I'm new to configuring sdwan with bgp, I've worked on both separately very well but have found it difficult to integrate them together. The scenario is as follows:
I want SDWAN communication between 2 Fortigate with 4 site to site ipsec VPNs and BGP routing. Neither of the 2 is hub or spoke so the ADVPN functionality I think does not fit in my scheme. Basically it would be a SPOKE-SPOKE or HUB-HUB communication if we see it in some way.
FGT 1 -------- 4 VPN in SDWAN --------------- FGT2
The idea is that it works as it does with static routing; when a link is degraded by packet loss it switches to the next link and vice versa when the primary link improves it returns the traffic.
I have tried to follow the guide below:
https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-self-healing-with-bgp/559415/overview
But most of the documentation you find refers to HUB-SPOKE or ADVPN. I have tried to make adjustments to make it HUB-HUB but the configuration has not worked for me.
Does anyone have any recommendations or guidelines?
Hi @sirma504 ,
To achieve this requirement, we may need to refer couple of documents. There may not be a single document that fully explain each detail step.
Firstly, regarding to the 4 site-to-site IPsec tunnels and BGP routing, we can follow below document:
Then, to add each IPsec tunnel interface to the SDWAN zone, we can follow below document:
Further more, for the SDWAN outgoing interface selection based on the packet loss, we can use the strategy of 'Best Quality' in the SDWAN rule as mentioned below:
https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/22371/best-quality-strategy
Regards,
George
User | Count |
---|---|
2627 | |
1400 | |
810 | |
672 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.