Internet resilience • routing control • SD-WAN planning
FortiGate Dual WAN Configuration in Dubai, UAE
Two internet circuits only improve resilience when the firewall knows which path to use, how to judge link health, what traffic must move during a failure, and how to return traffic to normal after recovery. FourTeck helps businesses plan and configure FortiGate dual WAN environments around actual ISP details, routing behaviour, business applications, NAT, VPNs and testing requirements rather than relying on a generic template.
Before configuration, confirm
- FortiGate model and installed FortiOS version
- WAN1 and WAN2 handoff type, gateway and addressing
- Failover-only or active-active objective
- Inbound NAT, VPN and public IP dependencies
- Applications that need path preference or SLA control
SD-WAN or traditional routing
Gateway, health probe, route, policy
Failover behaviour and application continuity
Model, FortiOS, ISP and topology
Direct answer: what does dual WAN configuration do?
FortiGate dual WAN configuration connects two internet paths to one FortiGate so the firewall can choose or change the outgoing path according to the design. Businesses commonly use it for primary-and-backup ISP failover, active use of both links, application-aware path selection through SD-WAN, or a mixture of these goals. Organisations that depend on cloud applications, voice, remote access, online transactions or branch connectivity should consider it when one ISP outage would materially disrupt operations. Before proceeding, confirm the FortiGate model and FortiOS version, both ISP parameters, public IP dependencies, NAT and VPN requirements, expected link-selection policy, and a safe testing window.
What the service is designed to achieve
A dual WAN project is not simply the act of enabling a second interface. The useful outcome is predictable traffic behaviour. The firewall must know which links are members of the design, how each link is reached, what condition represents a usable path, which traffic may use each path, and what should happen when conditions change. For some organisations, the correct result is a strict primary ISP with a standby circuit. For others, both circuits should carry traffic while key applications remain pinned to the better path. The configuration should also take security policies, source NAT, DNS, VPNs, published services and monitoring into account.
Who should consider it
The service may suit companies that already pay for two ISP links but are unsure whether failover works, businesses replacing a router with a FortiGate, offices experiencing unstable connectivity, branches that need application-aware path selection, and IT teams that want a cleaner SD-WAN design. It is also relevant when an existing setup fails over only when an interface goes physically down but does not react correctly to upstream ISP failure. The exact benefit depends on the topology. Dual WAN does not guarantee internet availability because both circuits can still share a common upstream dependency, building path, power source or provider infrastructure.
Business problems a well-planned design can address
ISP failure stops the office
A secondary circuit can be configured as an alternate path when the preferred route becomes unusable, subject to correct monitoring and routing design.
Both links exist but one is idle
SD-WAN policies can be considered when the business wants to use available links actively rather than keeping one permanently idle. The right strategy depends on application behaviour and link characteristics.
Failover occurs too late
A cable may remain up even when internet reachability is impaired. Link-health monitoring or SD-WAN Performance SLAs can help make path decisions using reachability or measured quality instead of physical link state alone.
Applications follow the wrong path
Traffic rules can be aligned with business requirements so selected applications, destinations or traffic groups prefer an appropriate link, while fallback behaviour is defined in advance.
Service-fit decision matrix
| Business situation | Relevant assistance | Scope dependency |
|---|---|---|
| WAN1 should carry normal traffic and WAN2 should take over on failure | Primary/backup routing, health detection, policy and NAT review | ISP addressing, route type, failback expectations |
| Both ISPs should be used | SD-WAN membership, service rules and distribution strategy | Application sensitivity, bandwidth, session behaviour |
| Voice or SaaS traffic should avoid degraded links | Performance SLA planning and application/path rules | Acceptable latency, jitter, loss and reachable test targets |
| Inbound services use public IPs on one or both ISPs | VIP/NAT, DNS and return-path review | Public addressing, DNS control, server behaviour |
| Site-to-site VPNs must survive an ISP event | WAN and VPN topology review with controlled failover testing | Peer capabilities, tunnel design, routing and remote-side configuration |
Buyer information and service scope
| Topic | FortiGate Dual WAN Configuration |
|---|---|
| Main purpose | Plan and implement predictable use of two internet connections through failover, SD-WAN or a suitable routing design. |
| Suitable for | Businesses using supported FortiGate appliances or virtual FortiGate deployments with two usable WAN paths. |
| Assessment support | Review of topology, WAN handoffs, current routing, firewall policies, NAT, VPN dependencies and business objectives. |
| Configuration support | Scope may include interfaces, SD-WAN members, routes, health checks, SD-WAN rules, policies, NAT and related settings. |
| Testing guidance | Controlled link-failure, recovery, route, session and application testing according to agreed scope. |
| Customer inputs required | FortiGate model, FortiOS version, ISP parameters, network diagram, public IP use, VPN list, critical applications and maintenance constraints. |
| Licensing guidance | Feature and database availability can depend on FortiOS version, FortiGate platform, subscription or service entitlement. Confirm the exact environment before relying on a feature. |
| Availability guidance | Contact FourTeck to confirm current service scheduling, remote or onsite coordination and quotation scope. |
| Important note | Exact commands and GUI paths can vary by FortiOS release and design. Changes should be based on the installed environment and tested against business traffic. |
Configuration, compatibility and dependency notice
FortiGate can implement dual internet connectivity in more than one way. Modern deployments commonly use SD-WAN because it groups member interfaces, supports service rules and can use Performance SLA measurements to influence path selection. Traditional routing with route preference and link monitoring can still be appropriate for a straightforward primary-and-backup requirement. The correct choice depends on FortiOS release, operational complexity, existing policies, the way each ISP supplies addressing and gateways, whether VPNs or inbound services depend on a public IP, and whether both circuits should be active. A configuration copied from another firewall may therefore produce the wrong result. FourTeck scopes the design around the actual appliance and network rather than treating dual WAN as a fixed checklist.
A practical engagement journey
Discover the current network
Collect FortiGate details, interface usage, ISP handoffs, routes, policies, NAT, VPNs and operational constraints. Establish what currently works and where failure occurs.
Define path behaviour
Agree whether the target is active-passive failover, active-active use, application steering, quality-based selection or a controlled combination.
Plan the change
Map required interface, route, SD-WAN, policy, NAT, health-check and VPN changes. Identify rollback requirements and a safe maintenance window where needed.
Configure and validate
Implement the agreed design, inspect routing and health status, test intended traffic flows, simulate suitable failure conditions and document the resulting behaviour.
Health-aware failover instead of interface-state guessing
A common dual WAN mistake is to assume that an Ethernet interface showing “up” means the internet service is usable. An ISP circuit can retain local link state while upstream routing, DNS reachability or provider transport is impaired. FortiGate designs can use link monitoring or SD-WAN Performance SLAs to test reachability through a specific path. In SD-WAN, performance health checks can measure conditions such as latency, jitter and packet loss and use the result in link-selection logic. For a simpler traditional failover design, a link monitor can be used to influence route availability when a monitored destination becomes unreachable.
The monitoring target matters. A single target can fail for reasons unrelated to the ISP, while a target that is reachable through the wrong path can give misleading results. Source interface, routing, probe protocol, thresholds and recovery behaviour therefore need deliberate planning. The goal is not the fastest possible failover at any cost. Aggressive thresholds can create flapping if a link has brief congestion or packet loss. The configuration should match the tolerance of the applications using the connection and should be verified during controlled tests.
Traffic steering and active use of both circuits
When both ISP links are intended to carry traffic, the design should begin with business traffic rather than with a generic load-balancing option. Web browsing, Microsoft 365 or other SaaS access, cloud backups, voice, remote desktop, IPsec tunnels and public-facing servers have different sensitivity to path changes. SD-WAN rules can be used to express path preference for selected traffic and can take link quality into account where suitable. This creates a more controlled approach than simply spreading every new session across both links without considering application behaviour.
Equal bandwidth is not required, but unequal circuits should be treated intentionally. A 1 Gbps primary line and a much smaller backup line cannot be expected to deliver identical user experience after failure. Likewise, two links with different latency characteristics may deserve different roles. FourTeck can help map applications and network segments to path-selection goals, identify which traffic must have priority, and decide how fallback should occur. The final rules remain dependent on the FortiOS version, the available features and the customer’s routing and security policy.
NAT, sessions, VPNs and return-path behaviour
Internet failover is often discussed only in terms of routes, but active user sessions are affected by source addresses and return paths. When outbound traffic moves from one ISP to another, the public source address normally changes if each provider allocates a different public range. Some applications tolerate a new session immediately; others may require users to reconnect. FortiGate includes configuration options that can influence how sessions react to route changes, but these should be applied only after reviewing the current design and FortiOS behaviour.
Inbound services require even more planning. If a server is published with a VIP on WAN1, moving outbound routing to WAN2 does not automatically make that service reachable through WAN2. Public DNS, additional public IPs, VIPs, reverse-path expectations and the remote application’s behaviour all matter. Site-to-site VPNs can also need peer-side changes, secondary tunnels or routing logic. A good dual WAN project therefore inventories what depends on each public IP before changes are made. This prevents a successful browsing failover from being mistaken for complete business-service continuity.
Where this configuration is commonly useful
Head offices using cloud applications
Dual WAN can provide an alternate internet path for email, ERP, CRM, collaboration, remote support and other cloud-dependent workflows when the primary circuit is unavailable.
Retail and branch environments
Branches may use two providers to reduce the impact of a last-mile outage and, where suitable, direct different application classes over preferred links.
Warehouses and operations sites
Sites relying on cloud inventory, barcode systems, CCTV access, VoIP or remote management can benefit from defined failover behaviour when the network architecture supports it.
Professional services and clinics
Organisations with client systems, online portals, cloud telephony or remote access may need a documented secondary path and tested recovery procedure.
Multi-site organisations
Dual WAN at branches can be coordinated with IPsec, SD-WAN overlays or routing policies, but resilience depends on both the local FortiGate and the remote-side design.
Temporary ISP migration
A second circuit may be introduced during provider migration or office change. The routing plan should clarify which link is preferred during transition and when old addressing can be removed.
Operational considerations after deployment
Dual WAN should be monitored after the initial test because link quality, provider routes and application use change over time. The IT team should know where to view SD-WAN member state, Performance SLA results, active routes and firewall logs. If the design uses traditional routing, route status and link-monitor results should be part of troubleshooting. A configuration backup should be taken before and after controlled changes, and any out-of-band or local recovery method should be understood before touching a production edge firewall.
Capacity also matters during failure. A secondary link that is adequate for backup browsing may not be large enough for all video conferencing, cloud backup and software updates at once. Traffic shaping or application prioritisation may therefore become relevant after failover. DNS, DHCP option distribution, proxy settings, upstream routers and public DNS records can introduce additional dependencies. For larger environments, centralised management, logging or branch-standardisation may be considered separately. FourTeck can help identify these dependencies during discovery, but the final scope should be agreed rather than assumed to include every adjacent firewall task.
Questions to resolve before a quotation
Specify whether WAN1 is always preferred, both links should be active, or applications should follow different paths.
Decide whether simple reachability is sufficient or whether latency, jitter and packet loss should influence decisions.
List inbound NAT, published servers, VPN peers, whitelists and external services that expect a specific source IP.
Confirm static, DHCP or PPPoE delivery, gateway information, VLAN tags, modem/router mode and any upstream NAT.
Some businesses want immediate failback to WAN1; others prefer a more conservative return after the primary link stabilises.
Define whether links can be disconnected physically, upstream reachability can be blocked, or tests must remain non-disruptive.
Procurement and evaluation checklist
What buyers usually want to understand before they change dual WAN
Failover and load balancing are not the same requirement. Failover means an alternate link is used when the preferred path becomes unavailable or unsuitable according to the configured health logic. Load balancing or active-active use means both links can participate during normal operation. A business may want one, the other, or selective use of both. The correct choice affects routes, SD-WAN rules, testing and user expectations. It also affects capacity planning: a secondary circuit that is only sized for essential traffic may not be suitable for unrestricted active use.
SD-WAN is usually the more flexible design when traffic quality matters. FortiGate SD-WAN can group WAN members and apply rules that steer traffic according to business criteria. Performance SLA health checks can measure link quality indicators including latency, jitter and packet loss. This can be useful for applications that remain technically reachable but perform poorly on a degraded link. The thresholds should be chosen around real application tolerance rather than copied from a sample configuration. Excessively strict values can cause frequent path changes, while overly loose values may leave users on a poor connection for too long.
Not always. If the external source address changes between ISPs, many internet services see the traffic as a new connection. FortiGate has controls related to route-change session behaviour, but application state, NAT and the remote endpoint still influence what users experience. Plan for some sessions to reconnect during a real ISP transition.
They can participate in one SD-WAN design, but “combined” does not mean one single download will automatically equal the sum of both circuits. Session distribution, application design, routing and provider paths all matter. Use business traffic classes and realistic expectations when defining the policy.
ISP addressing changes the design. Static public IPs are common for servers, site-to-site VPNs, third-party whitelists and services that expect a known source address. DHCP or PPPoE handoffs can have different gateway and route behaviour. If the two ISPs use different public subnets, outbound failover changes the source identity seen by internet services. If an organisation publishes services from its FortiGate, inbound continuity may require DNS changes, secondary VIPs, dual-homed application design or coordination with external systems. It should never be assumed that a working outbound failover automatically protects inbound services.
A successful test needs more than browsing to a website. Testing should include the routing table, SD-WAN or link-monitor state, DNS resolution, critical cloud applications, voice where relevant, remote access, VPN tunnels, public services and recovery to the preferred link. It is useful to record the expected behaviour before the test begins. That way, the team can distinguish a design issue from a normal application reconnect. For high-impact environments, a rollback plan and local access method should be agreed before changing the edge firewall.
Dual WAN does not remove every single point of failure. Two circuits may still enter the same building duct, terminate on common carrier infrastructure, share power or depend on the same FortiGate appliance. Businesses with stricter availability objectives may need to review firewall high availability, diverse carrier paths, redundant switches and power design separately. Those are related architecture decisions, not automatic parts of a dual WAN configuration.
The fastest way to obtain an accurate quotation is to provide the actual network facts. Share the FortiGate model, FortiOS version, current configuration backup where appropriate, WAN addressing, a simple topology diagram, existing routes, critical applications, public IP dependencies, VPN list and the required failover behaviour. FourTeck can then identify whether the request is a straightforward route-and-monitor task, an SD-WAN policy project, or a broader change involving NAT, VPN and application testing. For related firewall planning, buyers can also review FourTeck firewall services and Fortinet firewall guidance for Dubai.
Decision questions that deserve a direct answer
Should we use SD-WAN or static-route failover?
Choose based on the required behaviour, not on terminology. A simple primary-and-backup design can be handled with traditional routing and health monitoring when the environment is straightforward. SD-WAN is more appropriate when both links are active, applications need different path preferences, or link quality should influence selection. Existing configuration, FortiOS version and operational skills also matter.
What information is essential from each ISP?
Provide the handoff type, IP address, subnet, gateway, DNS details where relevant, VLAN tag if used, modem or router mode, public IP allocation and any provider-side restrictions. If the circuit uses DHCP or PPPoE, mention that explicitly. These details determine how interfaces and routes are built and how monitoring probes leave each link.
Will our site-to-site VPN automatically move to WAN2?
Not necessarily. A VPN peer may be tied to a WAN1 public IP, a specific interface or a remote-side configuration that does not know about WAN2. VPN resilience should be treated as its own design item. The peer firewall, tunnel parameters, routing and public IP availability need review before promising failover.
Can we keep the same public IP when changing ISPs?
Usually not unless the addressing arrangement specifically supports portability or provider-independent routing. Most ordinary business circuits have different provider-assigned public addresses. That means outbound sessions may present a new source IP after failover, and inbound services may need separate planning.
How do we know failover is actually working?
Verify more than the dashboard. Observe route state, health-check or SLA status, source IP changes, internet access, DNS, business applications and any VPN or inbound-service dependencies. Then restore the primary path and confirm recovery behaves as intended. Record the results so future troubleshooting has a known baseline.
Can FourTeck configure an existing FortiGate remotely?
Remote work can be considered when safe management access, backups, local hands and an agreed change procedure are available. Some environments may require onsite coordination because the ISP handoff, cabling, modem state or recovery risk cannot be handled safely from a remote session. The quotation should define the delivery method rather than assuming it.
How FourTeck can assist with planning and configuration
FourTeck can support the project from requirement clarification through configuration and testing. The first task is to establish the desired operational outcome and compare it with the current firewall state. This can include reviewing interface definitions, default routes, SD-WAN settings, firewall policies, source NAT, VIPs, VPNs and monitoring behaviour. The scope can then be narrowed to the changes that are actually required. For a new installation, the work may start with WAN interface planning. For an existing production firewall, change control, backup and rollback preparation are normally more important.
The service can also be coordinated with broader firewall solutions in Dubai, FortiGate and firewall product selection, or a wider network migration requirement. If the existing appliance is undersized, out of support, short on interfaces or unable to meet the required inspection workload, dual WAN configuration alone may not address the operational problem. In that case, FourTeck can help separate the immediate connectivity need from any hardware, licensing or lifecycle decision so the buyer receives a quotation based on a clear bill of work.
UAE availability and support guidance
Businesses in the UAE can contact FourTeck to confirm current availability for FortiGate dual WAN consultation, configuration, testing and related firewall support. Service scheduling can depend on the existing FortiGate model, FortiOS version, whether safe remote access is available, whether an onsite visit is required, and how much of the work must be performed during a defined maintenance window. Delivery and project coordination should be discussed after the exact requirement is confirmed. If a customer also needs a new FortiGate appliance, licenses or accessories, those items should be quoted separately according to model, entitlement, quantity and current vendor lead time. Installation and configuration scope should be stated in the quotation when required rather than assumed to be bundled.
Dubai, Abu Dhabi, Sharjah and Ajman project coordination
FourTeck can discuss FortiGate dual WAN requirements for businesses operating across Dubai, Abu Dhabi, Sharjah and Ajman. The practical delivery model depends on whether the change is limited to firewall configuration or also requires ISP handoff checks, cabling verification, modem changes, local testing or coordination with a customer IT team. Multi-site customers should provide a short topology and identify whether every site follows the same standard or uses different FortiGate models and provider arrangements. A consistent design can simplify support, but the configuration should still respect site-specific addressing, bandwidth, VPN peers and application dependencies. Contact FourTeck with the affected locations, desired timeline and current device details so the service scope can be planned accurately.
GCC Availability
FourTeck can assist organisations planning FortiGate dual WAN work across GCC markets where the project can be supported through suitable remote coordination, local project arrangements or a defined delivery scope. Requirements may include reviewing two ISP connections, selecting an appropriate SD-WAN or failover approach, preparing configuration changes, testing link behaviour, checking VPN dependencies, and documenting the final design. Customers in the United Arab Emirates, Saudi Arabia, Kuwait, Qatar, Bahrain or Oman should share the destination country, FortiGate model, FortiOS release, number of sites, ISP handoff type and expected implementation timeline. Service availability, travel or onsite coordination, licensing, vendor lead times and project scheduling can vary by country and scope. A dual WAN design should also account for country-specific ISP addressing practices and any provider restrictions. FourTeck can coordinate quotation and requirement review after the customer confirms the technical and commercial details. For regional enquiries, buyers may also use the FourTeck Kuwait resource where relevant.
Africa Availability
Organisations in Africa can contact FourTeck for FortiGate requirement review, configuration planning, license or appliance guidance where needed, and coordination of dual WAN projects. The most useful starting information is the destination country, existing FortiGate model, installed FortiOS version, number of WAN circuits, provider handoff details, public IP use, VPN dependencies, expected number of sites and the preferred project schedule. Availability and fulfilment can depend on destination, product model, quantity, license region, shipping arrangements, local power or regulatory conditions, vendor lead time and whether installation work is remote or requires local coordination. FourTeck does not assume that one configuration is suitable for every branch or country. East African customers can review FourTeck Kenya, while wider regional enquiries can use FourTeck Africa as an additional contact path for planning and quotation discussions.
Related products and services to consider
FortiGate firewall sizing
Useful when the existing appliance may not have the throughput, interface count or lifecycle position required for two links and current security inspection needs.
FortiGate SD-WAN configuration
Consider when application steering, quality-aware path selection, multi-site standards or active use of both WAN circuits is a central requirement.
FortiGate VPN resilience review
Relevant when site-to-site tunnels, remote peers or cloud VPN gateways must be assessed separately for secondary-WAN operation.
Firewall policy and NAT review
Useful when dual WAN changes interact with public services, source NAT, VIPs, application access or legacy firewall rules.
Why businesses contact FourTeck for this work
The value of configuration assistance is clarity around dependencies. A business may know it has WAN1 and WAN2 but still need help deciding whether route preference, SD-WAN, performance health checks, policy routing or a wider VPN redesign is appropriate. FourTeck can help turn that uncertainty into a defined scope by collecting the device and ISP details, identifying business-critical traffic, checking the current route and policy structure, and building a test plan around the required outcome. This is also useful for procurement teams because it separates service labour, hardware, licenses and optional onsite work instead of hiding them inside one vague line item.
Customers can request help for a single firewall or discuss a standard for multiple sites. Documentation, change planning, configuration backup, testing and handover can be included where required. The exact deliverables depend on the quotation. FourTeck does not treat an unverified lab example as a production-ready configuration; the final settings must reflect the customer’s appliance, FortiOS release, ISP arrangement and operational risk. For company background or broader technology assistance, visit about FourTeck.
Frequently asked questions
1. What is FortiGate dual WAN configuration used for?
It is used to control how a FortiGate works with two internet connections. The design can provide primary-and-backup failover, active use of both links, application-aware path selection or quality-based routing through SD-WAN, depending on the requirement and supported configuration.
2. Is SD-WAN required for two WAN links?
No. FortiGate can also use traditional routing and link monitoring for some primary-and-backup designs. SD-WAN is generally the more flexible option when both links are active, traffic needs different path preferences, or performance measurements should influence link selection.
3. Can the FortiGate fail over when an ISP is down but the WAN port still shows up?
Yes, a properly designed health-check mechanism can test reachability or link quality beyond the local interface. The monitoring method, targets and thresholds must be configured carefully so the firewall does not make decisions from misleading probe results.
4. Will users keep the same public IP after WAN failover?
Usually not when the two ISPs provide different address ranges. Outbound sessions may appear from a new public source IP, and inbound services tied to WAN1 addressing need separate planning for WAN2.
5. Does dual WAN automatically protect site-to-site VPNs?
No. VPN resilience depends on tunnel design, peer configuration, public IPs, interface bindings and routing. The remote side may also require changes. VPN failover should be included explicitly in the project scope if it is a business requirement.
6. What do you need before configuring an existing FortiGate?
Useful inputs include the FortiGate model, FortiOS version, current backup, ISP parameters, WAN addressing, topology, current routes, NAT and VIP use, VPNs, critical applications, desired path behaviour and a suitable change window.
7. Can WAN1 and WAN2 have different speeds?
Yes. Different-speed circuits can be used, but policy and expectations should reflect the capacity difference. During failover, the smaller link may require prioritisation or traffic control to keep essential applications usable.
8. How should dual WAN failover be tested?
Testing should verify health status, route changes, source IP behaviour, internet access, DNS, critical applications, VPNs where included, and recovery to the preferred link. The exact test method should be agreed so production impact remains controlled.
9. How do I request a FortiGate dual WAN quotation in Dubai?
Send FourTeck the firewall model, FortiOS version, both ISP details, current topology, required failover or SD-WAN behaviour, VPN and public-service dependencies, preferred delivery method and expected project timing. FourTeck can then scope configuration, testing and any related onsite work.
Plan the failover before changing the production firewall
Share the FortiGate model, FortiOS version, two ISP handoffs and the behaviour you want during normal operation, failure and recovery. FourTeck can review the requirement and prepare a scoped configuration quotation for Dubai, the UAE or a coordinated regional project.