Hello to all,
Iām trying to build a single spoke hub & spoke (Dual hub) topology using the overlay template provided by FMG 7.6.3.
The architecture is formed by 2 VM fortigate hubs in 7.4.6 and an onprem A/S pair that acts as spoke in 7.4.6.
Full internet topology, each hub has only one link while the spoke has 2.
All the tunnels are UP, and HUB side I see the advertisement in BGP of the test subnet that Iām using onprem side (192.168.99.0/24).
The BGP advertisement has something strange, I would have expected to see the VPNs as next-hop interfaces, instead it uses directly the port 1 (outside of the hub) used by the underlay.
I noticed that the templates created by FMG do not assign an IP on the HUB interface tunnels, I donāt know if this is an error.
From the hub loopback (172.16.5.252) I can successfully ping the spokeās Lo (172.16.5.1).
Solved! Go to Solution.
I figured out the issue, so basically the RR client was turned on the branch side. so i removed that configuration and the routes was advertised correctly.
You can change the behavior of BGP on Hub by configuring set next-hop-self under bgp peers.
How to modify BGP next hop for route refl... - Fortinet Community
This way, the hub will advertise learned routes as they were locally available.
I figured out the issue, so basically the RR client was turned on the branch side. so i removed that configuration and the routes was advertised correctly.
User | Count |
---|---|
2609 | |
1390 | |
804 | |
664 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.