Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
52000cc
New Contributor

ADVPN hub-and-spoke

I configured three firewalls, with the HUB using a dial-up. One SPOKE can communicate normally with the HUB. However, after adding another SPOKE, although the IPSEC VPN tunnel was successfully established, the HUB's tunnel IP cannot be pinged. Could you please help identify what the issue might be? Thanks

3 REPLIES 3
syordanov
Staff
Staff

Dear 52000cc,

When the second spoke is connect, are you able do an ICMP between both spokes? From second spoke, can you ping the HUB?

IP addresses on the spokes VPN tunnel interface are assigned manually or with mode-config, range?
Please check the KB bellow :

https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/820072/advpn-with-bgp-as-the-routing-pro...

Make sure the following:
- Route-reflector-client is enabled only on the HUB;
- Advertise connected network is disabled under BGP routing protocol for this ADVPN ;
- Run a sniffer on the HUB and affected spoke like : diagnose sniffer packet any " host x.x.x.x and icmp" 4 , where x.x.x.x is the HUBs IP address

Best regards,
Fortinet.

.
52000cc

how can I setup this Advertise connected network is disabled under BGP routing protocol for this ADVPN?

 

VinayHM
Staff
Staff

Is the tunnel IP advertised in the IPsec?

Vinay HM
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors