Skip to main content
FortDoog
Explorer
July 25, 2024
Solved

BGP with AWS transit gateway

  • July 25, 2024
  • 5 replies
  • 7951 views

This is a follow up from: https://community.fortinet.com/t5/Support-Forum/AWS-IPSEC-on-BGP-routing-how-to-control-traffic-preference-for/td-p/279609

 

And now my issue is that I have connected the BGP with the VPCs but the routes in between are not being accepted by AWS TGW.

 

This is my situation, from Brazil and Virginia, I need to pass on their routes to Desarrollo. I have the prefix list, the route maps, all the jazz.

BGP diagram_corregido.jpg

 

But for the life of me, I cannot find WHY Desarrollo does NOT show those routes.

  • I can see the routes that set in the "Networks" section being propagated and see them also on the TGW route table.
  • I can see the routes from BOTH, Brazil and Virginia being propagated, but they are NOT on the TGW.

I thought it was the prefix list, set it to Permit ANY, still nothing.

The team I work for had the idea of enabling back the static routes on the firewall and use the Redistribute: Static. And ONLY then, the routes appeared on Desarrollo.

 

Yes, already raised a ticket with support. I know, maybe it is just some dumb thing I don´t see, no expert, I still call myself a newbie on this.

 

After sleepless nights found this while troubleshooting: https://community.fortinet.com/t5/FortiGate/Technical-Tip-BGP-with-AWS-transit-gateway/ta-p/287684

 

Now, my question, that tech tip above does not mention that all devices on the BGP group should have the same AS number, so my question is, and with the graphic above, does that mean that my firewall AS has to match the AWS TGW AS? Is that all the issue???

 

clue.jpg

 

option.jpg

 I say it because I was introduced to the concept of iBGP and eBGP. Apparently I´m doing eBGP but for what I have read, I´m supposed to do iBGP?

 

I´m lost and confused, please help.

 

@Jean-Philippe_P 

@Anthony_E 

@mle2802 

Best answer by Toshi_Esumi

If changing AS at each VPC is not an option, try "as-override" option on your FGT as in below:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-BGP-allowas-in-enable-or-as-override-when-local-AS/ta-p/197448

Toshi

5 replies

slovepreet
Staff
Staff
July 25, 2024

Hi FortDoog, 

-->I can see the routes from BOTH, Brazil and Virginia being propagated, but they are NOT on the TGW.

if the routes are being advertised and not received, the following are the commands that you can start to dig more into what's going on

 

get router info bgp neighbors 10.10.3.1 routes --> replace the Ip with your neighbor IP
get router info bgp neighbors 10.10.3.1 received-route

 

If you are seeing in one output and not another one that means it's being filtered  by the inbound policy 

 

Below article will shed some more light if that would be something that you are experiencing https://community.fortinet.com/t5/FortiGate/Technical-Tip-Difference-between-BGP-received-routes-and-routes/ta-p/272709

 

This is my best possible guess and starting point but a configuration file and more information here would certainly help to understand this more. 

 

I hope this helps 

 

 

FortDoog
FortDoogAuthor
Explorer
July 25, 2024

Hi @slovepreet 

 

I did that, I assumed that I filtered wrong, but then I tested using an empty prefix list set to permit any, and still, only routes on "Networks" were seen, plus a bunch of other stuff. But specifically, not the routes learned from the others BGPs. That´s why I´m more inclined to the tech tip.

 

Forgot to mention, from Brazil and Virginia, I propagated only mgmt routes, so far that works perfect. But the thing is that Desarrollo needs to know the routes from Brazil and Virgina, and that is the problem. I see the advertised routes and supposedly they are being sent but on the TGW are not appearing.

 

What does appear are the static routes the team setup manually and the ones on Networks.

Toshi_Esumi
SuperUser
SuperUser
July 25, 2024

If changing AS at each VPC is not an option, try "as-override" option on your FGT as in below:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-BGP-allowas-in-enable-or-as-override-when-local-AS/ta-p/197448

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!