Hello, I have 2 spokes and a branch..
Spoke 1 and Spoke 2 has 2 MPLS underlays. Hub has 2 MPLS and internet underlay (Internet underlay to handle traffic from other spokes). Spoke1 LAN network 10.1.1.0/24, Spoke2 LAN network 10.11.1.0/24..
I did ADVPN configs with all recommended commands at HUB and spoke (Netdevice disabled at Hub and Netdevice enabled at spoke, auto discovery etc).. Since I have two underlays in each spoke and two MPLS at HUB, I will have 4 tunnels (4paths) from each spoke to Hub. so my spoke 1 advertises 10.1.1.0/24 over 4 tunnels to HUB.. Hub is receiving it and could see 4 routes in the command output of get rotuer info routing table bgp. But when I use the command get router info bgp network, I could see only 2 routes have been selected as best (instead of 4). This two routes are getting advertised as 6 routes (with same next hop) to spoke 2... The next hop is not showing in the route table so that ADVPN gets established.. but I could see the IPs of the two dialup tunnel IP (which is not getting selected as best route in ) in the routing table as directly connected route. I am not sure, what config I have missed in BGP to see this behaviour. Due to this my ADVPN not working..
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello rajamanickam,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hi Raja,
I have made some research in our Knowledge Base:
There is a list of articles which could be useful for you.
Could you please have a look and tell me if it helped you?
If not, we will find another way to reply to your answer.
Regards,
Hi, Let me go through this link...
Hello,
If you didn't check this, check this:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/773406/bgp-multiple-path-support
With 4 tunnels, this example should be exactly your scenario.
Thanks for the link, after configuring additional path 4. I could see DC electing 4 best paths which are being advertised to other branches. But however still ADVPN is not working. I have raised a TAC case on this. Since I have all required policies, SDWAN rules, routes but still ADVPN between branches are not working.
Regards
Raja
Did you every get this issue resolved?
Hello Raja,
Have you a reply from TAC case ? I have a similar problem. Only networks HUB are learn from my branches.
Thanks for your reply.
Julien
Hi,
Create separate community post and we can check it.
Hi Adrien,
no problem, i post a new community post.
Best Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.