Hi. I need to connect 500 Cisco routers with a Fortigate. What is the best way to approach this? Preferably I want it to be an IPSec tunnel interface. As I know, AD VPN is only supported by Fortinet devices, so it won't work for me, but is there an alternative? Thanks in advance.
If your goal is for 500 branches to be able to bring up direct VPN tunnels with each other when needed, then indeed AD VPN by Fortigate is proprietary and I am not aware of anyone making it work with other vendors. In this case replacing your FGT with Cisco and configuring DMVPN would be the only way to provide it.
If, on the other hand, your 500 branches will talk directly only to the FGT as a hub, then it is a regular Hub-and-Spoke topology, with Hub being FGT, and spokes being Cisco. Usual VPN tunnels with BGP running inside them to advertise/withdraw routes would work. The challenge here as I see is scalability of configuring/monitoring/troubleshooting all this zoo. I once, years ago, designed and implemented POC for Cisco-only DMVPN with 300 branches, there were no problems, until we started deploying branch routers at scale with each branch differing in its connectivity bandwidth/quality/number of users at site/etc. Not fun w/o central management of some sort - later in the project client bought Cisco Prime to be able to manage such a large topology. The same goes with Fortigate - if all branches were FGT, you could automate deploying/centrally monitor and configure/logging using FortiManager. But with mix of vendors, it doubles the spendings for that.
User | Count |
---|---|
2574 | |
1373 | |
796 | |
657 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.