Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jdsauer77
New Contributor

SD-WAN(ish) design

Question regarding some Hub and Spoke SD-WAN configuration thoughts.

Hub - Single ISP, MPLS to remote spokes.

Spokes - 2 ISP + MPLS to main Hub.

Thought... Dynamic VPN from Spokes to Hub that utilize either ISP if the MPLS is down.

Question... is this possible?

Secondary question, is this possible if a secondary Hub is available that has access to the main Hub via MPLS/Direct connection?

So, with that out of the way I have the following scenario:

Hub1 - Single Internet Connection, Single MPLS connection.

Hub2 - Single Internet Connection, Single MPLS connection to Hub1.

Spokes - 1 or 2 ISP Connections, 1 or 0 MPLS to Hub1.

I want to set up spokes that can use a dynamic VPN to Hub1 if their MPLS connection fails, but the spoke has 2 internet connections. I would prefer to only have 1 VPN tunnel to configure, meaning that if WAN1 or WAN2 in the SD-WAN configuration is down, it won't matter as it would use the connection that is up to build the tunnel using a Dynamic tunnel configuration.

 

Is this type of configuration even possible? If so, how would you do it with FortiManager, which seems to think that every public or MPLS connection should use it's own tunnel. With the option of moving the external connections to dynamic IP Addresses to avoid static IP addressing costs, I'd just like to setup one tunnel that would utilize either WAN1 or WAN2, depending which one is up when the MPLS fails, with full BGP routing, OSPF routing, or whatever other option makes the most sense.

7 REPLIES 7
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

@vraev @heng @iyotov @jasonhong @bboudjema Has someone an idea of what to do please?

 

Thanks a lot as always :)

Jean-Philippe - Fortinet Community Team
Anthony_E
Community Manager
Community Manager

Hi,

 

Could you please open a TAC ticket and request help to our engineers?

https://support.fortinet.com/welcome/#/

 

Regards,

Anthony-Fortinet Community Team.
sjoshi
Staff
Staff

Hi,

 

To achieve dynamic VPN failover from spokes to hub1 using either ISP if MPLS is down, you can configure SD-WAN with dynamic tunnels on the FortiGate devices. You can set up a single tunnel that dynamically selects the available WAN interface for the VPN connection based on availability. FortiManager may require more manual configuration for this setup, ensuring proper routing protocols like BGP or OSPF are in place for dynamic routing. This configuration allows for seamless failover and optimal utilization of available connections.

Let us know if this helps.
Salon Raj Joshi
jdsauer77

Apologies for the delay in responding, but thank you. I think this is what I was trying to confirm. I don't see a way in the FGT GUI to do this, but when building a dynamic tunnel in FMG I do see that it asks what interfaces to use. I would assume that this is what I need to do for this to work?

I would be using a loopback interface for the BGP routing, which is already being done via the MPLS connection, correct?

Anthony_E
Community Manager
Community Manager

Thank you Salon!

Anthony-Fortinet Community Team.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors