I ADVPN with BGP and SDWAN enabled, is add route in the VPN Phase1 Interface should be enabled or diasbled?
Solved! Go to Solution.
Greetings!
In an ADVPN setup with BGP and SD-WAN enabled, the "add-route" setting in the VPN phase1 interface should be disabled. This allows BGP or another dynamic routing protocol to handle route announcements instead of IKE injecting the route.
Please refer the document: http://docs.fortinet.com/document/fortigate/7.6.3/administration-guide/820072/advpn-with-bgp-as-the-...
Best Regards!
Greetings!
In an ADVPN setup with BGP and SD-WAN enabled, the "add-route" setting in the VPN phase1 interface should be disabled. This allows BGP or another dynamic routing protocol to handle route announcements instead of IKE injecting the route.
Please refer the document: http://docs.fortinet.com/document/fortigate/7.6.3/administration-guide/820072/advpn-with-bgp-as-the-...
Best Regards!
how about 'update static route' in SDWAN, should be enabled or disabled?
Update static route should be disabled as you do not care about tearing down sessions as you are in a shared session state with just different transits.
^ may be too much info, but "update static route should be disabled"
Since you already have it set up, and if you just want to know the current config,
config vpn ipsec phase1-interface
edit [phase1-interface-name]
get | grep add-route
end
Toshi
User | Count |
---|---|
2559 | |
1356 | |
795 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.