Skip to main content
Liza1
Explorer II
June 20, 2024
Solved

Fortigate OSPF routes

  • June 20, 2024
  • 2 replies
  • 5779 views

Hello, i need your help.
You have one FortiGate and two routers. You need the FortiGate to know routes but not advertise them to the routers. For example, you have Area 10 where Router1 advertises 192.168.0.0/24, and Area 20 where Router2 advertises 192.168.100.0/24. However, when you check Router1, it also knows about Router2's network 192.168.100.0/24. This should not happen. How can you separate these networks? Can route maps or ACLs help? Have you encountered such a situation before? Any information would be valuable to me.


#fortigate #ospf #routemap #acl #routingtable #routes

Best answer by Toshi_Esumi

Or, if you configure those two areas as "totally stub" at the FGT like below, each router wouldn't get routes from the other side (inter-area routes). It would advertise a default route instead though.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuration-of-OSPF-Stub-Totally-Stub-NSSA-and/ta-p/194927
You still need to know how to configure "stub" on the router side.

Toshi

2 replies

Toshi_Esumi
SuperUser
SuperUser
June 21, 2024

Or, if you configure those two areas as "totally stub" at the FGT like below, each router wouldn't get routes from the other side (inter-area routes). It would advertise a default route instead though.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuration-of-OSPF-Stub-Totally-Stub-NSSA-and/ta-p/194927
You still need to know how to configure "stub" on the router side.

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.