Redundant VPNs between a pair of FGTs
Working on a branch office to HQ redundant vpn setup. Each location has 2 ISPs and I had planned on following this:
Â
Manual redundant VPN configuration | FortiGate / FortiOS 8.0.0 | Fortinet Document Library
Â
just using 2 tunnels (primary ISP to primary iSP, backup ISP to backup ISP) with static routes to force the backup tunnel over the secondary WAN at each location. Is there any drawback to this approach? I had considered using SD-WAN for the vpn traffic or possibly BGP but wasn’t sure if either offered a significant advantage in this situation. The branch office has a single /23 network and HQ has only 3 or 4 networks that need to be accessible. And the request is for the tunnels to utilize ISP1 as the primary when available.
