Good morning,
I am having a problem with an ADVPN using IPsec tunnels.
I have a hub-and-spoke setup, and at my branch office, I have two IPsec tunnels that communicate with the hub using the ADVPN BGP routing protocol.
When my branch office’s spoke-1 degrades, BGP routing doesn’t detect the failure in the SLA performance configured in the SD-WAN, where both tunnels (spoke-1 and spoke-2) are located, and it continues routing through the degraded spoke-1.
Has anyone else experienced this issue?
In the SD-WAN SLA configuration, I have disabled the static route update.
Hello Igor_Ribeiro,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
User | Count |
---|---|
2593 | |
1382 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.