Question regarding some Hub and Spoke SD-WAN configuration thoughts.
Hub - Single ISP, MPLS to remote spokes.
Spokes - 2 ISP + MPLS to main Hub.
Thought... Dynamic VPN from Spokes to Hub that utilize either ISP if the MPLS is down.
Question... is this possible?
Secondary question, is this possible if a secondary Hub is available that has access to the main Hub via MPLS/Direct connection?
So, with that out of the way I have the following scenario:
Hub1 - Single Internet Connection, Single MPLS connection.
Hub2 - Single Internet Connection, Single MPLS connection to Hub1.
Spokes - 1 or 2 ISP Connections, 1 or 0 MPLS to Hub1.
I want to set up spokes that can use a dynamic VPN to Hub1 if their MPLS connection fails, but the spoke has 2 internet connections. I would prefer to only have 1 VPN tunnel to configure, meaning that if WAN1 or WAN2 in the SD-WAN configuration is down, it won't matter as it would use the connection that is up to build the tunnel using a Dynamic tunnel configuration.
Is this type of configuration even possible? If so, how would you do it with FortiManager, which seems to think that every public or MPLS connection should use it's own tunnel. With the option of moving the external connections to dynamic IP Addresses to avoid static IP addressing costs, I'd just like to setup one tunnel that would utilize either WAN1 or WAN2, depending which one is up when the MPLS fails, with full BGP routing, OSPF routing, or whatever other option makes the most sense.
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Thanks,
Hello,
@vraev @heng @iyotov @jasonhong @bboudjema Has someone an idea of what to do please?
Thanks a lot as always :)
Hi,
Could you please open a TAC ticket and request help to our engineers?
https://support.fortinet.com/welcome/#/
Regards,
Hi,
To achieve dynamic VPN failover from spokes to hub1 using either ISP if MPLS is down, you can configure SD-WAN with dynamic tunnels on the FortiGate devices. You can set up a single tunnel that dynamically selects the available WAN interface for the VPN connection based on availability. FortiManager may require more manual configuration for this setup, ensuring proper routing protocols like BGP or OSPF are in place for dynamic routing. This configuration allows for seamless failover and optimal utilization of available connections.
Apologies for the delay in responding, but thank you. I think this is what I was trying to confirm. I don't see a way in the FGT GUI to do this, but when building a dynamic tunnel in FMG I do see that it asks what interfaces to use. I would assume that this is what I need to do for this to work?
I would be using a loopback interface for the BGP routing, which is already being done via the MPLS connection, correct?
Thank you Salon!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1749 | |
1114 | |
766 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.