I have HUB and SPOKE ADVPN topology, shortcut tunnels are working fine but direct BGP peering between spoke is not established and only spoke to HUB bgp is working, i have configured neighbour groups/range at both HUB and SPOKES. kindly suggest the solution.
Hi saqib366,
In normal ADVPN Hub-and-Spoke setup, there shouldn't be a direct BGP peering between two spokes. Spoke only establishes the BGP peering with the Hub and learn the BGP route from there, which includes the BGP routes of other spokes.
There will be a ADVPN shortcut tunnel negotiated between two spokes when one spoke sends the first packet to the other one through the Hub. This shortcut tunnel will make these two Spokes directly connected. The BGP between them is not required anyway.
Below document has a very brief introduction to the ADVPN setup, where we can see each spoke only establishes the BGP peering with two Hubs.
I understand, but the concern is that if the HUB goes down, the shortcut tunnels stay up, however, the iBGP routes learned from the HUB are no longer received. Without this routing information, spoke-to-spoke subnets lose reachability.
If we are concerning the Hub could go down, we can have secondary Hub configured as backup.
This is just like the Router Reflector in the IBGP full mesh setup. We don't need to establish the IBGP peering between each routers one by one but instead using the Router reflector to achieve the full mesh. We can also have secondary Router Reflector as backup in case the primary fails.
Regards,
George
User | Count |
---|---|
2568 | |
1358 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.