Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MO_mead
New Contributor

SD WAN ipsec

hi, I want to create sd-wan for branc office to HQ. I find only 2 guides (https://kb.fortinet.com/kb/documentLink.do?externalID=FD41297 and with BGP) but in my scenario I had 2 isp in brance office and 2 isp in HQ. I would not touch HQ inteface configuration..it's possible?

 

Thanks

Mirko

5 REPLIES 5
orani
Contributor II

SD-WAN is something different from vpn. Your branch office is connected directly to internet or through HQ? You have to configure 4 ipsec vpns. 1. Branch 1 <--> hq 1 2. Branch 1 <--> hq 2 3. Branch 2 <--> hq 1 4. Branch 2 <--> hq 2 Then if you want branch internet traffic go throwgh HQ, you have to configure an sd-wan with those 4 vpns and some health checks as the article you provided. If you want your branch internet traffic go directly to the internet add to the sd-wan the to internet connections and force the traffic to go through those interfaces. In that scenario internet traffic will pass directly to internet and all other traffic would go to branch (depending the rules you will create).

Orestis Nikolaidis

Network Engineer/IT Administrator

Orestis Nikolaidis Network Engineer/IT Administrator
MO_mead
New Contributor

Thanks Orani good answerd!

 

In my case, branch internet traffic go throwgh HQ. The theory is clear the extecution not so such.

I create vpn, sd-wan and policy only in branch office but in HQ (ok vpn site-site) Do I make nothing else?

 

Thanks again

 

orani
Contributor II

At hq you have to create the ipsec vpn and also the approptiate rules for the ipsec traffic

Orestis Nikolaidis

Network Engineer/IT Administrator

Orestis Nikolaidis Network Engineer/IT Administrator
orani
Contributor II

After completing this, check also via ping if your traffic is ok from branch to hq, from branch to internet and from hg to branch

Orestis Nikolaidis

Network Engineer/IT Administrator

Orestis Nikolaidis Network Engineer/IT Administrator
MO_mead

Hi Orani, thanks again for your time and suggestions. In reality I had some problem to configure vpn in branch office, in particolary for understand to set ip of vpn tunnel, but now i try again, but you have other suggestions or (fortigate) guide I will be very happy to follow them.

Thanks.

Labels
Top Kudoed Authors