Created on
09-24-2023
09:23 PM
Edited on
06-30-2025
09:51 PM
By
Anthony_E
Description |
This article describes that ADVPN (Auto Discovery VPN) with SD-WAN (Software-Defined Wide Area Networking) is a powerful solution and provides methods for FortiGate ADVPN with SD-WAN. |
Scope |
FortiGate. |
Solution |
Verify the step-by-step configuration:
show vpn ipsec phase1-interface show vpn ipsec phase2-interface
show system sdwan-link-interface show system sdwan-link-load-balance
diagnose vpn ike gateway list diagnose vpn ike gateway summary diagnose vpn ike gateway info <gateway-name>
diagnose sys sdwan link list diagnose sys sdwan link info <link-name> diagnose sys sdwan link-monitor status diagnose sys sdwan link-monitor <link-name>
diagnose sys sdwan member
diagnose debug reset diagnose debug enable diagnose debug application sdwan -1 | diagnose debug application link-monitor -1 ( for real-time link monitor debugging) diagnose debug disable
Make sure that the SD-WAN and ADVPN configurations are consistent across all FortiGates. Examine the firewall for any rules or regulations that could be preventing SD-WAN or ADVPN traffic.
If there is a routing problem, follow the below steps to determine where the issue lies:
To discover and fix the problem, the erroneous route selection for traffic in ADVPN with SD-WAN requires a methodical approach utilizing commands. It will efficiently identify and fix improper route selection by using the troubleshooting procedures described in this article and the available commands.
diagnose sniffer packet <interface> <filter> 6 0 l
Determine which traffic is being misrouted. Also, monitor traffic flow and routing behavior. Form the flow debugs determine incorrect route selection might be continuous or occasional:
diagnose debug flow filter addr <Source IP | Destination IP> diagnose debug enable
get router info routing-table all
show firewall policy <----- View the configured firewall policies. show router policy <----- View the configured policy routes. diagnose firewall proute list <----- View the policy routes generated by SD-WAN rules.
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.