Skip to main content
islam_nadim
New Member
July 20, 2023
Solved

Hub and Spoke Topology Not Working as Expected

  • July 20, 2023
  • 13 replies
  • 11098 views

Hello,

 

I've built a Hub-and-Spoke lab as I need to deploy SD-WAN, which is my ultimate goal here. The configuration went smooth with no issues I can remember. However, after the configuration is complete, and BGP is up, the spokes are not able to reach each other. I tried troubleshooting, and found that the Hub is not passing the traffic. Below is my topology on EVE/PNet

 

Topology.png

 

I'm not sure where the issue is. But the firewalls doesn't pass the traffic through the tunnels!

 

I need to get SD-WAN fully running here.

 

All 3 firewalls are running the same version: FortiOS-VM64-KVM v7.2.4,build1396,23013 (GA.F).

 

For the IPSec Tunnels, I created the tunnels using the wizard using the Hub-and-Spoke Template

 

I'm really not sure what is missing here.

Best answer by islam_nadim

Hello @mauromarme ,

 

I've got it to work in Hub-and-Spoke deployment after I changed the image I was using.

 

Seems that the FOS Image doesn't pass traffic. I changed to the FGT with trial license, and it worked with me. Time to work on the SD-WAN and see the outcome. It might take some time to work on it.

13 replies

mauromarme
Staff
Staff
July 20, 2023

Hello Islam,

Hoping you are doing well.
Could you please attach the FortiGate configuration files along with the BGP commands below?
get router info bgp summary -> This command will display your BGP neighbors IP. Use those IPs on the commands below.
get router info bgp neighbors x.x.x.x advertised-routes
get router info bgp neighbors x.x.x.x received-routes

Thanks!


npariyar
Staff
Staff
July 21, 2023

Hello Islam,

 

Did you create a firewall policy for spoke-to-spoke communication?

 

Eg:

edit 0
set name "spoke2spoke"
set srcintf "advpn-hub"
set dstintf "advpn-hub"
set srcaddr "all"
set dstaddr "all"
set action accept
set schedule "always"
set service "ALL"
next
end

 

You can follow the below article for ADVPN with BGP as the routing protocol.

https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/820072/advpn-with-bgp-as-the-routing-protocol

 

Regards

Niroj Pariyar

 

islam_nadim
New Member
July 21, 2023

Hello @npariyar ,

 

I do have the policy in place. It is created automatically via the VPN Wizard

 

    edit 2         set name "vpn_Hub-Spoke_spoke2spoke_0"         set uuid f20a5d8c-2676-51ee-12b6-2c70588442df         set srcintf "Hub-Spoke"         set dstintf "Hub-Spoke"         set action accept         set srcaddr "all"         set dstaddr "all"         set schedule "always"         set service "ALL"         set logtraffic all         set comments "VPN: Hub-Spoke (Created by VPN wizard)"     next
Contributor III
July 25, 2023

 

Hi @islam_nadim ,

That was a clear network design.

When you created a VPN on the HUB, there is an options to create a spoke.
Each spoke will have unique code. You just need to apply this code to each spoke respectively.
Do not use same code for all spoke.

Else, you may need to verify interface and BGP configuration and do manual changes.

islam_nadim
New Member
July 26, 2023

Hi @Anonymous ,

I've already built the Hub and Spoke using the wizard but for some reason it is not working.

Contributor III
July 27, 2023

hi @islam_nadim ,

Do you mind to share you HUB VPN configuration screenshot?

islam_nadim
New Member
July 26, 2023

Hi @balbasorus ,

I've already built the Hub and Spoke using the wizard but for some reason it is not working.

Nebula1
Explorer
December 19, 2023

First of all if you are thinking happened config failed:
I think you should check this all steps again,
1- How did you do ipsec tunnel for hub and spoke devices:
Is these true ? tunnel ip address, local subnets, and AS numbers.
2- Is it true interfaces of devices (wan port) and wan ip address for tunnels.
3- Spoke devices should announce networks (local subnets) with BGP.
4- You can check on BGP portal , can you see neighbors? you should see ip address and remote AS of spokes. ( maybe it didnthappen)

islam_nadim
New Member
December 19, 2023

Hi, configuration is correct. BGP is running fine .. The issue was in the image of the Fortigate itself. After changing it, everything worked as expected.

syeedkazmi
New Member
August 21, 2024

Hi All,

I have the same issue where Hub is able to have communication with Spokes and vise versa but Spoke to Spoke communication is not working. when checked the routes on Spoke is not available for other sopke only routes of Hub is advertised.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!