Hello,
I currently have a hub and spoke SDWAN solution, using ADVPN, IBGP and SDWAN rules to steer traffic across the overlay or breakout locally across the internet.
I need to add another Hub that will provide access to more infrastructure and advertise specific prefixes to the spokes, but this Hub also needs to communicate with the existing Hub. I currently have x2 overlays on the existing Hub to each spoke. My plan was to continue this design on the new Hub and create x2 new overlays so the spokes can reach the new hub. I will then make both the hubs spokes of each other.
My worry was that if I make the hubs spokes of each other, that they might try to shortcut to other spokes. Is what I have proposed above along the right lines, appreciate any advice/recommendations.
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
You may find the PDF in this document helpful, page 76 where there is explanation on Dual Hub set up: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Fortinet-Auto-Discovery-VPN-ADVPN/ta-p/195...
Making the Hubs, spokes of each other is not required.
I don't think Dual Region would suit my environment because Hub1 and Hub2 will have the same spokes, whereas the Dual region suggests spokes are unique to the region.
Even for this, you can follow the 'Dual Region' configuration but with the same AS number in the BGP settings to ensure both Hubs and all Spokes are in the same iBGP AS. The Spokes from different region (different eBGP AS) will still end up forming shortcut tunnels with each other.
For example, assuming each Spoke as 2 ISPs. 1 ISP can be used to form the tunnel to Hub1 and the other to Hub 2. Hub 1 and Hub 2 will have an site-to-site ipsec between each other with 'auto-discovery forwarder and receiver and sender' enabled. Unfortunately, I am not able to find any documents with this specific configuration. This will have to be tested in the lab. I would highly suggest you to contact the Fortinet Sales/Professional Services Team for consultation of this specific design.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1645 | |
1070 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.