Skip to main content
amseamans
New Member
March 26, 2019
Question

Fortigate and MPLS moving

  • March 26, 2019
  • 8 replies
  • 14922 views

I searched the forums and saw different things and just got more confused. LOL 

 

Here is our current set up (simplified). 

We have fortigate 200E at two sites. We have S2S VPn between the sites that are always active. We also have an MPLS circuit between the sites. The MPLS is currently on our Core switch and using BGP to announce routes to the other site (and a couple more MPLS connected sites). The ISP side has an IP of our LAN on it as the "gateway" for routing across the MPLS. There are static routes for the other sites on the core switch which can be changed between the fortigate for S2S traffic in the event that the MPLS is down.  There are also routes for use of the MPLS.  I want to move the MPLS to our fortigates so we can do some more things with it and so we can add our new redundant core switches. The issue is i am not sure how to connect the MPLS to the fortigate since the IP is in the same range as the LAN.  Do i just add another LAN ip to an interface and then have the BGP neighbors look at that IP address? I can do the routing in the fortigate and such once i get it connected properly.  

8 replies

Toshi_Esumi
SuperUser
SuperUser
March 26, 2019

Moving the MPLS circuit from the core-sw to FGT should be easy. You just need to copy the BGP config to the FGT with a new IP and the ISP need to change the neighboring to the FGT IP.

But if you want to merge two paths to the same destination into one BGP domain, you need to design the entire network properly including AS paths. I'm assuming it's L3 MPLS with eBGP over the ISP. Then S2S VPN would be a shorter path ASpath-wise, if you don't manipulate metrics.

amseamans
amseamansAuthor
New Member
March 27, 2019

Not looking to merge paths as we will be removing the MPLS circuits next year and moving to SD WAN or something like that. The MPLS is horrible for us. 

 

Any ways to understand what you are saying... 

Don't get on me about the IPs this was done prior to me. LOL

 

Site A:

LAN IP of FGT: 192.168.1.7

Core Switch IP: 192.168.1.10

IP of MPLS (carrier Side): 192.168.1.254 

 

Site B:

LAN IP of FGT: 10.64.0.3

Core Switch IP: 10.64.0.5

IP of MPLS (carrier side): 10.64.0.254

 

So if I move the MPLS to the FGT I need to change the IP for the MPLS side to something different and add another IP range to the interface for the MPLS? correct? Like Below 

 

Site A:

LAN IP of FGT: 192.168.1.7

Core Switch IP: 192.168.1.10

IP of MPLS (carrier Side): 10.0.0.1

IP of MPLS on FGT: 10.0.0.2

 

Then the BGP on the FGT at Site B would have the 10.0.0.2 as its neighbor.  

Toshi_Esumi
SuperUser
SuperUser
March 27, 2019

It's depending on the MPLS provider but I wouldn't expect any particular change necessary. From the provider's view, the BGP neighbor 192.168.1.10 devices will change from your core sw to the FGT. Nothing else would change. If you want to keep the .10 IP on the sw instead of moving it to the FGT, and the FGT has like .11, the provider just needs to change the neighbor IP to .11 instead.

Just talk to the vendor, and schedule a maintenance window with them if that's the case.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!