← Back to knowledge base
mediumSD-WAN

Troubleshooting loss of Internet access through an SD-WAN interface

Confirmed 7/30/2026

Problem

Internet access fails after changing the outgoing interface in a LAN firewall policy from a working WAN interface to SD-WAN, even though SD-WAN Status reports that the links are up and can ping Google.

Symptoms

Traffic reaches the Internet when the firewall policy uses an individual WAN interface, but fails when the same policy uses SD-WAN as its outgoing interface. SD-WAN Status may still show successful probes and an up state.

Environment

FortiGate with two broadband ISP connections configured for SD-WAN load balancing. FortiGate model: null.

Root Cause

The available information does not identify one confirmed cause. Likely configuration areas include missing ISP gateways on SD-WAN members, an absent default route through SD-WAN, an incorrectly configured SLA, or NAT not being enabled on the LAN-to-SD-WAN firewall policy.

Solution

  1. Confirm that SD-WAN is enabled and that both broadband interfaces are configured as SD-WAN members.
  2. Verify that the gateway for each ISP is specified on its corresponding SD-WAN member.
  3. Configure an SLA for link up/down detection.
  4. Create a default route that uses SD-WAN.
  5. Configure the firewall policy from the internal network to SD-WAN, and enable NAT on that policy.
  6. Review the SD-WAN routes and static routes for correctness.
  7. Check the routing monitor and confirm that it displays the expected routes.

Verification

In SD-WAN Status, confirm that the SLA reports the links as up and that the probe can ping Google. In the routing monitor, verify that the expected SD-WAN and default routes are installed. Then test Internet access from a LAN client through the LAN-to-SD-WAN policy.

Tags

No tags yet.

Community rating

/ 5 (0)

Discussion (0)

    No comments yet.