Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Aghiles
New Contributor

DMVPN: Fortigate as HUB and Cisco Routers as Scope

Hi,

 

One of my customers want to replace his Cisco Router, configured as DMVPN Hub, with a fortigate 1000D firewall.

The cisco Router is used to create VPNs with other cisco router, in the spoc sites.

 

Do Fortigate support DMVPN and is there a way to make this configuration running without replacing the cisco routers on the spoc sites.

 

Best regards 

3 REPLIES 3
ede_pfau
SuperUser
SuperUser

DMVPN is Cisco proprietary and is not supported in FortiOS.

As far as I understand the (Wikipedia article about) DMVPN it is hub-and-spoke, but at the same time fully meshed, using dynamic routing and a lot of other stuff. I'd think you could build that with Fortigates but with conventional means only, meaning, a lot of effort.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
hubertzw
Contributor III

Auto Discovery VPN (ADVPN) is a Fortinet proprietary protocol. This is pretty much the same concept as DMVPN but available only on FortiGates:

 

https://kb.fortinet.com/kb/documentLink.do?externalID=FD39360

 

gahlberg

ADVPN is not a Fortinet proprietary protocol, it is a standard RFC from back in 2013 written by HP and Juniper Networks, see: https://datatracker.ietf.org/doc/html/rfc7018 

However, the implementation of the ADVPN Standard on FortiOS only works with Fortinet devices, but by no means is ADVPN in a general sense proprietary.  Back when ADVPN was being developed (at the sametime) Cisco was pushing DMVPN to become a standard, but it never made it to that stage, and ADVPN won out.  Cisco's DMVPN only made it to the draft stage and never made it to a published RFC.  DMVPN is therefore only proprietary to Cisco and has several drawbacks in comparison to ADVPN, like the additional overhead of GRE and NHRP, as an example.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors