Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Timi33
New Contributor

VPN IPSEC over SDWAN

Hi guys,

I'm new on this forum, i'm Infrastructure Manager in France.

My parc is made of 300D / 60 D / 90D.

We have 4 distant sites.

 

Actually we are using WAN 1&2 with DPD to have a redundancy between all links.

We have IPSEC to link sites, but it's very complicated to manage it.

 

For instance to link PARIS & BORDEAUX we have 2

An for rules we have to do for each ipsec

For instance

LAN PARIS -> LAN BORDEAUX via WAN 1 to WAN1

LAN PARIS -> LAN BORDEAUX via WAN 1 to WAN2

LAN PARIS -> LAN BORDEAUX via WAN2 to WAN1

LAN PARIS -> LAN BORDEAUX via WAN2 to WAN2

 

LAN PARIS <- LAN BORDEAUX via WAN 1 to WAN1

LAN PARIS <- LAN BORDEAUX via WAN 1 to WAN2

LAN PARIS <- LAN BORDEAUX via WAN2 to WAN1

LAN PARIS <- LAN BORDEAUX via WAN2 to WAN2

 

It makes a lot of rules for us to have redundancy for each rules.

 

We were thinking about SD WAN to simplify that but it appears that there is not IPSEC over SDWAN.

We are in 6.0.1 of FORTI OS

 

We would like to do something like that

 

LAN PARIS -> LAN BORDEAUX via IPSECSDWAN 

LAN PARIS <- LAN BORDEAUX via IPSECSDWAN 

 

IPSECSDWAN would be

WAN 1 to WAN 1 priority 0 

WAN 1 to WAN 2 priority 10

WAN 2 to WAN 1 priority 20 

WAN 2 to WAN 2 priority 30 

 

Do you know if it possible ? 

 

Have a nice day.

 

Cheers

 

Tim

 

 

 

0 REPLIES 0
Labels
Top Kudoed Authors