Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Said7
New Contributor II

How does sites exchange routes via Fortisase?

Hello folks,

 

Anyone can explain me what is going on and how to fix this pls!?

 

I just connected 2 separate sites to Fortisase using Secure Private Access.

BGP to Forti PoPs are established but the sites are not exchanging routes.

Shouldn't the 2 sites reach each other through Forticloud? This is what i'm used to in Velo Cloud and Cato.

I only have 2 sites, head office in Europe and another site in the USA.

 

Regards

Said

2 REPLIES 2
distillednetwork
Contributor III

Have you looked at the BGP recursive routes yet?  This is a good document that outlines some different topologies.

 

https://docs.fortinet.com/document/fortisase/latest/feature-fortigate-ngfw-to-fortisase-spa-hub-conv...

::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::
::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::
Said7

Thank you for the prompt response.

 

The BGP recursive routes only words if inter HUB routing outside Fortisase already exists.

This means that I should configure a tunnel between the 2 sites.

 

I was expecting that through the SPA, the 2 sites will be exchanging routes.

The only BGP routes i learn from Fortisase PoPs are FortiClient subnets and PoPs ip range.

 

The reason is that SASE does not advertise routes to the HUB.
SASE supports traffic between HUB and connected endpoints (SASE VPN clients), and vice versa — but not HUB-to-HUB communication.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors