Hello everyone
example i have three spoke under same advpn, but i wanna isolate spoke A from other spoke B & C, can i do that ?
Greetings!
Yes it is possible to isolate the spoke A from other spoke by using network ID.
Please check this document: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Use-case-of-Network-Ids-with-ADVPN-shortcu...
Regards!
In that environment, if you want to use ADVPN for customers, you need to set up an ADVPN per customer/VDOM. As you said, the isolation is done by VDOM. You shouldn't/can't set up one ADVPN network across VDOM borders.
Toshi
So if we have 3 customer with multiple site, we need create 3 vdom so we have 3 as bgp for spoke to spoke communication ?
Think about those three VDOMs as three physical boxes of firewalls(or just Cisco/Juniper whatever routers terminating IPsec VPNs), which happen to be at one (your) location. Then it would be obvious what you need to do to serve/connect each customer's locations to them.
Toshi
User | Count |
---|---|
2552 | |
1356 | |
795 | |
647 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.