Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mnz160889
New Contributor

ADVPN - Hub2Hub query

Hi

 

I've deployed ADVPN in a lab before it goes into production....and it seems to be working fine.

 

The topology is dual HUB, with each HUB advertising different LAN subnets. The WAN is identical at all sites/spokes - Dual internet. All firewalls are in the same region

 

There is also a requirement for the 2 hubs to communicate over the VPN. I cant find much documentation on this when the HUBS are in the same region.

 

I wondered if anyone has done this before, and could sanity check the way I've done it if I share the config

 

 

Thanks

 

3 REPLIES 3
gfleming
Staff
Staff

Can you explain the reasoning between having two hubs that have different LAN subnets? Are these two different data centers? Are they active-active DC? Do you have an IDC? More info would be great so we can make recommendations.

Cheers,
Graham
Mnz160889

Thanks for the reply

 

yes active/active and totally seperate DC's....the spokes use services from both

 

The initial lab was just deployed as a HUB/SPOKE ADVPN SDWAN (with no Hub2Hub), following the Fortinet deployment guide almost to the letter. Tested and works ok

 

I then looked at sorting the Hub2Hub connection, to do that I created new PHASE1/2 interfaces on each hub and added the BGP neighbors. Not set up this particular scenario up before though so just want to ensure I'm not missing anything.  

 

Thanks

gfleming

OK so you have no IDC link between the data centers? 

 

This might help you out:

 

https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-architecture-for-enterprise/644109/multipl...

Cheers,
Graham
Labels
Top Kudoed Authors