Skip to main content
wamendoza
Explorer II
July 20, 2023
Question

ADVPN to connect all my IPsec VPNs to AWS?

  • July 20, 2023
  • 2 replies
  • 1805 views

 

hi team

Does anyone have any experience with IPsec VPNs between Fortigate and AWS?

I have a client that has IPs connected to two different peers in AWS

Now my client has a new IPs and wants to connect them to the same two peers in AWS, but AWS reports that now it needs a routing protocol like BGP for it...

Can I use ADVPN to connect all my IPsec VPNs to AWS?

2 replies

jdelafuente_FTNT
Staff & Editor
Staff & Editor
July 21, 2023

Hello wamendoza,

If remote peers have public IP; yes it is possible, but commonly ADVPN deployments are so difficult, here is some community guides for it:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-ADVPN-with-BGP-as-the-routing-protocol/ta-p/192437

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-ADVPN-and-analyzing-logs/ta-p/199965

 

Also you can register for free in https://training.fortinet.com/ and enroll in NSE7 Enterprise, there is a dedicated chapter for ADVPN.

wamendoza
wamendozaAuthor
Explorer II
July 21, 2023

Hi Jonathan, so fact, i take the idea from Nse7 advpn, but, right now i not sure if this IS the best way....

Unfortly AWS, say me i need use BGP protocol, so, you have some another ide for this one? because also i need some redundancy in each tunnel...

and thanks for answer me

Yes, is a public ip

wamendoza
wamendozaAuthor
Explorer II
July 21, 2023

Hi Jonathan, so fact, i take the idea from Nse7 advpn, but, right now i not sure if this IS the best way....

Unfortly AWS, say me i need use BGP protocol, so, you have some another ide for this one? because also i need some redundancy in each tunnel...
and thanks for answer me

 

yes, is a public ip