Skip to main content
Igor_Ribeiro
New Member
September 16, 2025
Question

ADVPN + BGP + SDWAN

  • September 16, 2025
  • 3 replies
  • 490 views

Good morning,

I am having a problem with an ADVPN using IPsec tunnels.

I have a hub-and-spoke setup, and at my branch office, I have two IPsec tunnels that communicate with the hub using the ADVPN BGP routing protocol.

When my branch office’s spoke-1 degrades, BGP routing doesn’t detect the failure in the SLA performance configured in the SD-WAN, where both tunnels (spoke-1 and spoke-2) are located, and it continues routing through the degraded spoke-1.

Has anyone else experienced this issue?

In the SD-WAN SLA configuration, I have disabled the static route update.

3 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
September 19, 2025

Hello Igor_Ribeiro, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Staff & Editor
Staff & Editor
September 22, 2025

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
funkylicious
SuperUser
SuperUser
September 22, 2025

hi,

have you implemented a extra config for BGP similar with the one described https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-self-healing-with-bgp/559415/overview ?

 

"jack of all trades, master of none"
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!