Yes possible however you would be looking at a multi-hub / multi-region design. So the intermediate device would be considered a hub, not a spoke and would have connection/peering to the other hub and the spokes below it.
Thanks for your information,
Could it be consider non standard fortinet practice design and possible won’t get fortinet support if there is issue happen since fortinet never verified the design whether is working?
Thanks
As long as you configure your intermediate device as a Hub then you are all good. Just read those docs and understand the configuration for multi-hub/region deployment and go for it.
In your case it iwll look like this:
HUB1 <--> HUB2 <---> multiple other site spokes (ADVPN between HUBS and HUB2 and Spokes
User | Count |
---|---|
2119 | |
1187 | |
770 | |
451 | |
345 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.