Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
saqib366
New Contributor

iBGP on shortcut tunnel - ADVPN

I have HUB and SPOKE ADVPN topology, shortcut tunnels are working fine but direct BGP peering between spoke is not established and only spoke to HUB bgp is working, i have configured neighbour groups/range at both HUB and SPOKES. kindly suggest the solution.

3 REPLIES 3
GeorgeZhong
Staff
Staff

Hi saqib366,

 

In normal ADVPN Hub-and-Spoke setup, there shouldn't be a direct BGP peering between two spokes. Spoke only establishes the BGP peering with the Hub and learn the BGP route from there, which includes the BGP routes of other spokes. 

 

There will be a ADVPN shortcut tunnel negotiated between two spokes when one spoke sends the first packet to the other one through the Hub. This shortcut tunnel will make these two Spokes directly connected. The BGP between them is not required anyway.

 

Below document has a very brief introduction to the ADVPN setup, where we can see each spoke only establishes the BGP peering with two Hubs.

 

https://docs.fortinet.com/document/fortigate/7.6.3/administration-guide/985659/advpn-and-shortcut-pa...

saqib366

I understand, but the concern is that if the HUB goes down, the shortcut tunnels stay up, however, the iBGP routes learned from the HUB are no longer received. Without this routing information, spoke-to-spoke subnets lose reachability.

 

 

GeorgeZhong
Staff
Staff

Hi saqib366,

If we are concerning the Hub could go down, we can have secondary Hub configured as backup.

 

This is just like the Router Reflector in the IBGP full mesh setup. We don't need to establish the IBGP peering between each routers one by one but instead using the Router reflector to achieve the full mesh. We can also have secondary Router Reflector as backup in case the primary fails. 

 

Regards,

George

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors