Created on
11-18-2025
02:31 AM
Edited on
11-18-2025
02:34 AM
By
Jean-Philippe_P
| Description |
The article illustrates a dual-hub ADVPN topology. The key feature being demonstrated is that multiple independent shortcut tunnels can exist between the same pair of spokes. |
| Scope | FortiGate, ADVPN. |
| Solution |
ADVPN implementation allows multiple concurrent shortcut tunnels between the same pair of spokes as long as they are negotiated over different hub gateways. Each shortcut has its own independent lifetime and is not tied to the continued existence of the original parent tunnel that triggered it.
Refer to the diagram and sequence of events:
For the second shortcut to be created, it is needed to differentiate between the overlays by setting a network ID on each of them.
config vpn ipsec phase1-interface
After setting a different network ID on each overlay (both HUB and spoke side), both shortcuts can now be established at the same time. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.