Technical Tip: How to check BGP advertised and received routes on a FortiGate
Description
This article describes how to check BGP-advertised and received routes on a FortiGate.
Â
Scope
Â
FortiGate.
Solution
Â
Topology:
Â

Â
EBGP peering between FGT1 and FGT2 is up. In this lab setup, both FortiGates are advertising their Loopback interfaces via eBGP to each other.
Outputs from FortiGate1:
FortiGate1# get router info bgp summary
BGP router identifier 3.3.3.3, local AS number 65003
BGP table version is 11
2 BGP AS-PATH entries
0 BGP community entries
Neighbor       V        AS MsgRcvd MsgSent  TblVer InQ OutQ Up/Down State/PfxRcd
10.56.240.2  4     65004   670     667      10           0   0       2d15h37m       2
Total number of neighbors 1Â
Once a BGP connection is established, the field State/PfxRcd will be updated if local FortiGate receives any prefixes from its BGP peer. BGP announces networks in the BGP 'UPDATE' packet. If routes are not advertised or received, the following capture should be performed on the FortiGate:
diagnose sniffer packet any ' Host <BGP Neighbour IP> and port 179' 6 0 l
This capture can be performed from the FortiGate GUI as it provides a Wireshark-readable file: Troubleshooting Tip: Packet Capture on FortiOS GUI.
Example:

FortiGate1Â is advertising and is learning two routes.Â
The command to verify the routes FortiGate1Â is advertising to FortiGate2Â is:
get router info bgp neighbors <neighbor IP> advertised-routesÂ
For example:
FortiGate1 # get router info bgp neighbors 10.56.240.2 advertised-routes
BGP table version is 11, local router ID is 3.3.3.3
Status codes: s suppressed, d damped, h history, * valid, > best, i - internal
Origin codes: i - IGP, e - EGP, ? - incomplete
  Network         Next Hop           Metric LocPrf  Weight  RouteTag Path
*> 3.3.3.3/32Â Â Â Â Â Â 10.56.240.1Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â 100Â Â Â Â 32768Â Â Â Â Â Â Â 0Â Â Â Â Â Â Â Â Â Â Â Â Â i
*> 50.50.50.50/32Â Â 10.56.240.1Â Â Â Â Â Â Â Â Â Â Â Â Â Â 100Â Â Â Â 32768Â Â Â Â Â Â Â 0Â Â Â Â Â Â Â Â Â Â Â Â Â i
Total number of prefixes 2
The command to verify routes that FGT1 is receiving from the BGP peer FGT2 is:
Â
get router info bgp neighborsÂ
The command 'get router info bgp neighbors'Â shows details of the neighbors, including: Peer IP address, router ID, remote AS, BGP state, and the negotiated capabilities.
get router info bgp neighbors <neighbor IP> received-routes
The command 'get router info bgp neighbors <neighbor IP> routes'Â shows only filtered (in) received routes. If received routes are not filtered, the output of these commands will be the same.Â
For example:
Â
FortiGate1 # get router info bgp neighbors 10.56.240.2 route
BGP table version is 11, local router ID is 3.3.3.3
Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,
             S Stale
Origin codes: i - IGP, e - EGP, ? - incomplete
Network         Next Hop           Metric LocPrf Weight RouteTag Path
*> 4.4.4.4/32Â Â Â Â Â Â 10.56.240.2Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â 0Â Â Â Â Â Â Â Â Â Â 0Â Â Â Â Â Â 65004 i
*> 75.75.75.75/32Â Â 10.56.240.2Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â 0Â Â Â Â Â Â Â Â Â Â Â 0Â Â Â Â Â Â 65004 i
Total number of prefixes 2
FortiGate1 # get router info routing-table bgp
Routing table for VRF=0
BÂ Â Â Â Â Â 4.4.4.4/32 [20/0] via 10.56.240.2, port1, 00:50:26
BÂ Â Â Â Â Â 75.75.75.75/32 [20/0] via 10.56.240.2, port1, 00:50:26
Â
For testing purposes, filter received routes on FortiGate1. Apply a prefix-list to allow only 75.75.75.75/32:
FortiGate1 # config router prefix-list
   edit "ALLOW-ONLY-75"
       config rule
           edit 1
               set prefix 75.75.75.75 255.255.255.255
               unset ge
               unset le
           next
       end
   next
end
FortiGate1 # config router bgp
   set as 65003
   set router-id 3.3.3.3
    config neighbor
      edit "10.56.240.2"
        set soft-reconfiguration enable
        set prefix-list-in "ALLOW-ONLY-75"
        set remote-as 65004
      next
end
As seen with 'set prefix-list-in "ALLOW-ONLY-75"', the prefix-list is filtering received routes.
The output below shows all received routes.
FortiGate1 # get router info bgp neighbors 10.56.240.2 received-routes
BGP table version is 11, local router ID is 3.3.3.3
Status codes: s suppressed, d damped, h history, * valid, > best, i - internal
Origin codes: i - IGP, e - EGP, ? - incomplete
  Network         Next Hop           Metric LocPrf Weight RouteTag Path
*> 4.4.4.4/32Â Â Â Â Â Â 10.56.240.2Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â 0Â Â Â Â Â Â Â Â Â 0Â Â Â Â Â Â Â Â 65004 i
*> 75.75.75.75/32Â Â 10.56.240.2Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â 0Â Â Â Â Â Â Â Â Â 0Â Â Â Â Â Â Â Â Â 65004 i
Â
Total number of prefixes 2
The output below shows only filtered (in) received routes.
FortiGate1 # get router info bgp neighbors 10.56.240.2 route
BGP table version is 11, local router ID is 3.3.3.3
Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,
             S Stale
Origin codes: i - IGP, e - EGP, ? - incomplete
  Network                  Next Hop           Metric LocPrf Weight RouteTag Path
*> 75.75.75.75/32Â Â 10.56.240.2Â Â Â Â Â Â Â Â Â Â Â Â Â Â 0Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â 0Â Â Â Â Â Â Â Â Â 0Â Â Â Â Â Â Â Â Â Â Â Â 65004 i
Total number of prefixes 1FortiGate1 # get router info routing-table bgp
Routing table for VRF=0
BÂ Â Â Â Â Â 75.75.75.75/32 [20/0] via 10.56.240.2, port1, 00:55:45
It is possible to filter specific subnets or routes based on AS number etc, with the 'grep' keyword:
get router info bgp neighbors <x.x.x.x> advertised-routes | grep <network subnet>
get router info bgp neighbors <x.x.x.x> advertised-routes | grep <AS number>Â
The following commands will show the IPv6 neighbors, network, the routing table, and received and advertised routes in the CLI:
get router info6 bgp neighbors
get router info6 bgp network bgp
get router info6 routing-table bgp
get router info6 bgp neighbors <x.x.x.x> received-routesÂ
get router info6 bgp neighbors <x.x.x.x> advertised-routesÂ
Note:
If an error occurs after running the 'get router info bgp neighbors <neighbor IP> received-route', then enable the 'set soft-reconfiguration enable'Â command under the BGP neighbor.
For example:
Â
FortiGate1 # get router info bgp neighbors 10.56.240.2 received-routes
% Inbound soft reconfiguration not enabled
To enable soft configuration:
config router bgp
  config neighbor
    edit "10.56.240.2
      set soft-reconfiguration enable    Â
endÂ
This option enables (or disables) allowing IPv4 inbound soft reconfiguration. Once enabled, FortiGate starts storing BGP neighbor-received updates.
Note:
For BGP to advertise any prefixes, the prefixes need to be installed on the RIB first, either by static routes, directly connected, or learned by other dynamic routing protocols. This is not a FortiOS design, but how the BGP protocol works. When the port goes down, the connected route will be removed from the routing table.
BGP prefers the route with the longest prefix length when multiple routes exist to the same destination.
To allow routes to be advertised in BGP that are not installed on the routing table, use the following command:
Â
config router bgp
  set network-import-check disabled
endÂ
This configuration can be applied to a per-prefix network according to the following settings, where 'set network-import-check disable' will override the global 'enable' settings for this prefix.
config router bgp
  set network-import-check enable
    config network
      edit 1
        set prefix 75.75.75.75 255.255.255.255
        set network-import-check disable
    end
endÂ
Under 'config network', the available options for 'network-import-check' are:
global: Use global network synchronization value (default).
enable: Enable network synchronization per prefix.
disable: Disable network synchronization per prefix.
Â
Related article:
