Want to route traffic from a Spoke2 (Site2) which is connected to Spoke1 via point to point link. Spoke1 connect to Hub via ISP link. Currently Spoke 2 uses dynamic routing on the underlay to exchange networks with spoke1. Is there a way to create a overlay tunnel using SDWAN on this scenario from Spoke2 towards hub? any reference material is appreciated.
look into ADVPN and treat Spoke1 as a pseudo-hub for the topology.
| Hub1/2 |<----underlay ebgp----> | Spoke1 |<----ospf----> | Spoke2 |<----underlay ospf----> | Spoke3 |<---underlay bgp---> | Hub1/2 |
+-----------+
Spoke1 is required to carry traffic from spoke 2 and spoke3 towards hub1/2
Spoke 3 has to act as failover for spoke 1. We can have 2 overlay one at spoke1 and spoke3 but i cant figureout how to route
Spoke2 to hub (there is no requirement to send traffic b/w spokes. Only hub and spoke traffic)
Created on 12-13-2025 06:14 AM Edited on 12-13-2025 06:15 AM
i would start reading these and maybe it helps , https://docs.fortinet.com/document/fortigate/7.6.0/sd-wan-sd-branch-architecture-for-mssps/445259/in... or https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/391857/overlay and plan it according to your needs/design.
Created on 12-13-2025 02:45 PM Edited on 12-13-2025 02:46 PM
Thanks I have gone through some of the documentation and unfortunately the scenario is a bit unique. Standard sdwan configuration without connecting to hub directly is not possible and advpn is used when spoke to spoke shortcuts required that is also not the case here. I was thinking if below is a possible solution to configure an ipsec tunnel over ipsec tunnel towards hub with a different localid
| User | Count |
|---|---|
| 2842 | |
| 1436 | |
| 812 | |
| 803 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.