Hi everyone,
I'm currently working on configuring a Dynamic VPN (DVPN) setup using FortiGate firewalls. The topology includes two main hubs and multiple spokes (branch offices). I'm trying to understand the best way to structure the VPN connections.
My question is: Is it possible to configure a single tunnel from each spoke that connects to both hubs, or is it required to set up a separate tunnel from each spoke to each hub individually https://100001.onl/
Hi Raven403,
In a dynamic VPN (dial-up VPN) setup using FortiGate firewalls, each spoke (branch office) typically needs to establish a separate tunnel to each hub
Please refer to the document below for more information:
If you have found a solution, please like and accept it to make it easily accessible to others.
Regards,
Aman
Hi, no, in Fortinet world you have to have 2 separate tunnels to 2 hubs if you want the 2nd hub to be used. It is, after all, ADVPN, not DMVPN by Cisco, it may look similar, but underlying mechanisms are completely different.
User | Count |
---|---|
2549 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.