Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mounirabdallah0415
New Contributor

Fortigate ADVPN dual WAN hub and spokes

I have a single hub and multiple spokes in the topology. All with dual WAN.
Branch to branch via the primary ADVPN tunnel works ok. When I fail one of the WAN links at either of the spokes, BGP fails. Spoke to hub still works ok, but spoke to spoke fails. Anyone has a similar setup working?

Mounir Abdallah
Mounir Abdallah
5 REPLIES 5
akristof
Staff
Staff

Hi,

It should be relatively easy setup. Do you have also double WAN on HUB? So you have dual overlay? If yes, then I would check all the settings and the routing on HUB when one of the branches has 1 WAN down.

Adrian
mounirabdallah0415

Thanks Adrian. Yes dual WAN on the hub.

 

So it's like this?:

 

Overlay1 (10.10.10.0/24):

spoke1/wan1->hub/wan1

spoke2/wan1->hub/wan1

 

Overlay2 (11.11.11.0/24):

spoke1/wan2->hub/wan2

spoke2/wan2->hub/wan2

 

Cheers

Mounir Abdallah
Mounir Abdallah
akristof

Hi.

In that case, my suggestion would be:

- Verify routing when wan1 on branch is down. I don't expect anything wrong with it but to be sure.

- Run ike debug when shortcut is trying to be negotiated.

There are couple possibilities. Either HUB is not even sending shortcut offer to the spokes (usually routing problem) or shortcut offer is dropped on spoke because same shortcut was already negotiated for example. But this would need more detailed investigation, so I would recommend to open support ticket to verify flow.

Adrian
FortiRookie

Just a hunch but how long is your Phase-1 interface name via 2nd ISP? Make sure it's not longer than 12 characters, If it then reduce it to 12 and clear bgp session. You can find out exact reason by turning on debug for ipsec.

mounirabdallah0415

Thanks. It's actually 12 characters

Mounir Abdallah
Mounir Abdallah
Labels
Top Kudoed Authors