FortiGate SD-WAN Performance SLA and Load Balancing - 夜莺博客

FortiGate SD-WAN Performance SLA and Load Balancing

An SD-WAN rule without a performance SLA is just policy routing with extra steps. The value of FortiGate SD-WAN comes from health checks that continuously measure latency, jitter and packet loss per member link, and rules that only select a link while it meets the target. This guide shows the full configuration - members with costs, a health check with SLA thresholds, a lowest-cost rule with load balancing enabled, and the diagnose commands that tell you which link is actually being used right now.

Members, Costs and Zones

Each WAN interface becomes an SD-WAN member with an optional cost. Cost is only meaningful when the rule strategy is lowest cost (SLA), where the cheapest link that satisfies the SLA wins. Add members explicitly and give the cheaper link a lower cost.

config system sdwan
    config members
        edit 1
            set interface "wan1"
            set cost 10
        next
        edit 2
            set interface "wan2"
            set cost 5
        next
    end
end

If no SD-WAN zone is specified, members join the default virtual-wan-link zone. Use explicit zones when you want per-zone steering - for example an MPLS zone and a broadband zone with different SLA definitions.

Performance SLA (Health Check)

The health check defines the probe target and the thresholds. FortiGate supports ping, HTTP, DNS and other probe types; pick a target that reflects the real path, not just the next hop.

config system sdwan
    config health-check
        edit "google"
            set server "google.com"
            set members 1 2
            config sla
                edit 1
                    set latency-threshold 10
                    set jitter-threshold 5
                next
            end
        next
    end
end

Leave packet loss unset for now if you want the simplest starting point, then tighten it once you have baseline data. Thresholds that are too aggressive cause permanent flapping between members, which is worse than a slow link.

Rule Strategy: Lowest Cost with Load Balancing

The strategy name changed over releases: what FortiOS 7.0 called maximize bandwidth (load-balance) is now configured inside the lowest cost (SLA) strategy by enabling load balancing on the rule. All links that satisfy the SLA are then used together, distributed by the hash method.

config system sdwan
    config service
        edit 1
            set name "gmail"
            set load-balance enable
            set mode sla
            set internet-service enable
            set internet-service-name "Google-Gmail"
            config sla
                edit "google"
                    set id 1
                next
            end
            set priority-members 1 2
        next
    end
end

Hash methods include round-robin (default), source-ip-based, source-dest-ip-based, and the bandwidth-aware inbandwidth, outbandwidth and bibandwidth options. Bandwidth-aware methods compare the estimated upstream and downstream bandwidth values configured on each interface:

config system interface
    edit "wan1"
        set estimated-upstream-bandwidth 100000
        set estimated-downstream-bandwidth 500000
    next
end

The minimum-sla-meet-members setting adds a floor: the rule only takes effect if at least that many members meet the SLA, which prevents a single poor link from attracting all traffic.

Diagnosing Which Link Won

diagnose sys sdwan health-check status
diagnose sys sdwan service4 1
diagnose sys sdwan service
diagnose sys sdwan member

The service output lists each member with its sequence number, alive state, whether it passes the SLA, and whether it is currently selected. A member that is alive but not selected is failing the SLA thresholds - compare the reported latency and jitter against your configured values. Note that on 7.4.5 and later, session re-evaluation after a route-table change is more aggressive, so load-balanced rules can shift members more often than older firmware.

Design Notes

Keep SLA thresholds symmetric across members or traffic will oscillate. Monitor diagnose sys sdwan health-check status over a full business day before tightening thresholds, and remember that load balancing a latency-sensitive application across two links with different round-trip times can hurt more than it helps. For branch designs built on cellular backup, 5G/LTE branch failover SD-WAN design covers the failover side, and the FortiGate FortiOS CLI troubleshooting cheat sheet collects the general debugging commands.

原文链接:https://docs.fortinet.com/document/fortigate/8.0.1/administration-guide/342836/lowest-cost-sla-strategy