Fortinet white logo
Fortinet white logo

SD-WAN / SD-Branch Architecture for MSSPs

No inter-regional ADVPN

No inter-regional ADVPN

If inter-regional ADVPN support is not required, there is no longer need to preserve a BGP NH across the regions. The routing can be then optimized by summarizing the regional LAN prefixes on the Hubs.

The following diagram follows the same LAN prefix 10.4.1.0/24, which is advertised by "site2-1" (from Region 2), and is propagated to "site1-1" (from Region 1) without inter-regional ADVPN support:

As can be seen, the Hub in Region 2 ("site2-H1") now simply advertises a regional LAN summary (rather than a regional loopback summary!) towards the Hub in Region 1 ("site1-H1"), which in turn readvertises it towards its Spokes. All inter-regional traffic will then flow through the Hubs, like in any traditional multi-regional Hub-and-Spoke network.

No inter-regional ADVPN

No inter-regional ADVPN

If inter-regional ADVPN support is not required, there is no longer need to preserve a BGP NH across the regions. The routing can be then optimized by summarizing the regional LAN prefixes on the Hubs.

The following diagram follows the same LAN prefix 10.4.1.0/24, which is advertised by "site2-1" (from Region 2), and is propagated to "site1-1" (from Region 1) without inter-regional ADVPN support:

As can be seen, the Hub in Region 2 ("site2-H1") now simply advertises a regional LAN summary (rather than a regional loopback summary!) towards the Hub in Region 1 ("site1-H1"), which in turn readvertises it towards its Spokes. All inter-regional traffic will then flow through the Hubs, like in any traditional multi-regional Hub-and-Spoke network.