Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
etamminga
New Contributor

Please explain FortiManager VPN Star-Topology Hub-to-Hub interface

Hi,

Can someone please explain how FortiManager Star Toplogies work? And especially the reason for the Hub-to-Hub interface?

 

I've setup a VPN using Star Topology in FortiManager 5.6.1. FM deploys VPN Tunnels to both hubs and configures routes with prio-2 for routes at the Hub site pointing Hub-to-Hub (and vise-versa). This Hub-to-Hub tunnel is part of a vpnmgt_XXXX_mesh Zone which is not used anywhere.

 

I have my HQ network advertising RFC1918 (Private) IP ranges to my Fortigate Hubs using OSPF. The static routes configured for these VPN Hub-to-Hub interfaces are more specific. I do not want this Hub-to-Hub VPN to have a better match than my HQ network interface routes. 

 

In short; I need a detailed description on how this VPN Star Topology is supposed to work (theory). Can anyone give me a link to a document that describes the theory behind the FM manged VPN's? The online help is useless for "the theory behind", just describes individual field settings.

 

Regards,

Erik

2 REPLIES 2
chall_FTNT
Staff
Staff

As for why there is a hub-to-hub tunnel in the case of multi-hub star topologies, in the more general case scenario, it cannot be assumed that the hubs have another private network connecting them together (as it sounds like yours does).

 

It sounds like you don't want static routes installed for that hub-to-hub connection.  If that is the case, you may wish to change the routing option for the hubs to be "Manual (via Device Manager)".

Chris Hall
Fortinet Technical Support
etamminga

Thanks for your response.

 

Are there any "Design guides" for the FortiManager-managed-VPN options?

Regards,

Erik

Labels
Top Kudoed Authors