Hi there
I need your advice on what is the best IPsec design for our setup.
We have one HQ with dual ISP's and 14 other sites with single ISP.
Now my question is should I implement it, via static routes like here Technical Tip: Redundant IPSEC Tunnel using single WAN connection , IPSEC Aggregate or something else?
(Fortigate v7.4.9 build2829)
Thanks for your recommendation and have a nice day.
Hi
The shared tech tip is a good approach.
However using sd-wan is definitely the most flexible, effective and modern approach so far.
More traditional option is like using BGP to make one side primary and the other side a backup.
Toshi
| User | Count |
|---|---|
| 2750 | |
| 1419 | |
| 812 | |
| 740 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.