FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Article Id 225484


This article describes the best practice for HUB in the ADVPN scenario with multiple overlays. The focus will be on HUB because ADVPN with SDWAN on HUB is not supported when this article is written.

It will be based on routing decisions of HUB which future shortcuts will be formed.




ADVPN with multiple overlays.




In this example, HUB has 2 ADVPN tunnels: advpn and advpn_b. Hub will have 2 routes for each subnet from each spoke to select.




If considering default behavior, when Spoke1 ( will send traffic to Spoke2 ( it will be received from one of the tunnels (which one, depends on the routing selection of spoke1). The outgoing route that HUB will select depends on the load-balancing algorithm, most of the time it is source-ip-based. In a normal scenario, this would be sufficient if expecting that the traffic will flow over the HUB always.


But in the ADVPN scenario, it will be expected that a shortcut will be formed. The shortcut is formed based on the incoming and outgoing interface that HUB will select. Make sure that possibility and efficiency of shortcut are always the highest.


Sometimes, it is possible to have one advpn tunnel over INET and a second over MPLS. In this case, the shortcut will not be formed, because usually it is not possible to route MPLS IPs over internet. It can also happen to have 2 different ISPs that traffic between them will work, but it can be more expensive, or traffic will have higher latency.





The result is that FortiGate will try to honor the decision of Spoke that is sending the traffic and will use the same overlay for outgoing traffic. This will achieve that if the traffic came from advpn interface, it will be forwarded via advpn.


As it is policy-route, it will need to have a valid route in the routing-table. So, in case the destination spoke has only one overlay up, advpn_b then HUB will follow routing-table. Because of this, if traffic will stay on the same overlay, the chance of a successful shortcut is higher.