Hi
I've deployed ADVPN in a lab before it goes into production....and it seems to be working fine.
The topology is dual HUB, with each HUB advertising different LAN subnets. The WAN is identical at all sites/spokes - Dual internet. All firewalls are in the same region
There is also a requirement for the 2 hubs to communicate over the VPN. I cant find much documentation on this when the HUBS are in the same region.
I wondered if anyone has done this before, and could sanity check the way I've done it if I share the config
Thanks
Can you explain the reasoning between having two hubs that have different LAN subnets? Are these two different data centers? Are they active-active DC? Do you have an IDC? More info would be great so we can make recommendations.
Thanks for the reply
yes active/active and totally seperate DC's....the spokes use services from both
The initial lab was just deployed as a HUB/SPOKE ADVPN SDWAN (with no Hub2Hub), following the Fortinet deployment guide almost to the letter. Tested and works ok
I then looked at sorting the Hub2Hub connection, to do that I created new PHASE1/2 interfaces on each hub and added the BGP neighbors. Not set up this particular scenario up before though so just want to ensure I'm not missing anything.
Thanks
OK so you have no IDC link between the data centers?
This might help you out:
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1112 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.