I configured three firewalls, with the HUB using a dial-up. One SPOKE can communicate normally with the HUB. However, after adding another SPOKE, although the IPSEC VPN tunnel was successfully established, the HUB's tunnel IP cannot be pinged. Could you please help identify what the issue might be? Thanks
Dear 52000cc,
When the second spoke is connect, are you able do an ICMP between both spokes? From second spoke, can you ping the HUB?
IP addresses on the spokes VPN tunnel interface are assigned manually or with mode-config, range?
Please check the KB bellow :
Make sure the following:
- Route-reflector-client is enabled only on the HUB;
- Advertise connected network is disabled under BGP routing protocol for this ADVPN ;
- Run a sniffer on the HUB and affected spoke like : diagnose sniffer packet any " host x.x.x.x and icmp" 4 , where x.x.x.x is the HUBs IP address
Best regards,
Fortinet.
how can I setup this Advertise connected network is disabled under BGP routing protocol for this ADVPN?
Is the tunnel IP advertised in the IPsec?
User | Count |
---|---|
2546 | |
1354 | |
795 | |
643 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.