Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
xiaolin
New Contributor II

peering routing with Fortigate H/A on Azure

We have hub-spoke setup on Azure. Fortigate FW(H/A) is in Hub vnet-A , it peer to two spokes vnet-B and vnet-C . It need route traffic between vnet-B, vnet-C .

Current setup is Vnet-A peering with Vnet-B and peering with Vnet-C

In spoke Vnet-B , have user define route table say - going to vnet-C subnet , next hop is primary FG-A internal ip address. this route table associated to vnet-b subnets

In spoke vnet-c , have user defind  route table say  - going to vnet-B subnet , next hop is primary FG-A internal IP adddress. this route table associated to vnet-c subnets

In Hub vnet-A , have use define route table say - going to Vnet-B subnet, Vnet-C subnet ,next hop is primary FG-A internal IP adddress. this route table associated to vnet-a internal subnets

Now VM in Vnet-B can talk to Vnet-C .

But when FG do failover, , sdn connector change Vnet-A internal route table , say -going to Vnet-B subnet, Vnet-C subnet ,next hop is new primary FG-B internal IP adddress.

But sdn connector can not change Vnet-B and Vnet-C route tables. so communication between B and C broken after hub F/G failover.

What other solution for this case ?

1 Solution
xiaolin
New Contributor II

FG account team recommend staying with SDN, as it is the preferred method moving forward.

View solution in original post

5 REPLIES 5
Anthony_E
Community Manager
Community Manager

Hello Xiaolin,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello Xiaolin,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hi Xiaolin,

 

I found this documentation:

https://docs.fortinet.com/document/fortigate-public-cloud/7.4.0/azure-administration-guide/983245/ha...

 

Could you please tell me if it helps.

 

Regards,

Anthony-Fortinet Community Team.
xiaolin
New Contributor II

Hi  Anthony ,

 

Thank you , Our setup is  Active/Passive-SDN in the link. so looks like sdwan api can not change other subscription' vnet RT. we created FG from azure marketplace , and select active/passive HA with Fabric connector failover.

I will try  active/passive-ELB-ILB, and see if it help. will update

 

xiaolin
New Contributor II

FG account team recommend staying with SDN, as it is the preferred method moving forward.

Labels
Top Kudoed Authors