Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FaraJawa
New Contributor

Routing Spoke traffic with no direct connection to hub

Want to route traffic from a Spoke2 (Site2) which is connected to Spoke1 via point to point link. Spoke1 connect to Hub via ISP link. Currently Spoke 2 uses dynamic routing on the underlay to exchange networks with spoke1. Is there a way to create a overlay tunnel using SDWAN on  this scenario from Spoke2 towards hub? any reference material is appreciated.  

4 REPLIES 4
funkylicious
SuperUser
SuperUser

look into ADVPN and treat Spoke1 as a pseudo-hub for the topology.

"jack of all trades, master of none"
"jack of all trades, master of none"
FaraJawa

| Hub1/2 |<----underlay ebgp----> | Spoke1 |<----ospf----> | Spoke2 |<----underlay ospf----> | Spoke3 |<---underlay bgp---> | Hub1/2 |

+-----------+ 

Spoke1 is required to carry traffic from spoke 2 and spoke3 towards hub1/2 

Spoke 3 has to act as failover for spoke 1. We can have 2 overlay one at spoke1 and spoke3 but i cant figureout how to route

Spoke2 to hub (there is no requirement to send traffic b/w spokes. Only hub and spoke traffic) 

funkylicious

i would start reading these and maybe it helps , https://docs.fortinet.com/document/fortigate/7.6.0/sd-wan-sd-branch-architecture-for-mssps/445259/in... or https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/391857/overlay and plan it according to your needs/design.

"jack of all trades, master of none"
"jack of all trades, master of none"
FaraJawa

Thanks I have gone through some of the documentation and unfortunately the scenario is a bit unique. Standard sdwan configuration without connecting to hub directly is not possible and advpn is used when spoke to spoke shortcuts required that is also not the case here. I was thinking if below is a possible solution to configure an ipsec tunnel over ipsec tunnel towards hub with a different localid

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Allowing-multiple-IPSec-dial-up-connection...

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors