Skip to main content
dwear
New Member
April 2, 2018
Question

Full Mesh VPN with redundant ISPs

  • April 2, 2018
  • 9 replies
  • 12115 views

I have 4 sites, with 2 ISPs on each, and I want to create a full mesh VPN. I've tried to use the VPN manager to create the VPNs, which works awesome as long as I'm only using 1 ISP with each FG. If I go to add in the other ISP connection as another managed gateway, i get an error when installing the policy stating 33- duplicate. I'm guessing that is because the FG is duplicated, or that it is trying to VPN from ISP 1 to ISP 2 within the same FG. Anyone know how to accomplish a full mesh with dual VPNs? 

    9 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    April 2, 2018

    Full mesh itself doesn't require multiple ISPs per site. If you have 4 total sites, each needs 3 vpns (like A->B, A->C, A->D).

    Redundancy between two ISP circuits requires a failover mechanism you choose. However, VPN itself doesn't fail-over one interface to another since you need to specify the interface in the IPsec phase1-interface config. So, you would end up setting 3 x 2 vpns over two ISP interfaces exhaustively per location and change routes from the primay VPNs to the secondary VPNs either by a routing protocol or by link-monitor to remove the primary static routes when the primary interface monitor goes down.

    dwear
    dwearAuthor
    New Member
    April 3, 2018

    Thanks. Maybe my question wasn't clear. What you stated is what I already understand how to do via the Fortigates themselves. My question is, how do I accomplish that via Fortimanager and VPN manager? As we open more branches, the configuration will get exponentially more difficult. VPN Manager appears to solve that problem by simply adding the device as a managed gateway and letting it handle the tunnels. It does it easily if each site only had 1 ISP. I can't seem to get it to work with multiple ISPs at each site though, or at least I can't figure out how its supposed to be done. 

    Toshi_Esumi
    SuperUser
    SuperUser
    April 3, 2018

    I don't know anything about VPN manager. So you need to wait somebody else's reply. But I would expect much from it.

     

    But as you said, that's why mesh is not an effective topology when the number of sites get larger. By the same token iBGP, which by nature requires mesh topology, has  route-reflector concept to overcome the issues coming with larger scale installations. I recommend you consider selecting a couple or three of hub locations and connect the rest of them to those hub locations over VPNs. Hub locations should be meshed (in case three or more hubs). Since every locations including those hub locations have two ISP circuits, multiple-hub topology is reasonably redundant.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!