Description | This article describes how to configure ADVPN v2.0 on existing ADVPN v1.0 tunnels. |
Scope | FortiGate v7.4.2+. |
Solution | ADVPN v2.0 was introduced in FortiGate v7.4.2 onwards to overcome the weaknesses of ADVPN v1.0 when configured with SD-WAN. ADVPN v2.0 focuses on ADVPN 2.0 edge discovery and path management. In Edge Discovery, the following is added:
Transport Groups are added to each member under the SD-WAN configuration. Members of the same transport group can create shortcuts with each other.
config system sdwan config members config service
In cases where branches have interfaces that are not compatible to establish shortcuts like MPS and and ISP, the configuration below can be used, where all of the SD-WAN members are defined as 'transport-group's.
In Path Management, the following is added: Path selection is determined by combining local information, remote information, and the SD-WAN rule mode (sla, priority). Based on the information received from all links on other spokes, local spokes choose a path with which to create shortcuts.
To check what information is being sent by the remote Spoke, use the 'diagnose sys sdwan advpn-session' command: This command gives the following:
Note: By default, ADVPN v2.0 is disabled. This means that after upgrading to FortiOS v7.4.2, ADVPN v1.0 will continue to operate unless the ADVPN v2.0 framework is explicitly enabled. ADVPN v2.0 must be enabled per SD-WAN zone. Before migrating to ADVPN v2.0, ensure that all devices are upgraded to FortiOS v7.4.2 or later. ADVPN v1.0 and ADVPN v2.0 can coexist in a mixed environment. However, for full interoperability and to leverage the benefits of ADVPN v2.0, all participating devices should be upgraded to FortiOS v7.4.2.
Related documents: BGP overlay for ADVPN2.0 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.