Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
shiryunaga
New Contributor

[ADVPN] isolate site in advpn

Hello everyone

example i have three spoke under same advpn, but i wanna isolate spoke A from other spoke B & C, can i do that ?

4 REPLIES 4
Dhruvin_patel

Greetings!

 

Yes it is possible to isolate the spoke A from other spoke by using network ID.

Please check this document: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Use-case-of-Network-Ids-with-ADVPN-shortcu...

 

Regards!

Dhruvin Patel
Toshi_Esumi
SuperUser
SuperUser

In that environment, if you want to use ADVPN for customers, you need to set up an ADVPN per customer/VDOM. As you said, the isolation is done by VDOM. You shouldn't/can't set up one ADVPN network across VDOM borders.

Toshi

shiryunaga

So if we have 3 customer with multiple site, we need create 3 vdom so we have 3 as bgp for spoke to spoke communication ?

Toshi_Esumi

Think about those three VDOMs as three physical boxes of firewalls(or just Cisco/Juniper whatever routers terminating IPsec VPNs), which happen to be at one (your) location. Then it would be obvious what you need to do to serve/connect each customer's locations to them.

Toshi

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors