Skip to content
FORTIGATE / FREE PATH

Control the path. Prove the decision.

Work through FortiGate SD-WAN scenarios involving path selection, health checks, failover, routing, and application traffic.

This is the engineering problem. This is how a real engineer investigates it. This is how KiwiTut lets you practise it.

Request Access The simulator is private. Access is controlled and issued by request.

FREE PATH / FORTIGATE FOCUS / PREPARES FOR KIWITUT PRO

FGT-HQ / OPERATOR SESSIONLIVE STATE

READ THE CLI.
UNDERSTAND THE STATE.
MAKE THE CHANGE.

Diagnose the failure.
Fix the network.
Prove the recovery.
Business impact → evidence → recovery → validation
KIWITUT PRO / RECOVERY VALIDATIONREAL INTERFACE
KiwiTut Pro recovery state showing the selected path and failover validation after an SD-WAN incident
Recovery state — the selected path, the failover result, and the validation evidence.
01

SD-WAN members

Understand which interfaces and transports are available to the FortiGate path-selection system.

02

Performance SLA

Interpret latency, jitter, and packet-loss measurements against the service requirement.

03

Health checks

Use health state to determine whether a member is eligible for application traffic.

Read member state first

A path that is not a healthy member cannot carry SD-WAN traffic no matter what the rules say.
Verify with: diagnose sys sdwan member

Evidence disciplineState the expected member, cost and status before reading output – then confirm the output matches that expectation.
04

Rules and path selection

Trace classification, rule behavior, preference, cost, and the selected forwarding path.

05

Failover

Understand what changes when a member fails health criteria and another path becomes eligible.

BUSINESS IMPACTBranch users cannot reach protected services.
EXPECTED PATHPreferred member per rule.
ACTUAL PATHDegraded member still selected.
FGT-HQ # diagnose sys sdwan member
member(1): interface=wan1 status=alive
member(2): interface=wan2 status=degraded
Failover reality

Existing sessions can stick to a degraded member until they expire – failover alone does not prove user recovery.
Validate with: diagnose sys sdwan load-balance

06

Traffic validation

Prove that the application uses a usable path after failover, including routing and return traffic.

07

Routing interaction

SD-WAN does not replace routing – it feeds it. The chosen member must surface as a usable route before any rule can steer traffic.

Route dependency

The selected member installs or activates the route forwarding relies on.
Confirm with: diagnose sys sdwan routes and get router info routing-table all

Enterprise pattern

Branch-to-HQ and internet breakout both depend on this hand-off: SD-WAN chooses the egress, routing makes it reachable, policy permits it.

08

Verification checklist

  • Expected member alive in diagnose sys sdwan member
  • Rule evaluation matches intent in diagnose sys sdwan load-balance
  • Active route present in get router info routing-table all
  • End-to-end probe succeeds (execute ping)
  • Sessions survive or re-establish cleanly
Recovery proofAn incident is closed by evidence, not intention – capture each output as proof of restoration.

Related engineering paths: FortiGate VPN operations, the symptom-first troubleshooting workflow, and the CLI decision-record guide. Or browse the full FortiGate paths catalogue.

FORTIGATE LAB? THE MODEL MATTERS

Train inside KiwiTut Pro.

These public paths describe the engineering work. The real hands-on FortiGate network operations simulator is private beta at app.kiwitut.com and is available only after controlled access is approved.

ENGINEERING

KiwiTut Engineering develops practical FortiGate-focused enterprise network engineering simulation. Request Access