Hi,
Can someone please explain how FortiManager Star Toplogies work? And especially the reason for the Hub-to-Hub interface?
I've setup a VPN using Star Topology in FortiManager 5.6.1. FM deploys VPN Tunnels to both hubs and configures routes with prio-2 for routes at the Hub site pointing Hub-to-Hub (and vise-versa). This Hub-to-Hub tunnel is part of a vpnmgt_XXXX_mesh Zone which is not used anywhere.
I have my HQ network advertising RFC1918 (Private) IP ranges to my Fortigate Hubs using OSPF. The static routes configured for these VPN Hub-to-Hub interfaces are more specific. I do not want this Hub-to-Hub VPN to have a better match than my HQ network interface routes.
In short; I need a detailed description on how this VPN Star Topology is supposed to work (theory). Can anyone give me a link to a document that describes the theory behind the FM manged VPN's? The online help is useless for "the theory behind", just describes individual field settings.
Regards,
Erik
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
As for why there is a hub-to-hub tunnel in the case of multi-hub star topologies, in the more general case scenario, it cannot be assumed that the hubs have another private network connecting them together (as it sounds like yours does).
It sounds like you don't want static routes installed for that hub-to-hub connection. If that is the case, you may wish to change the routing option for the hubs to be "Manual (via Device Manager)".
Thanks for your response.
Are there any "Design guides" for the FortiManager-managed-VPN options?
Regards,
Erik
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.