Skip to main content
mounirabdallah0415
Visitor III
June 21, 2022
Question

Fortigate ADVPN dual WAN hub and spokes

  • June 21, 2022
  • 1 reply
  • 3887 views

I have a single hub and multiple spokes in the topology. All with dual WAN.
Branch to branch via the primary ADVPN tunnel works ok. When I fail one of the WAN links at either of the spokes, BGP fails. Spoke to hub still works ok, but spoke to spoke fails. Anyone has a similar setup working?

1 reply

akristof
Staff
Staff
June 22, 2022

Hi,

It should be relatively easy setup. Do you have also double WAN on HUB? So you have dual overlay? If yes, then I would check all the settings and the routing on HUB when one of the branches has 1 WAN down.

mounirabdallah0415
Visitor III
June 22, 2022

Thanks Adrian. Yes dual WAN on the hub.

 

So it's like this?:

 

Overlay1 (10.10.10.0/24):

spoke1/wan1->hub/wan1

spoke2/wan1->hub/wan1

 

Overlay2 (11.11.11.0/24):

spoke1/wan2->hub/wan2

spoke2/wan2->hub/wan2

 

Cheers

akristof
Staff
Staff
June 22, 2022

Hi.

In that case, my suggestion would be:

- Verify routing when wan1 on branch is down. I don't expect anything wrong with it but to be sure.

- Run ike debug when shortcut is trying to be negotiated.

There are couple possibilities. Either HUB is not even sending shortcut offer to the spokes (usually routing problem) or shortcut offer is dropped on spoke because same shortcut was already negotiated for example. But this would need more detailed investigation, so I would recommend to open support ticket to verify flow.