Your suggestion of using OSPF with IPSec could be a good solution, because it seems to be exactly thesame as DMVPN. The only drawback of it is that it uses OSPF instead of EIGRP, were EIGRP is a bit faster than OSPF. Also EIGRP is better suited for our network design. Can Fortigates do EIGRP?Your mistaken, DMVPN has no requirement to use OSPR,EIGRP or RIP over the dynamic tunnels. In your case, deploy OSPF over interface-mode ipsec tunnels and you could have redundant tunnels and quickfailover. You could adjust your ospf timers if needed to get the quick failover interval. btw we run OSPF over our DMVPN tunnels, EIGRP is not going to be a option for you.
PCNSE
NSE
StrongSwan
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.