Description | This article describes how to take debug in ADVPN when the shortcuts between Spokes are not established, despite the tunnel being up. |
Scope | FortiOS. |
Solution |
If the connectivity between Hub and Spoke is fine, take the IKE debugs to further analyze the details for the ADVPN shortcut.
Take the debug on spoke to collect the shortcut negotiation:
FGT SDW 1 # diagnose debug reset
diagnose vpn ike log filter mrem-addr4 x.x.x.x y.y.y.y
The above IKE debug on Spoke-1 is filtered for multiple IP addresses (mdst-addr4):
It allows capturing the shortcut negotiation between Spoke1↔Hub as well as the shortcut tunnel establishment between Spoke-1↔Spoke-2. Now trigger the shortcut by sending traffic from the Spoke-1 source to the Spoke-2 destination.
Wait for 15 seconds and then stop debug with the help of the below command:
diagnose debug reset |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.