Skip to main content
etamminga
New Member
January 2, 2018
Question

Please explain FortiManager VPN Star-Topology Hub-to-Hub interface

  • January 2, 2018
  • 2 replies
  • 5061 views

Hi,

Can someone please explain how FortiManager Star Toplogies work? And especially the reason for the Hub-to-Hub interface?

 

I've setup a VPN using Star Topology in FortiManager 5.6.1. FM deploys VPN Tunnels to both hubs and configures routes with prio-2 for routes at the Hub site pointing Hub-to-Hub (and vise-versa). This Hub-to-Hub tunnel is part of a vpnmgt_XXXX_mesh Zone which is not used anywhere.

 

I have my HQ network advertising RFC1918 (Private) IP ranges to my Fortigate Hubs using OSPF. The static routes configured for these VPN Hub-to-Hub interfaces are more specific. I do not want this Hub-to-Hub VPN to have a better match than my HQ network interface routes. 

 

In short; I need a detailed description on how this VPN Star Topology is supposed to work (theory). Can anyone give me a link to a document that describes the theory behind the FM manged VPN's? The online help is useless for "the theory behind", just describes individual field settings.

 

Regards,

Erik

2 replies

chall_FTNT
Staff
Staff
January 2, 2018

As for why there is a hub-to-hub tunnel in the case of multi-hub star topologies, in the more general case scenario, it cannot be assumed that the hubs have another private network connecting them together (as it sounds like yours does).

 

It sounds like you don't want static routes installed for that hub-to-hub connection.  If that is the case, you may wish to change the routing option for the hubs to be "Manual (via Device Manager)".

etamminga
etammingaAuthor
New Member
January 3, 2018

Thanks for your response.

 

Are there any "Design guides" for the FortiManager-managed-VPN options?

Regards,

Erik

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!