I have 3 sites and connect to the datacenter using different wan connections. The simple topology is :
Site1-wan1-dc
Site2-wan2-dc
Site3-wan3-dc
With this scenario it's possible to create advpn between every site to the dc? If yes, is there any tunnel shortcut across sites?
Hi There,
Since the setup includes 3 separate WAN links at the hub, which connect to 3 different spokes, you have to heavily rely on routing(usually BGP) for shortcut to work. The complexity of this requirement is the independence of each link per spoke, which creates zero visibility of presence independent of each site. You can ease the configuration a little by using BGP on a loopback at the DC. My recommendation would be to approach a Fortinet partner or sales to achieve this requirement using the links below:
Fortinet Professional Services:
https://www.fortinet.com/support/support-services/professional-services
Fortinet local Partner:
https://www.fortinet.com/partners/partner-program/find-a-partner.html
Thanks
Yea, that's why I don't like ADVPN. Only one hub an three spokes, and three separate VPNs at hub with an individual interface. Which requires a special consultation service? I could easily (would take some planning and execution) set up a meshed network (3+2+1=6 IPSec total) with BGP manually.
Toshi
Hi Toshi, Its your call whether to use professional or partner service. Technology is great and requires expertise, which I trust you can achieve easily :)
Thanks
User | Count |
---|---|
2571 | |
1364 | |
796 | |
651 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.