a lin...