Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
velosy
New Contributor II

SDWAN ADVPN Dual Hub Question

Hello,

 

I currently have a hub and spoke SDWAN solution, using ADVPN, IBGP and SDWAN rules to steer traffic across the overlay or breakout locally across the internet.

 

I need to add another Hub that will provide access to more infrastructure and advertise specific prefixes to the spokes, but this Hub also needs to communicate with the existing Hub. I currently have x2 overlays on the existing Hub to each spoke. My plan was to continue this design on the new Hub and create x2 new overlays so the spokes can reach the new hub. I will then make both the hubs spokes of each other.

 

My worry was that if I make the hubs spokes of each other, that they might try to shortcut to other spokes. Is what I have proposed above along the right lines, appreciate any advice/recommendations.

 

Thanks

3 REPLIES 3
jiahoong112
Staff
Staff

You may find the PDF in this document helpful, page 76 where there is explanation on Dual Hub set up: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Fortinet-Auto-Discovery-VPN-ADVPN/ta-p/195... 

 

Making the Hubs, spokes of each other is not required.

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
velosy
New Contributor II

I don't think Dual Region would suit my environment because Hub1 and Hub2 will have the same spokes, whereas the Dual region suggests spokes are unique to the region.

jiahoong112

Even for this, you can follow the 'Dual Region' configuration but with the same AS number in the BGP settings to ensure both Hubs and all Spokes are in the same iBGP AS. The Spokes from different region (different eBGP AS) will still end up forming shortcut tunnels with each other.

 

For example, assuming each Spoke as 2 ISPs. 1 ISP can be used to form the tunnel to Hub1 and the other to Hub 2. Hub 1 and Hub 2 will have an site-to-site ipsec between each other with 'auto-discovery forwarder and receiver and sender' enabled. Unfortunately, I am not able to find any documents with this specific configuration. This will have to be tested in the lab. I would highly suggest you to contact the Fortinet Sales/Professional Services Team for consultation of this specific design. 

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors