Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BusinessUser
Contributor

2 Ipsec site to site tunnel to the same location

FW1 has ISP1 connected to FW2 ISP3

FW1 has ISP2 connected to FW2 ISP3.

FW1 ISP1 and ISP2 are configured as SDWAN interfaces.

Will this design work?

 

SO when FW2 wants to go to FW1, how does it choose to go to FW1?

Which one will be given priority? 

7 REPLIES 7
pmudgal
Staff
Staff

Hello,

 

Thank you for contacting Fortinet support, you can refer the below KB in order to understand how to configure it.

 

REF:https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-IPsec-VPN-with-SD-WAN/ta-p/20984...

REF: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-bond-2-ISP-with-SD-WAN-and-load-bal...

 

Above documents support the way you want to configure your network.

 

Best Regards,

Piyush

BusinessUser

Excellent reply but I have another question.

What if:

FW1 has ISP1 connected to FW2 ISP3

FW1 has ISP2 connected to FW2 ISP3.

FW1 ISP1 and ISP2 are not SDWAN.

What will be the route selection practice then?

hbac

Hi @BusinessUser,

 

If you are not using SDWAN, you need to create separate static routes for each tunnel. You can give those routes and same distance but different priorities. 

 

If you want to control what traffic should go through which tunnel, you can use policy routes. 

 

Regards, 

Shashwati

Thank you for contacting Fortinet support, please refer the below KB in order to understand redundant IPSec tunnel configuration.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Redundant-IPSEC-Tunnel-using-single-WAN-co...

nfored
New Contributor II

can I piggyback and ask if this provides more granular  control then just using link-monitor? I have always used link monitor for ipsec tunnels redundancy and sdwan for wan redundancy 

sw2090
Honored Contributor

if you are not using sdwan for the ipsec itself the answer is simple: you :)

In this cave you have to have redundant routing with prio and distance set the way you want the VPNs to be used. It will then primarily use the one that has the lowest routing prio. If they have the same prio it will chose the lowest distance. If that tunnel goes down it will switch over to the other one.

Did that with numerous IPSec S2S Tunnels for years. Meanwhile I switched over to sdwan vpn because that only needs one route and sdwan does the rest then ;)

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
sw2090
Honored Contributor

oh probably I should mention that sdwan vpn was introduced with FortiOS 7.0.x. So it is not supported in older FortiOSes. Just fyi...

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors