Skip to main content
Reshans
New Member
May 17, 2025
Question

FortiGate ADVPN Redundant tunnel traffic not working

  • May 17, 2025
  • 1 reply
  • 1142 views

I have created ADVPN in one hub and two branches with two isp. my issue is one tunnel traffic all are working but when down active tunnel and all traffic going via this tunel but my issue is branch hub connectivity ok but branch to branch not ping.

 

Please see the below.

 

topology.pngtracert with wokring traffic.pngworking with routing table.pngnot working routing.pngnot working tracert.png 

1 reply

funkylicious
SuperUser
SuperUser
May 17, 2025

from the prntscrn that you have posted, i assume that 192.168.40.0/24 is the network in spoke2 which is unreachable from spoke1.

based on the last output of the routing monitor, the route towards that destination is using the internet link of ISP1/port1 whereas before it was using the ipsec tunnel intf SP1BKTU.

 

i would look into the ipsec/bgp config for hub/spokes and see where the issue might be.

you could also have a look at https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/820072/advpn-with-bgp-as-the-routing-protocol 

"jack of all trades, master of none"
Reshans
ReshansAuthor
New Member
May 18, 2025

same bgp setting but traffic still going via int site active tunnel working fine