Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Morus
New Contributor II

SDWAN BGP on Looback (Dynamic) + ADVPN 2.0 info

Hello to all,
I’m trying to build a single spoke hub & spoke (Dual hub) topology using the overlay template provided by FMG 7.6.3.
The architecture is formed by 2 VM fortigate hubs in 7.4.6 and an onprem A/S pair that acts as spoke in 7.4.6.

Full internet topology, each hub has only one link while the spoke has 2.
All the tunnels are UP, and HUB side I see the advertisement in BGP of the test subnet that I’m using onprem side (192.168.99.0/24).

 

The BGP advertisement has something strange, I would have expected to see the VPNs as next-hop interfaces, instead it uses directly the port 1 (outside of the hub) used by the underlay.

Immagine 2025-05-30 105102.png

I noticed that the templates created by FMG do not assign an IP on the HUB interface tunnels, I don’t know if this is an error.
From the hub loopback (172.16.5.252) I can successfully ping the spoke’s Lo (172.16.5.1).

1 Solution
Morus
New Contributor II

I figured out the issue, so basically the RR client was turned on the branch side. so i removed that configuration and the routes was advertised correctly.

View solution in original post

2 REPLIES 2
xshkurti
Staff
Staff

You can change the behavior of BGP on Hub by configuring set next-hop-self under bgp peers.

How to modify BGP next hop for route refl... - Fortinet Community

This way, the hub will advertise learned routes as they were locally available.

Morus
New Contributor II

I figured out the issue, so basically the RR client was turned on the branch side. so i removed that configuration and the routes was advertised correctly.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors