Hello Everyone,
I am looking into how to connect several sites to each other, who all have a primary broadband WAN connection and a 5G backup WAN connection, all with static IPs. Our current site-to-site connections are only configured to use one WAN connection on each end, so when the office broadband connection goes down on occasion, the office has internet access via the 5G but no VPN access because it is configured for the single interface. There seem to be multiple paths i could take here and none of them seem as simple as i thought they would be.
Our network mainly consists of all Fortigate devices. F40s, 60Fs, a 61F, a 71F, and some 81Fs at our two data centers.
Approximately 15 of our sites, including our data centers, LANs are already connected to eachother via L3VPN managed by Windstream, connected to their SDWAN solution, VeloCloud, and routed to eachother via BGP.
The other 15 sites are not on any kind of managed SDWAN solution at this time. Each site has a primary broadband WAN connection, and a backup 5G connection. They are currently setup to connect to our data center via IPSEC site-to-site at our main data center, 81F-ColoPrimary. The problem we want to solve is when their primary broadband connection goes down, is to stay connected to our data centers.
Our goal is:
So i found this tech tip article and started going through it on our test Fortigate-Test. https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-IPsec-VPN-with-SD-WAN/ta-p/20984...
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
@Cogency
Thanks for your query.
Actually, i suspect support will give you design advices, because it requires changes in your infrastructure.
Based on your requirements, you are in need for ADVPN with SDWAN.
Please check this link as it has some good configuration examples.
ADVPN and shortcut paths | FortiGate / FortiOS 7.4.1 | Fortinet Document Library
Regards,
@Cogency
Thanks for your query.
Actually, i suspect support will give you design advices, because it requires changes in your infrastructure.
Based on your requirements, you are in need for ADVPN with SDWAN.
Please check this link as it has some good configuration examples.
ADVPN and shortcut paths | FortiGate / FortiOS 7.4.1 | Fortinet Document Library
Regards,
Sorry for the very late reply, but thank you for the advice.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1632 | |
1063 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.