Fortinet white logo
Fortinet white logo

SD-WAN / SD-Branch Architecture for MSSPs

IKE extension: exchange-ip-addrv4

IKE extension: exchange-ip-addrv4

This feature allows IKE to inject a custom /32 route on both sides of an IPsec tunnel:

In BGP on loopback design, we use it to provide loopback reachability without the use of additional routing protocols. It injects the /32 loopback route both over static IPsec tunnels (Spoke-to-Hub) and over dynamic ADVPN shortcuts (Spoke-to-Spoke).

In the above example, it helps the Hub “site1-H1” to resolve the route towards 10.0.2.0/24, by injecting the loopback route 10.200.1.2/32, which serves as a BGP NH. The same happens in the opposite direction: the Hub’s loopback route is injected on the Spoke, allowing it to resolve the routes advertised by the Hub.

As for the ADVPN shortcut support, we will see the resolution examples in the following topics:

IKE extension: exchange-ip-addrv4

IKE extension: exchange-ip-addrv4

This feature allows IKE to inject a custom /32 route on both sides of an IPsec tunnel:

In BGP on loopback design, we use it to provide loopback reachability without the use of additional routing protocols. It injects the /32 loopback route both over static IPsec tunnels (Spoke-to-Hub) and over dynamic ADVPN shortcuts (Spoke-to-Spoke).

In the above example, it helps the Hub “site1-H1” to resolve the route towards 10.0.2.0/24, by injecting the loopback route 10.200.1.2/32, which serves as a BGP NH. The same happens in the opposite direction: the Hub’s loopback route is injected on the Spoke, allowing it to resolve the routes advertised by the Hub.

As for the ADVPN shortcut support, we will see the resolution examples in the following topics: