SDWAN SLA performace in spoke1 choose shortcut tunnel to spoke2 because the latency is more small than main tunnel to the hub.
SDWAN SLA performace in spoke2 choose main tunnel to spoke2 because the latency is more small than main tunnel to the hub.
With this case spoke1 and spoke2 can't communiate. DOing the packet sniffer i can see traffic from LAN spoke1 is reach to spoke2 but spoke2 will reply using main tunnel to the hub.
How we can deal with asymetric routing like this due to different SLA performance result?
I solved the issue by assigning priorities to each SD-WAN member/route (I have 4 routes per site to reach the peer). I only needed to assign the same priorities on the corresponding routes at both sites, and now the failovers happen symmetrically.
I preferred this approach because we have some voice traffic running between the sites, and it could not tolerate asymmetry, even if the routing was technically correct.
Be careful with ADVPN 2.0. It is really more dangerous that it is helpful, and should really be using only in situation where you have different transits (MPLS & DIA...).
Question, which ADVPN flavor are deploying and is this in lab or production? This will tell us what SLA mechanism you are using and allow me to pinpoint where your configuration issue is at.
I did a video not to long ago on this: https://youtu.be/3SmNWZGlIgw?si=9sMbir2BXQDsJV_W
For asymmetric routing issues like this, policy-based routing or SLA-aware routing could help ensure replies follow the intended path. On a lighter note, thinking about stable and reliable solutions reminds me of installing a hochwertiger Vinylboden—solid, durable, and dependable under all conditions!
This is a new feature on 7.6.4.
But actually I'm not very sure if it helps with your issue.
User | Count |
---|---|
2593 | |
1382 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.