Skip to main content
jdsauer77
New Member
November 19, 2024
Question

SD-WAN(ish) design

  • November 19, 2024
  • 7 replies
  • 2649 views

Question regarding some Hub and Spoke SD-WAN configuration thoughts.

Hub - Single ISP, MPLS to remote spokes.

Spokes - 2 ISP + MPLS to main Hub.

Thought... Dynamic VPN from Spokes to Hub that utilize either ISP if the MPLS is down.

Question... is this possible?

Secondary question, is this possible if a secondary Hub is available that has access to the main Hub via MPLS/Direct connection?

So, with that out of the way I have the following scenario:

Hub1 - Single Internet Connection, Single MPLS connection.

Hub2 - Single Internet Connection, Single MPLS connection to Hub1.

Spokes - 1 or 2 ISP Connections, 1 or 0 MPLS to Hub1.

I want to set up spokes that can use a dynamic VPN to Hub1 if their MPLS connection fails, but the spoke has 2 internet connections. I would prefer to only have 1 VPN tunnel to configure, meaning that if WAN1 or WAN2 in the SD-WAN configuration is down, it won't matter as it would use the connection that is up to build the tunnel using a Dynamic tunnel configuration.

 

Is this type of configuration even possible? If so, how would you do it with FortiManager, which seems to think that every public or MPLS connection should use it's own tunnel. With the option of moving the external connections to dynamic IP Addresses to avoid static IP addressing costs, I'd just like to setup one tunnel that would utilize either WAN1 or WAN2, depending which one is up when the MPLS fails, with full BGP routing, OSPF routing, or whatever other option makes the most sense.

7 replies

Anthony_E
Staff
Staff
November 22, 2024

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
Jean-Philippe_P
Staff & Editor
Staff & Editor
November 25, 2024

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Staff & Editor
Staff & Editor
November 27, 2024

Hello,

 

@vraev @heng @iyotov @jasonhong @bboudjema Has someone an idea of what to do please?

 

Thanks a lot as always :)

Jean-Philippe - Fortinet Community Team
Anthony_E
Staff
Staff
December 3, 2024

Hi,

 

Could you please open a TAC ticket and request help to our engineers?

https://support.fortinet.com/welcome/#/

 

Regards,

Best Regards
sjoshi
Staff
Staff
December 3, 2024

Hi,

 

To achieve dynamic VPN failover from spokes to hub1 using either ISP if MPLS is down, you can configure SD-WAN with dynamic tunnels on the FortiGate devices. You can set up a single tunnel that dynamically selects the available WAN interface for the VPN connection based on availability. FortiManager may require more manual configuration for this setup, ensuring proper routing protocols like BGP or OSPF are in place for dynamic routing. This configuration allows for seamless failover and optimal utilization of available connections.

Thanks, Salon
jdsauer77
jdsauer77Author
New Member
December 11, 2024

Apologies for the delay in responding, but thank you. I think this is what I was trying to confirm. I don't see a way in the FGT GUI to do this, but when building a dynamic tunnel in FMG I do see that it asks what interfaces to use. I would assume that this is what I need to do for this to work?

I would be using a loopback interface for the BGP routing, which is already being done via the MPLS connection, correct?

Anthony_E
Staff
Staff
December 4, 2024

Thank you Salon!

Best Regards
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!