Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Salimco
New Contributor

ADVPN with BGP redundancy issue

Screenshot 2025-01-18 092052.png

 

i have HUB & SPOKE scenario as shown in the picture with dual WAN connections one is DIA and the Second is private WAN Microwave Network and I configured auto discovery in to WAN interfaces and all spokes can access the HUB and spokes to spokes shortcut come up and suppose the internet VPN is selected first duo to aging time in BGP table when branch1 try to access branch 3 the shortcut tunnel come up and working fine but when the internet interface come down in branch 3 in example the microwave VPN tunnel not start between the branches . how can i configure this scenario to allow fail-over shortcut VPN ?

Note the spokes to HUB fail-over working fine and no SDWAN Configured in this scenario and IBGP Multi-path and additional path is configured in all devices and the HUB playing as BGP router reflector

1 Solution
kandchka1
New Contributor

Which method are you using for ADVPN? BGP on Loopback or BGP per overlay? Depending on your setup you may need a policy route that will enforce WAN <> WAN and MWAVE <> MWAVE. As far as your MWAVE do yo have your phase1 to monitor you WAN before it comes up or is it always up?

View solution in original post

10.0.0.0.1 192.168.1.254
2 REPLIES 2
kandchka1
New Contributor

Which method are you using for ADVPN? BGP on Loopback or BGP per overlay? Depending on your setup you may need a policy route that will enforce WAN <> WAN and MWAVE <> MWAVE. As far as your MWAVE do yo have your phase1 to monitor you WAN before it comes up or is it always up?

10.0.0.0.1 192.168.1.254
Salimco

exatly that solve my problem (policy route enforcment ) same input interface to be output interface thank u very much

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors