Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
a1lyass
New Contributor

VPN between Fortigate and 500 Cisco devices

Hi. I need to connect 500 Cisco routers with a Fortigate. What is the best way to approach this? Preferably I want it to be an IPSec tunnel interface. As I know, AD VPN is only supported by Fortinet devices, so it won't work for me, but is there an alternative? Thanks in advance.

10.0.0.0.1 192.168.1.254
1 REPLY 1
Yurisk
SuperUser
SuperUser

If your goal is for 500 branches to be able to bring up direct VPN tunnels with each other when needed, then indeed AD VPN by Fortigate is proprietary and I am not aware of anyone making it work with other vendors. In this case replacing your FGT with Cisco and configuring DMVPN would be the only way to provide it.

 

If, on the other hand, your 500 branches will talk directly only to the FGT as a hub, then it is a regular Hub-and-Spoke topology, with Hub being FGT, and spokes being Cisco. Usual VPN tunnels with BGP running inside them to advertise/withdraw routes would work. The challenge here as I see is scalability of configuring/monitoring/troubleshooting all this zoo. I once, years ago, designed and implemented POC for Cisco-only DMVPN with 300 branches, there were no problems, until we started deploying branch routers at scale with each branch differing in its connectivity bandwidth/quality/number of users at site/etc. Not fun w/o central management of some sort - later in the project client bought Cisco Prime to be able to manage such a large topology. The same goes with Fortigate - if all branches were FGT, you could automate deploying/centrally monitor and configure/logging using FortiManager.  But with mix of vendors, it doubles the spendings for that. 

 

https://yurisk.info
https://yurisk.info
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors