i have HUB & SPOKE scenario as shown in the picture with dual WAN connections one is DIA and the Second is private WAN Microwave Network and I configured auto discovery in to WAN interfaces and all spokes can access the HUB and spokes to spokes shortcut come up and suppose the internet VPN is selected first duo to aging time in BGP table when branch1 try to access branch 3 the shortcut tunnel come up and working fine but when the internet interface come down in branch 3 in example the microwave VPN tunnel not start between the branches . how can i configure this scenario to allow fail-over shortcut VPN ?
Note the spokes to HUB fail-over working fine and no SDWAN Configured in this scenario and IBGP Multi-path and additional path is configured in all devices and the HUB playing as BGP router reflector
Solved! Go to Solution.
Which method are you using for ADVPN? BGP on Loopback or BGP per overlay? Depending on your setup you may need a policy route that will enforce WAN <> WAN and MWAVE <> MWAVE. As far as your MWAVE do yo have your phase1 to monitor you WAN before it comes up or is it always up?
Which method are you using for ADVPN? BGP on Loopback or BGP per overlay? Depending on your setup you may need a policy route that will enforce WAN <> WAN and MWAVE <> MWAVE. As far as your MWAVE do yo have your phase1 to monitor you WAN before it comes up or is it always up?
exatly that solve my problem (policy route enforcment ) same input interface to be output interface thank u very much
User | Count |
---|---|
2559 | |
1357 | |
795 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.