Skip to main content
BusinessUser
Explorer
January 24, 2024
Question

2 Ipsec site to site tunnel to the same location

  • January 24, 2024
  • 7 replies
  • 2975 views

FW1 has ISP1 connected to FW2 ISP3

FW1 has ISP2 connected to FW2 ISP3.

FW1 ISP1 and ISP2 are configured as SDWAN interfaces.

Will this design work?

 

SO when FW2 wants to go to FW1, how does it choose to go to FW1?

Which one will be given priority? 

7 replies

pmudgal
Staff
Staff
January 24, 2024

Hello,

 

Thank you for contacting Fortinet support, you can refer the below KB in order to understand how to configure it.

 

REF:https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-IPsec-VPN-with-SD-WAN/ta-p/209840

REF: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-bond-2-ISP-with-SD-WAN-and-load-balance/ta-p/248772

 

Above documents support the way you want to configure your network.

 

Best Regards,

Piyush

BusinessUser
Explorer
January 25, 2024

Excellent reply but I have another question.

What if:

FW1 has ISP1 connected to FW2 ISP3

FW1 has ISP2 connected to FW2 ISP3.

FW1 ISP1 and ISP2 are not SDWAN.

What will be the route selection practice then?

hbac
Staff
Staff
January 25, 2024

Hi @BusinessUser,

 

If you are not using SDWAN, you need to create separate static routes for each tunnel. You can give those routes and same distance but different priorities. 

 

If you want to control what traffic should go through which tunnel, you can use policy routes. 

 

Regards, 

nfored
New Member
January 25, 2024

can I piggyback and ask if this provides more granular  control then just using link-monitor? I have always used link monitor for ipsec tunnels redundancy and sdwan for wan redundancy 

sw2090
SuperUser
SuperUser
January 25, 2024

if you are not using sdwan for the ipsec itself the answer is simple: you :)

In this cave you have to have redundant routing with prio and distance set the way you want the VPNs to be used. It will then primarily use the one that has the lowest routing prio. If they have the same prio it will chose the lowest distance. If that tunnel goes down it will switch over to the other one.

Did that with numerous IPSec S2S Tunnels for years. Meanwhile I switched over to sdwan vpn because that only needs one route and sdwan does the rest then ;)

sw2090
SuperUser
SuperUser
January 25, 2024

oh probably I should mention that sdwan vpn was introduced with FortiOS 7.0.x. So it is not supported in older FortiOSes. Just fyi...

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!