Skip to main content
AlexFeren
New Member
October 9, 2019
Question

EIGRP through the fortigate in transparent mode - corrected

  • October 9, 2019
  • 1 reply
  • 2683 views

Since original "Eigrp throug the fortigate in transparent mode" thread is locked, I wanted to correct it for posterity.

 

In it, the statement "EIGRP is multicast protocol IP 88" is partially incorrect - indeed EIGRP is BOTH Multicast and Unicast. (For explanation, see "EIGRP startup process - Unicast and multicast Updates containing topology information".)

 

So, enabling multicast-skip-policy is insufficient - a (Unicast) firewall policy to cover protocol 88 is needed.

    1 reply

    emnoc
    New Member
    October 9, 2019

    Your 100% correct that it's not  100% mcast. In fact, OSPF is ALSO  the same and many mistakes that it uses mcast only. Typically neighbor discovery is mcast and updates are unicast for both protocols.

     

    Ken Felix