I have a single hub and multiple spokes in the topology. All with dual WAN.
Branch to branch via the primary ADVPN tunnel works ok. When I fail one of the WAN links at either of the spokes, BGP fails. Spoke to hub still works ok, but spoke to spoke fails. Anyone has a similar setup working?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
It should be relatively easy setup. Do you have also double WAN on HUB? So you have dual overlay? If yes, then I would check all the settings and the routing on HUB when one of the branches has 1 WAN down.
Thanks Adrian. Yes dual WAN on the hub.
So it's like this?:
Overlay1 (10.10.10.0/24):
spoke1/wan1->hub/wan1
spoke2/wan1->hub/wan1
Overlay2 (11.11.11.0/24):
spoke1/wan2->hub/wan2
spoke2/wan2->hub/wan2
Cheers
Hi.
In that case, my suggestion would be:
- Verify routing when wan1 on branch is down. I don't expect anything wrong with it but to be sure.
- Run ike debug when shortcut is trying to be negotiated.
There are couple possibilities. Either HUB is not even sending shortcut offer to the spokes (usually routing problem) or shortcut offer is dropped on spoke because same shortcut was already negotiated for example. But this would need more detailed investigation, so I would recommend to open support ticket to verify flow.
Just a hunch but how long is your Phase-1 interface name via 2nd ISP? Make sure it's not longer than 12 characters, If it then reduce it to 12 and clear bgp session. You can find out exact reason by turning on debug for ipsec.
Thanks. It's actually 12 characters
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.