Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rajamanickam
Contributor

SDWAN at DC

Hello all,

 

 We have recently deployed Fortinet SDWAN with Hub and Spoke topology. We have configured all overlay and underlay interfaces as SDWAN interfaces and configured necessary SDWAN rules to pick the correct link.

 

In DC, we have combined underlay, overlay, tunnels to SIG provider as SDWAN interfaces.. There are some traffic which is getting originated from DC to branches. For this traffic, we have configured SDWAN rule with performance SLA. We are using single SDWAN template for all the branches. From DC, how a performance SLA can be written to determine the best path towards branches, since we cant have SLA configured towards each branches... Any suggestions on this?

 

 

4 REPLIES 4
akristof
Staff
Staff

Hello,

 

Thank you for your question.

If I understand, your DC = HUB, correct? You have standard HUB&Spoke without ADVPN or with ADVPN? Usually, SDWAN on HUB is not preferred exactly because of this problem. Based on model/version you can have up to 4000 health-checks. There is no good way how to achieve this, if you want to have SDWAN with rules based on SLA on HUB to reach multiple spokes.

Adrian
rajamanickam
Contributor

Thank you for the reply.. Its ADVPN with H&S

We have 1 DC (Hub1), 1 DR (Hub2).. Since we are also doing IPSEC integration with a SIG provider we have to forward default traffic towards that SIG provider. That is the reason we have to configure all these interfaces (overlay between H&S, underlay on Hubs, IPSEC towards SIG) as one SDWAN interface and we are writing rules for the respective interfaces. Currently  we have around 11brances which falls under same SDWAN template. For these branches, we have configured 2 health check servers bound to a performance sla towards branches from DC. These 2 health check servers are two loop back ips of the 2 different branches. There is a very rare scenario that all underlays of these 2 sites goes down at same time, hence we are using this way. Just want to check for any other alternate ways possible to detect the health check of branches when the traffic is orginating from DC to branches..

akristof

Hi,

 

Thanks for feedback. On HUB there is no easier way how to do it. So it really depends on the scale. We have automated health-checks but it is for SDWAN with ADVPN on spokes, where shortcuts are automatically probed.

Adrian
rajamanickam

Can you help with the documentation link of "Automated health-checks for ADVPN on spokes". We are also running ADVPN for spoke to spoke on demand tunnels. 

Labels
Top Kudoed Authors