Fortinet white logo
Fortinet white logo

SD-WAN / SD-Branch Architecture for MSSPs

Health measurement

Health measurement

Measuring current health status of each SD-WAN/ADVPN 2.0 Member is important for optimal shortcut management.

ADVPN 2.0 relies on the following two methods:

  • Every Spoke actively probes each overlay path towards its Hub(s), using the standard Performance SLA configuration. The standard recommendation is to configure a dedicated loopback interface on each Hub for the health probing using Ping protocol. Later, these health measurements are exchanged between Spokes during the Discovery process, and they serve as an estimation of the health status during the Path Selection.

    Note

    While the health measured between each Spoke and its Hub does not necessarily correlate to the health of the actual Spoke-to-Spoke path, it is nevertheless a good estimation. It is capable of detecting both local and remote connection issues and helps the Path Selection mechanism avoid triggering shortcuts over unhealthy WAN links.

  • Once a shortcut is built, an additional health probing is automatically activated over it (known as ADVPN shortcut monitoring). This probing (also using Ping protocol) is more accurate, because it measures health of the actual path between the two Spokes' loopbacks.

Both measurements are considered by the Path Selection mechanism. For example, even if both Spokes report good health between each one of them and its respective Hub, a shortcut between them might be found out of SLA. In this situation, the Path Selection mechanism will attempt to trigger another shortcut.

Health measurement

Health measurement

Measuring current health status of each SD-WAN/ADVPN 2.0 Member is important for optimal shortcut management.

ADVPN 2.0 relies on the following two methods:

  • Every Spoke actively probes each overlay path towards its Hub(s), using the standard Performance SLA configuration. The standard recommendation is to configure a dedicated loopback interface on each Hub for the health probing using Ping protocol. Later, these health measurements are exchanged between Spokes during the Discovery process, and they serve as an estimation of the health status during the Path Selection.

    Note

    While the health measured between each Spoke and its Hub does not necessarily correlate to the health of the actual Spoke-to-Spoke path, it is nevertheless a good estimation. It is capable of detecting both local and remote connection issues and helps the Path Selection mechanism avoid triggering shortcuts over unhealthy WAN links.

  • Once a shortcut is built, an additional health probing is automatically activated over it (known as ADVPN shortcut monitoring). This probing (also using Ping protocol) is more accurate, because it measures health of the actual path between the two Spokes' loopbacks.

Both measurements are considered by the Path Selection mechanism. For example, even if both Spokes report good health between each one of them and its respective Hub, a shortcut between them might be found out of SLA. In this situation, the Path Selection mechanism will attempt to trigger another shortcut.