Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mikebutash
New Contributor

OCVPN/ADVPN and (e|i)BGP integrations

Hi all, I've got a customer with a lot of transit circuits as well as vpn redundancy configured today, but adding prefixes is pretty painful with all the fortigates.  I'm exploring using OCVPN or ADVPN along with extending BGP to the Fortigates to ease dealing with new routes and failover paths here.

 

I've ready everything I can find on OCVPN+BGP, there isn't a whole lot of detail how BGP works around it, other than the docs out there indicate it seems to use an IBGP mesh with the hubs being route reflectors.  ADVPN docs indicate using EBGP between sites, which is really what I'm looking for to use EBGP between sites in general internally vs IBGP and needing to use reflectors. I just don't know if I can leverage OCVPN and EBGP that every hub/spoke site would be a new private ASN.

 

What is the preferred method of deploying BGP with OCVPN around either of these as an upgrade/replacement for traditional prefix-based tunnels?  Is there a recommendation for/against OCVPN or ADVPN in these situations? 

 

Ideally we're moving away from circuits and more toward sdwan, so a need for real dynamic routing is at hand.  It's really just 5 sites, but a lot of prefixes, and traditional vpn today is pretty messy with phase2 exchanges.  Ideally every site and layer is EBGP to each other and between layers and as dynamic as possible.

 

Thanks in advance!

-mb
1 Solution
Anthony_E
Community Manager
Community Manager

Hello mb,

 

I found this documentation:

 

https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/820072/advpn-with-bgp-as-the-routing-pr...

 

Could you please tell me if it helps?

 

Regards,

Anthony-Fortinet Community Team.

View solution in original post

3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello mb,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello mb,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello mb,

 

I found this documentation:

 

https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/820072/advpn-with-bgp-as-the-routing-pr...

 

Could you please tell me if it helps?

 

Regards,

Anthony-Fortinet Community Team.
Top Kudoed Authors