hi,
Could you please kindly clarify the meaning of the 'Site B is isolated'? Did you mean no Internet connectivity?
If the site B needs to join the ADVPN setup, it needs to have the underlay connectivity (Internet) to the Hub's public IP to form the IPsec tunnel. Also, it should be able to talk to the public IP of the site A to form the Shortcut tunnel once it receives the shortcut offer from the hub.
Regards,
George
Thx GeorgeZhong for respond
i wanna site A and site B cant talk each other, because advpn using same as BGP, how to make routing BGP site A and site B dont adv each other thx
hi,
for your situation i would say that you have several ways of achieving that:
- in the current advpn setup you just block from fw rules access between them ( this involves in my opinion the least amount of work )
- another idea would be to create a dedicated site2site vpn between site b or a ( whichever you want to isolated ) and the hub, this way it wont be part of the advpn
User | Count |
---|---|
2609 | |
1390 | |
804 | |
664 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.