Dynamic BGP (Neighbor-group) over the ADVPN spokes in Fortigate Hub-Spoke solution
Hi everyone,
I am using 1 Hub, 2 spokes, FortiOS 7.6.3, ADVPN 2.0, BGP loopback peering without overlay IP.
So, every things is good, ADVPN works right, just a problem for peering dynamic BGP between spokes.
When spoke to spoke wants to speak (test by loopback addresses), auto shortucky is established, Good, but spokes cannot established BGP peering, based on my diagnose, TCP 179 will be drop due no match selector in IPsec, it seems that problem is the Tunnel between spokes but no, tunnel will established without any problem, but BGP cannot.
I should note that if I use 'execute restart router' , so spokes start to establish BGP peering! it means that tunnel is not problem.
The main problem is that BGP peering starts to etablish between spokes before complete establishing tunnel.
So, I am looking for a way to make some delay, just a second or 2 second in BGP peering process or restart BGP peering establishing between spokes after ADVPN establishing.
Can you help me how can I do it ?
