Hi,
One of my customers want to replace his Cisco Router, configured as DMVPN Hub, with a fortigate 1000D firewall.
The cisco Router is used to create VPNs with other cisco router, in the spoc sites.
Do Fortigate support DMVPN and is there a way to make this configuration running without replacing the cisco routers on the spoc sites.
Best regards
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
DMVPN is Cisco proprietary and is not supported in FortiOS.
As far as I understand the (Wikipedia article about) DMVPN it is hub-and-spoke, but at the same time fully meshed, using dynamic routing and a lot of other stuff. I'd think you could build that with Fortigates but with conventional means only, meaning, a lot of effort.
Auto Discovery VPN (ADVPN) is a Fortinet proprietary protocol. This is pretty much the same concept as DMVPN but available only on FortiGates:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD39360
Created on 07-20-2024 07:16 PM Edited on 07-20-2024 07:20 PM
ADVPN is not a Fortinet proprietary protocol, it is a standard RFC from back in 2013 written by HP and Juniper Networks, see: https://datatracker.ietf.org/doc/html/rfc7018
However, the implementation of the ADVPN Standard on FortiOS only works with Fortinet devices, but by no means is ADVPN in a general sense proprietary. Back when ADVPN was being developed (at the sametime) Cisco was pushing DMVPN to become a standard, but it never made it to that stage, and ADVPN won out. Cisco's DMVPN only made it to the draft stage and never made it to a published RFC. DMVPN is therefore only proprietary to Cisco and has several drawbacks in comparison to ADVPN, like the additional overhead of GRE and NHRP, as an example.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.