Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HS08
Contributor

SDWAN Asymetric

SDWAN SLA performace in spoke1 choose shortcut tunnel to spoke2 because the latency is more small than main tunnel to the hub.

SDWAN SLA performace in spoke2 choose main tunnel to spoke2 because the latency is more small than main tunnel to the hub.

With this case spoke1 and spoke2 can't communiate. DOing the packet sniffer i can see traffic from LAN spoke1 is reach to spoke2 but spoke2 will reply using main tunnel to the hub.

How we can deal with asymetric routing like this due to different SLA performance result?

14 REPLIES 14
Igneus
New Contributor II

I solved the issue by assigning priorities to each SD-WAN member/route (I have 4 routes per site to reach the peer). I only needed to assign the same priorities on the corresponding routes at both sites, and now the failovers happen symmetrically.

I preferred this approach because we have some voice traffic running between the sites, and it could not tolerate asymmetry, even if the routing was technically correct.

give it a shot
give it a shot
djp
New Contributor III

Be careful with ADVPN 2.0.  It is really more dangerous that it is helpful, and should really be using only in situation where you have different transits (MPLS & DIA...).  

Question, which ADVPN flavor are deploying and is this in lab or production?  This will tell us what SLA mechanism you are using and allow me to pinpoint where your configuration issue is at.



djp
New Contributor III

I did a video not to long ago on this:  https://youtu.be/3SmNWZGlIgw?si=9sMbir2BXQDsJV_W

jamesmarsden8
New Contributor

For asymmetric routing issues like this, policy-based routing or SLA-aware routing could help ensure replies follow the intended path. On a lighter note, thinking about stable and reliable solutions reminds me of installing a hochwertiger Vinylboden—solid, durable, and dependable under all conditions!

AEK
SuperUser
SuperUser

This is a new feature on 7.6.4.

https://docs.fortinet.com/document/fortigate/7.6.0/new-features/204310/advpn-2-0-enhancement-trigger...

But actually I'm not very sure if it helps with your issue.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors