We are currently facing an issue in our ADVPN setup. Whenever the hub firewall goes down, the following problems occur:
BGP sessions drop and all routes are withdrawn.
Spoke-to-spoke shortcut tunnels remain in the UP state, however spoke-to-spoke communication does not work.
Our expectation from ADVPN was that spoke-to-spoke tunnels should continue to operate even if the hub is unavailable. However, in our case everything depends on the hub.
Could you please confirm if this is a design limitation or if there is a configuration/workaround to maintain BGP routes and spoke-to-spoke communication independently of the hub? Kindly guide us with the best practice solution.
Ensure the auto-discovery-shortcuts setting is independent: https://community.fortinet.com/t5/FortiGate/Technical-Tip-ADVPN-shortcut-tunnels-has-multiple-IPs-wh...
Autodiscovery is set independent still facing same issue
User | Count |
---|---|
2548 | |
1354 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.