Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
shiryunaga
New Contributor

[ADVPN] isolate site in advpn

Hello everyone

example i have three spoke under same advpn, but i wanna isolate spoke A from other spoke B & C, can i do that ?

3 REPLIES 3
Dhruvin_patel

Greetings!

 

Yes it is possible to isolate the spoke A from other spoke by using network ID.

Please check this document: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Use-case-of-Network-Ids-with-ADVPN-shortcu...

 

Regards!

Dhruvin Patel
konikbo2
Visitor

My apologies for not clarifying but we are an MSP. We will separate our customers out to individual ports and put them into their own VDOMS so their traffic is completely isolated. If one of our customers has multiple locations we want to be able to form adjacencies to the spoke fortigates so they can have spoke to spoke communications via BGP/OSPF . We will route public IP wan blocks from our provider to said VDOMs so we can NAT their traffic and perform UTM features that the Fortigate has to offer.

Toshi_Esumi
SuperUser
SuperUser

In that environment, if you want to use ADVPN for customers, you need to set up an ADVPN per customer/VDOM. As you said, the isolation is done by VDOM. You shouldn't/can't set up one ADVPN network across VDOM borders.

Toshi

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors