Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
xiaolin
New Contributor II

peering routing with Fortigate H/A on Azure

We have hub-spoke setup on Azure. Fortigate FW(H/A) is in Hub vnet-A , it peer to two spokes vnet-B and vnet-C . It need route traffic between vnet-B, vnet-C .

Current setup is Vnet-A peering with Vnet-B and peering with Vnet-C

In spoke Vnet-B , have user define route table say - going to vnet-C subnet , next hop is primary FG-A internal ip address. this route table associated to vnet-b subnets

In spoke vnet-c , have user defind  route table say  - going to vnet-B subnet , next hop is primary FG-A internal IP adddress. this route table associated to vnet-c subnets

In Hub vnet-A , have use define route table say - going to Vnet-B subnet, Vnet-C subnet ,next hop is primary FG-A internal IP adddress. this route table associated to vnet-a internal subnets

Now VM in Vnet-B can talk to Vnet-C .

But when FG do failover, , sdn connector change Vnet-A internal route table , say -going to Vnet-B subnet, Vnet-C subnet ,next hop is new primary FG-B internal IP adddress.

But sdn connector can not change Vnet-B and Vnet-C route tables. so communication between B and C broken after hub F/G failover.

What other solution for this case ?

1 Solution
xiaolin
New Contributor II

FG account team recommend staying with SDN, as it is the preferred method moving forward.

View solution in original post

5 REPLIES 5
Anthony_E
Community Manager
Community Manager

Hello Xiaolin,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello Xiaolin,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hi Xiaolin,

 

I found this documentation:

https://docs.fortinet.com/document/fortigate-public-cloud/7.4.0/azure-administration-guide/983245/ha...

 

Could you please tell me if it helps.

 

Regards,

Anthony-Fortinet Community Team.
xiaolin
New Contributor II

Hi  Anthony ,

 

Thank you , Our setup is  Active/Passive-SDN in the link. so looks like sdwan api can not change other subscription' vnet RT. we created FG from azure marketplace , and select active/passive HA with Fabric connector failover.

I will try  active/passive-ELB-ILB, and see if it help. will update

 

xiaolin
New Contributor II

FG account team recommend staying with SDN, as it is the preferred method moving forward.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors