Skip to main content
LCIT
Visitor III
January 26, 2024
Question

SD-WAN VPN to multiple locations with multiple ISPs

  • January 26, 2024
  • 2 replies
  • 4764 views

I'm working on learning the capabilities of the FortiNet SD-WAN features.  Using this guide https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-IPsec-VPN-with-SD-WAN/ta-p/209840 I've been able to connect SiteA and SiteB, each with multiple ISPs.  The SD-WAN features are working correctly and I'm quite happy with the setup.  Now I'm bringing SiteC into the picture.  SiteC's setup should be no different than SiteB really.  The question is at SiteA.  When I'm setting up the SD-WAN zone for connections between SiteA and SiteC, do I put the connections under the same zone that's used to connect SiteA and SiteB?  Or would I want to create a completely different Zone? 

 

Background, big picture, end game, if it makes any difference, is Hub & Spoke but then enabling the Route Reflection (I believe it's called) so that SiteB and SiteC can talk directly together without all their traffic going through SiteA. 

2 replies

hbac
Staff
Staff
January 26, 2024

Hi @LCIT,

 

If site B and site C are redundant (same internal network), you can put IPsec interfaces in the same zone in site A. But I don't think that is the case for your scenario.

 

It is better to put IPsec interfaces for site B and site C in separate SDWAN zone on site A. For hub and spoke, please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-SD-WAN-support-for-ADVPN/ta-p/189490

 

Regards, 

LCIT
LCITAuthor
Visitor III
January 26, 2024

SiteB and SiteC are separate networks, 192.168.2.0/24 and 192.168.3.0/24.  So on SiteA they should be 2 different SDWAN zones.  Is that because of routing? 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!