Troubleshooting Tip: BGP session flapping in ADVPN hub FortiGate with SD-WAN embedded measured health enabled
| Description | This article describes the cause and resolution of BGP session flapping on an ADVPN hub FortiGate when SD-WAN embedded SLA is enabled. The BGP peering is established over IPsec tunnels between the hub and spokes. |
| Scope | FortiGate (Tested with v7.4). |
| Solution | When BGP passive mode is disabled on the ADVPN hub FortiGate, SD-WAN health-check events can trigger repeated BGP session resets.
When a health check exceeds the configured Service Level Agreement thresholds, the hub resets the BGP session. Check from the hub side with the following commands:
After the health check recovers and returns to an acceptable state, the hub resets the BGP session again, which results in visible BGP flapping.
This behavior occurs only when BGP passive mode is disabled on the ADVPN hub. To resolve this issue, verify that BGP passive mode is enabled on the hub neighbor group.
On the hub FortiGate:
Additionally, review the SD-WAN health-check configuration on both the hub and spoke FortiGate devices. Ensure that recovery time and SLA thresholds, such as latency, jitter, and packet loss, are aligned with application tolerance levels in order to avoid unnecessary traffic failover between SD-WAN members. HUB FortiGate:
Related articles: |


