Dynamicly assign subnets to objects based on BGP community strings
As suggested by my contacts within Fortinet, I'm posting this on the community page as well.
In a network that is fully leveraging BGP for any routing decisions by matching (extended) community strings, it would be nice if the community string was able to control which firewall rule gets applied to traffic as well.
Since Customer traffic is already tagged using extended communities, it would be trivial to add an additional community string in the provisioning template on the PE routers. This community string is then propagated using BGP across the backbone towards a FortiGate cluster. FortiGate reads the community string and adds the received prefix to an object (e.g.: Address objects) and traffic will be handled as determined by rules/policies setup for said object. To illustrate:

FortiOS can already assign users/addresses dynamically using the Radius SSO feature, but it cannot do this based on BGP (extended) communities at this time.
The current suggestion from Fortinet is to use an "external connector", which can analyze BGP community strings and create address lists. The connector then provides the list of addresses to the FortiGate (API/CLI).
Has anyone tried using BGP attributes to selectively assign firewall rules/policies? If yes, how did you achieve this?
Edit: If you also want this as a feature in FortiOS, give this post a thumbs-ups.
