Skip to main content
ck8882
Explorer
June 1, 2023
Question

Is FortGiate SDWAN support ADVPN in hub to spoke, spoke to sub-spoke deployment approach

  • June 1, 2023
  • 3 replies
  • 1457 views
Hi All
 
Is it fortigate support deploy hub to spoke and spoke to sub-spoke deployment approach? on top this diagram, is it feasible support with ADVPN deployment between sub-spoke? The connection Like below
 
HUB <--> Spoke <---> multiple other site sub-spoke (ADVPN between sub-spoke)
 
thanks

3 replies

gfleming
Staff
Staff
June 1, 2023

Yes possible however you would be looking at a multi-hub / multi-region design. So the intermediate device would be considered a hub, not a spoke and would have connection/peering to the other hub and the spokes below it.

 

https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-sd-branch-architecture-for-mssps/435097/design-example-multi-regional-design

ck8882
ck8882Author
Explorer
June 1, 2023

Thanks for your information,

 

Could it be consider non standard fortinet practice design and possible won’t get fortinet support if there is issue happen since fortinet never verified the design whether is working?

 

Thanks

gfleming
Staff
Staff
June 2, 2023

As long as you configure your intermediate device as a Hub then you are all good. Just read those docs and understand the configuration for multi-hub/region deployment and go for it.

 

In your case it iwll look like this:

 

HUB1 <--> HUB2 <---> multiple other site spokes (ADVPN between HUBS and HUB2 and Spokes

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!