Skip to main content
mumbles202
New Member
July 9, 2026
Question

Redundant VPNs between a pair of FGTs

  • July 9, 2026
  • 3 replies
  • 57 views

Working on a branch office to HQ redundant vpn setup.  Each location has 2 ISPs and I had planned on following this:

 

Manual redundant VPN configuration | FortiGate / FortiOS 8.0.0 | Fortinet Document Library

 

just using 2 tunnels (primary ISP to primary iSP, backup ISP to backup ISP) with static routes to force the backup tunnel over the secondary WAN at each location.  Is there any drawback to this approach?  I had considered using SD-WAN for the vpn traffic or possibly BGP but wasn’t sure if either offered a significant advantage in this situation.  The branch office has a single /23 network and HQ has only 3 or 4 networks that need to be accessible.  And the request is for the tunnels to utilize ISP1 as the primary when available.

3 replies

sjoshi
Staff
Staff
July 10, 2026

Hi ​@mumbles202 

 

I would suggest create normal site to site vpn from 2 links.

In that case both the vpn will be up and create route from both the link.

Then on the route define same AD value and use priority value to make one link as pri and other as backup

the one having higher priority will be backup link.

If you are using sdwan, you can simple do it by using sdwan rule

Thanks, Salon
mumbles202
New Member
July 10, 2026

Thanks for the feedback.  So essentially what i was saying (primary isp to primary isp, standby to standby)?  That’s what I was leaning towards as it was the most simple and perhaps most straightforward to troubleshoot.  

sjoshi
Staff
Staff
July 11, 2026

Hi ​@mumbles202 

 

You may refer below article:

Let me know if any question

Thanks, Salon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.