2. Add static routes and security policies 3. Congure fail over detection and spillover load balancing 4. Results Using two ISPs for redundant Internet connections with distributed sessions This example describes how to improve the reliability of a networks connection to the Internet by using two Internet connections. It also includes confguration of equal cost multi-path load balancing to make effcient use of these two Internet connections by distributing sessions to both, without allowing either one to become overloaded. Internal Network Internal FortiGate wan 2 wan 1 Internet ISP 1 ISP 2 30 Step One: Confgure connections to the two ISPs Step Two: Add static routes and security policies Go to System > Network > Interface. Go to Router > Static > Static Route. For ECMP to work, both default routes must have the same Distance and Priority. 31 Step Three: Confgure fail over detection and spillover load balancing Set the Ping Interval and Failover Threshold to a smaller value for a more immediate reaction to a connection going down. Go to Policy > Policy > Policy. Go to Router > Static > Settings. Create two new Dead Gateway Detection entries. 32 The Spillover Threshold value is calculated in kbps (kilobit per second). However the bandwidth on interfaces is calculated in kBps (kilo Byte per second). For wan1 interface, Spillover Threshold = 100 kbps = 100000 bps 100000 bps = 102400 bps = 102400/8 Bps = 12800 Bps Go to Log & Report > Traffc Log > Forward Traffc to see network traffc from different source IP addresses fowing through both wan1 and wan2. Disconnect the wan1 port on the FortiGate unit to see all traffc will automatically fow through the wan2 port unit wan1 is available again. Results Go to Router > Static > Settings. Set the ECMP Load Balancing Method to Spillover.