[Fortigate] Hub-and-spoke ADVPN using IPsec VPN wizard/Dynamically add spokes using autoconfig key

Поділитися
Вставка
  • Опубліковано 8 вер 2024
  • How to configure Hub-and-spoke ADVPN using IPsec VPN wizard
    Auto-discovery Hub and spoke VPN with BGP as routing protocol
    Add multiple spokes using the autoconfiguration key
    Reference Topology: techtalksecuri...
    ================================
    Please donate to support the channel:
    UPI: techtalksecurity@axl
    PayPal: sumitnick4@gmail.com
    ================================
  • Наука та технологія

КОМЕНТАРІ • 17

  • @LostWorldOfComputerAndSoftware
    @LostWorldOfComputerAndSoftware 8 місяців тому +1

    Nice! This really helped me understand ADVPN. I love how you showed every step and that you didn't edit away mistakes, that way we also learned how to troubleshoot. Thanks man!

  • @kelumidu4116
    @kelumidu4116 Рік тому +4

    Thank you sir please do another one ad vpn with sd wan as well

  • @shahbazsandhu1031
    @shahbazsandhu1031 Рік тому

    Very nice and informative.
    Also, What do I need to check if I'm unable to ping the HUB from the spokes in my scenario but spokes can able to ping each other. Also, my setup is slightly different as I'm using 2 WAN connections- Primary and Failover.

  • @mirzadzafic8999
    @mirzadzafic8999 10 місяців тому +1

    Thank you for video. This solution is similar as Cisco DMVPN, but from this video i see that communication between spokes going through hub, in DMVPN Spoke dynamicaly establish tunnel with help of NHRP protocol and communicate directly which is benefit. Is this possible in this Fortigate ADVPN ? Also i am interested to see steps for creating this ADVPN mannualy not through wizard for better understanding.

    • @sumitnick4
      @sumitnick4  10 місяців тому +1

      Yes.hub and spoke motive is to connect all spoke to HUB dynamically and administer the traffic through Hub. Many vendors have tweaker the protocol to allow spoke to spoke communication as well like ADVPC in Juniper or Cisco.

    • @mirzadzafic8999
      @mirzadzafic8999 10 місяців тому

      @@sumitnick4 Thanks for aswer. I am wonder is it possible to confgireu Fortigate ADVPN mannualy thorugh GUI ? I found if we dont use ipsec hub and spoke template, and if want to configure ADVPN it is possible only through CLI?

    • @sumitnick4
      @sumitnick4  10 місяців тому

      it is
      @@mirzadzafic8999

  • @brutalali32
    @brutalali32 Рік тому

    Very informative , in real time does it requires public ip to be on both hub and spoke site or only hub site is enough

    • @sumitnick4
      @sumitnick4  Рік тому

      public IP on hub and NAT-T enabled will also work

  • @user-nv9dz9tv9v
    @user-nv9dz9tv9v 8 місяців тому

    in my similar tapology in EVE NG home setup...spokes to spokes communication is not dynamically pinging while the spokes can talk to the hub bidirectionally.. I am figuring out why spokes are not pinging ?

    • @sumitnick4
      @sumitnick4  8 місяців тому

      take a debug to check what is causing the ping to fail

  • @riyazshaikh6373
    @riyazshaikh6373 Рік тому

    Nice! Thanks for the video. I believe you are using private Ip address 192.168 as you are within the premises. This will be same if we use the public Ip address. Please comment.

  • @bonip5278
    @bonip5278 Рік тому

    If I want to deny the traffic between spokes by default, how to do that?

    • @bonip5278
      @bonip5278 Рік тому

      The spoke only can communicate with the HUB

    • @sumitnick4
      @sumitnick4  Рік тому

      You can tune the policy to allow or deny the source or destination