Hello, is there anyone who is running SD-WAN HUB in Azure? The FortiGate HUB has private IP on WAN side and the FortiManager will configure the SPOKEs to create IPSec connection to this private IP, not the public one.
I tried to set the local-gw in the IPSec configuration on the HUB in Azure to the public IP than the ike debug showed the SPOKE trying to connecting but No Proposal Choosen was the result. (probably the FortiGate excepted the connection to the public IP not to the private one)
If I chagne the private IP on the SPOKE to the public one the tunnel goes up. But every policy package install will rewrite back the IPSec remote-gw IP to the private one.
How to fix this?
AtiT
Hi AtiT,
following Deplyoment guide shows how to implement SD_WAN HUB in Azure:
Regards
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.