Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rajamanickam
Contributor

iBGP multipath in ADVPN - SDWAN

Hello, I have 2 spokes and a branch.. 

 

Spoke 1 and Spoke 2 has 2 MPLS underlays. Hub has 2 MPLS and internet underlay (Internet underlay to handle traffic from other spokes). Spoke1 LAN network 10.1.1.0/24, Spoke2 LAN network 10.11.1.0/24..

I did ADVPN configs with all recommended commands at HUB and spoke (Netdevice disabled at Hub and Netdevice enabled at spoke, auto discovery etc).. Since I have two underlays in each spoke and two MPLS at HUB, I will have 4 tunnels (4paths) from each spoke to Hub. so my spoke 1 advertises 10.1.1.0/24 over 4 tunnels to HUB.. Hub is receiving it and could see 4 routes in the command output of get rotuer info routing table bgp. But when I use the command  get router info bgp network, I could see only 2 routes have been selected as best (instead of 4). This two routes are getting advertised as 6 routes (with same next hop) to spoke 2...  The next hop is not showing in the route table so that ADVPN gets established.. but I could see the IPs of the two dialup tunnel IP (which is not getting selected as best route in ) in the routing table as directly connected route. I am not sure, what config I have missed in BGP to see this behaviour. Due to this my ADVPN not working..

9 REPLIES 9
Anthony_E
Community Manager
Community Manager

Hello rajamanickam,

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hi Raja,

 

I have made some research in our Knowledge Base:

 

https://community.fortinet.com/t5/forums/searchpage/tab/message?searchString=ADVPN&from=0&sortby=_sc...

 

There is a list of articles which could be useful for you.

Could you please have a look and tell me if it helped you?

 

If not, we will find another way to reply to your answer.

 

Regards,

Anthony-Fortinet Community Team.
rajamanickam
Contributor

Hi, Let me go through this link...

akristof
Staff
Staff

Hello,

 

If you didn't check this, check this:

https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/773406/bgp-multiple-path-support

With 4 tunnels, this example should be exactly your scenario.

Adrian
rajamanickam
Contributor

Thanks for the link, after configuring additional path 4. I could see DC electing 4 best paths which are being advertised to other branches. But however still ADVPN is not working. I have raised a TAC case on this. Since I have all required policies, SDWAN rules, routes but still ADVPN between branches are not working.

 

Regards

Raja

martini

Did you every get this issue resolved? 

Julien87

Hello Raja,

 

Have you a reply from TAC case ? I have a similar problem. Only networks HUB are learn from my branches. 

 

Thanks for your reply.

 

Julien

Julien
Julien
akristof

Hi,

Create separate community post and we can check it.

 

Adrian
Julien87

Hi Adrien,

 

no problem, i post a new community post.

 

Best Regards,

 

Julien
Julien
Labels
Top Kudoed Authors