Skip to main content
Rahlekk
New Member
March 18, 2024
Question

Adding 26 locations with dual redundant IPSec tunnels - OSPF vs. BGP

  • March 18, 2024
  • 1 reply
  • 1614 views

Hello all,

 

We currently have 26 locations on private MLPS. We will be installing standard internet circuits, as well as a backup cellular connection via Fortiextender.

I want to do a Hub and Spoke configuration; in the past I would simply create an IPSec tunnel over each interface (Primary and cellular backup), and then do OSPF cost based routing for redundancy. (Cellular tunnel would have a higher cost)

However, it seems that my 200F (hub) can only support a maximum of 10 OSPF neighbors. (https://docs.fortinet.com/max-value-table) I would need to add 52 (26 sites, two tunnels each)

Should I be going to BGP instead? If so, how would I configure redundancy between the two tunnel interfaces? I've only done OSPF in the past.

1 reply

knaveenkumar
Staff
Staff
March 19, 2024

Hi 

please refer the below document and use bgp over the tunnel its easy for route manipulation and choose the best path 

 

please refer the below document and configure :

 

https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/820072/advpn-with-bgp-as-the-routing-protocol

https://community.fortinet.com/t5/FortiGate/Technical-Tip-ADVPN-with-BGP-as-the-routing-protocol/ta-p/192437