Fortinet white logo
Fortinet white logo

SD-WAN / SD-Branch Architecture for MSSPs

IPsec overlay

IPsec overlay

Within each region, a standard ADVPN configuration is used to build a Hub-and-Spoke topology over each available underlay transport:

  • The Hubs act as Dial-Up IPsec endpoints for the Spokes in the region they serve. A separate Dial-Up IPsec endpoint is configured on each available underlay transport. Every such endpoint defines a point-to-multipoint overlay.

  • Every Spoke builds a separate static IPsec tunnel over each available underlay transport towards each of the Hubs. For example, in a Dual-Hub region with two underlay transports (for example, Internet and MPLS), every Spoke will build four static IPsec tunnels.

  • ADVPN is enabled on all Hubs and Spokes.

In order to interconnect multiple regions, the Hubs build IPsec tunnels between them:

  • Usually those are static IPsec tunnels, forming a Full Mesh, although alternative topologies can be considered when the number of regions becomes too large.

  • Optionally, ADVPN can be enabled (in forwarder mode) on all the Hub-to-Hub tunnels to allow inter-regional shortcuts.

  • The Hub-to-Hub tunnels can be built either over all available underlay transports or only over some of them. There is no strict relation between the transports used within each region and those used for the Hub-to-Hub connectivity.

    Note

    This flexibility is made possible by the ADVPN 2.0 framework. We discuss it in more detail in a dedicated section.

IPsec overlay

IPsec overlay

Within each region, a standard ADVPN configuration is used to build a Hub-and-Spoke topology over each available underlay transport:

  • The Hubs act as Dial-Up IPsec endpoints for the Spokes in the region they serve. A separate Dial-Up IPsec endpoint is configured on each available underlay transport. Every such endpoint defines a point-to-multipoint overlay.

  • Every Spoke builds a separate static IPsec tunnel over each available underlay transport towards each of the Hubs. For example, in a Dual-Hub region with two underlay transports (for example, Internet and MPLS), every Spoke will build four static IPsec tunnels.

  • ADVPN is enabled on all Hubs and Spokes.

In order to interconnect multiple regions, the Hubs build IPsec tunnels between them:

  • Usually those are static IPsec tunnels, forming a Full Mesh, although alternative topologies can be considered when the number of regions becomes too large.

  • Optionally, ADVPN can be enabled (in forwarder mode) on all the Hub-to-Hub tunnels to allow inter-regional shortcuts.

  • The Hub-to-Hub tunnels can be built either over all available underlay transports or only over some of them. There is no strict relation between the transports used within each region and those used for the Hub-to-Hub connectivity.

    Note

    This flexibility is made possible by the ADVPN 2.0 framework. We discuss it in more detail in a dedicated section.