I'm new to Fortinet gear and SDWAN so please have mercy. I'm trying to setup new gear using ADVPN and SDWAN for redundancy and load balancing. The issue is that all documentation has 2 WAN links for the hub and unfortunately we only have 1 per datacenter. Each spoke has two WAN links and we would like both to be able to pass traffic to the datacenter at the same time. I know how to just adjust the route weight on each link to have a primary and failover but we would really like to use SDWAN to have both of them work at the same time.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
One way , you could build 2vpns and then you can add these into a SDWAN zone
e.g
hub1. ISP-----------spoke1-ISP-A
hub1. ISP-----------spoke1-ISP-B
two two interfaces will be tied into a SDWAN zone
config system sdwan set status enable config zone edit "sdwan-spoke1" next end config members edit 1 set interface "spoke1-A" set zone "sdwan-spoke1" next edit 2 set interface "spoke1-B" set zone "sdwan-spoke1" next end Just remember you need routing or routes, a dynamic routing protocol would do great here. We use SPOKE for all of our spokes and private AS#Just keep in mind you can have upto 512 members in fortios 7.0 Ken Felix
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.