Hello folks,
Anyone can explain me what is going on and how to fix this pls!?
I just connected 2 separate sites to Fortisase using Secure Private Access.
BGP to Forti PoPs are established but the sites are not exchanging routes.
Shouldn't the 2 sites reach each other through Forticloud? This is what i'm used to in Velo Cloud and Cato.
I only have 2 sites, head office in Europe and another site in the USA.
Regards
Said
Have you looked at the BGP recursive routes yet? This is a good document that outlines some different topologies.
Thank you for the prompt response.
The BGP recursive routes only words if inter HUB routing outside Fortisase already exists.
This means that I should configure a tunnel between the 2 sites.
I was expecting that through the SPA, the 2 sites will be exchanging routes.
The only BGP routes i learn from Fortisase PoPs are FortiClient subnets and PoPs ip range.
The reason is that SASE does not advertise routes to the HUB.
SASE supports traffic between HUB and connected endpoints (SASE VPN clients), and vice versa — but not HUB-to-HUB communication.
User | Count |
---|---|
2647 | |
1405 | |
810 | |
690 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.