FusionHub improvements

Right now we find it hard to make full use of the fusion hub as it lacks:

  1. Dynamic routing (BGP & OSPF)
  2. Any routing within VRFs. Ideally, I would like to be able to have dynamic routing on the base (no-VRF) and then share a route into a VRF, so we can have separation of routes such that each VRF only sees selected routes. Even static routes within VRFs would be an improvement.
  3. multiple WAN interfaces. This is seperate, so we could use fusion hub’s on smaller sites where physical devices are inappropriate.
1 Like


Thanks for the feeback.

  1. We are working on this feature.
  2. Putting this into feature request.
  3. Putting this into feature request.
1 Like

Extra LAN/VLAN interfaces would be nice as well, for more advanced deployments.

1 Like

One major need is route isolation (like on the balance/max series).
We run a pure “star” topology (IP phone service). i.e. PEER-A should not see a route to PEER-B subnet via fusionhub.
Right now we have about 800 peers on balance routers in two data centers. Starting a major push into google cloud. When I have say 400 peers on a FH in one google region it will be an immense security hole AND waste of bandwidth for every peer to receive constant updates to 399 networks they should NOT see.

Also (I have asked about this for some time) ability to add manual route advertisements.
Issue is that in google cloud the virtual machine has a “LAN subnet” of a single ip address. i.e.
The other VMs are all on That is the “real” private subnet. But the DHCP gives the VM a single IP WITH NO GATEWAY. All routing/firewall rules are in the google cloud engine, not in the VM.
So FH advertises not but So you have an IP phone on a remote network that needs to reach…it cannot. So you have to add an outbound policy in every remote peer enforcing to “GOOGLEEAST” vpn. This means that when I move a peer from a balance to a FH I have to add rules to the peer. If I add another subnet at google I have to go back into every peer to edit.
Solution I am requesting is to be able to add multiple manual subnets of any size to be advertised. So I would add in the FH. It advertises it and everything now works