Connectivity between hubs in NGFW SDWAN

L2 Linker

When building an NGFW SDWAN hub-spoke network, SDWAN tunnels are not built between hubs. I was thinking of 2 options:

 

1) Manually building two tunnels between the hubs and put them in an SDWAN bundle myself, along with the rest of the SDWAN config (static routes to loopbacks over the SDWAN bundle, BGP Peering). Do you foresee any issues with this? It's a lot of config, where I wish auto-vpn just did it for you.

 

Or

 

2) I could just build tunnels and run BGP over them. Thoughts? How have you approached this?

L4 Transporter

Hello BBartik,

 

Have you tried to set the VPN Cluster to "full mesh" instead of "hub and spoke"?

Olivier

PCSNE - CISSP

Best Effort contributor

Check out our PANCast Channel

Disclaimer : All messages are my personal ones and do not represent my company's view in any way.