Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Waloo5
Contributor

fully-meshed VPN with Provisioning templates on FortiManager for FortiGates with multiple ISP lines

Hello Community,

how to create a fully-meshed VPN with Provisioning templates on FortiManager for FortiGates  with multiple ISP lines and 2 HUBs and multiples Spokes

my architecture is like :

HUB1 ==> 4 ISPs

HUB2==> 4 ISPs

10 Spoke ==> 2 ISPs

my gol is to have in the spoke full mesh to HUBs ( 8 tunnels VPN IPSec  to HUB1 and 8 tunnels to HUB2)

 

Amir
Amir
4 REPLIES 4
Waloo5

Hello, 

Thank you for reply. My question is to know if we can do it in Provisioning templates not in vpn manager.

Amir
Amir
farhanahmed
Staff
Staff

O I see.

 

I believe there is no restriction, you should be able to do it but would require some manual work.


I could not find any specific doc for this setup.

But, have separate IPSec templates for HUB1, HUB2 and one template SPOKES.

Use metavariables for interfaces/subnets and create multiple tunnels to each site.

If you want ADVPN, then on Spoke template enable the autodiscovery receive and for Hubs autodiscovery sender.

FA
Waloo5
Contributor

Hello, 

I found a solution to do this, but I'm not sure if it's the recommended approach from Fortinet.

In my SD-WAN Overlay setup, under the 'SD-WAN Overlay Template - Network Configuration (3/5)' section, I added multiple WAN Underlays for the Branch.

sdwan.png

 

In this example, I have 3 ISPs for Hub 1, 3 ISPs for Hub 2, and 2 ISPs for Spokes.

I hope this can help someone who is searching for a solution to this setup. I would also appreciate it if someone has a recommended solution to share it.

Best regards

 

 
Amir
Amir
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors