Skip to main content
sk4
Visitor III
September 22, 2025
Solved

How select next hop for bgp control plane message incase ECMP Route via ike/32 Injection

  • September 22, 2025
  • 7 replies
  • 965 views

I have three static routes to reaching my bgp Neighbour via ipsec tunnel by using ike/32 injection with same AD,metric and priority how fortigate will select the best path for bgp control plane message.
@Jean-Philippe_P @msingh_FTNT @Anthony_E 

Best answer by Toshi_Esumi

Since those are three static routes for the same destination, it would be load balanced based on "v4-ecmp-mode" setting under "config sys settings". But once the first packet establishes a session I wouldn't expect the path changes unless the session times out.

Toshi

7 replies

Anthony_E
Staff
Staff
September 25, 2025

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
Anthony_E
Staff
Staff
September 29, 2025

Hello,

We are still looking for someone to help you.

We will come back to you ASAP.


Thanks,

Best Regards
Anthony_E
Staff
Staff
September 30, 2025

Hi,

 

Did you have a look at this KB article?:

Technical Tip: ECMP routes for recursive BGP next hop resolution

 

Regards,

Best Regards
sjoshi
Staff
Staff
September 30, 2025

Hi @sk4 ,

 

can you share the routing table output

get router info routing-table details x.x.x.x >> where x.x.x.x is the neighbor IP and let me know which interface it should take

Thanks, Salon
Toshi_Esumi
SuperUser
SuperUser
September 30, 2025

Since those are three static routes for the same destination, it would be load balanced based on "v4-ecmp-mode" setting under "config sys settings". But once the first packet establishes a session I wouldn't expect the path changes unless the session times out.

Toshi

sk4
sk4Author
Visitor III
October 9, 2025

Thanks for sharing this. but incase of SDWAN enabled, "v4-ecmp-mode" setting under "config sys settings" is not available as its moved under config system sdwan under set load-balance-mode.

 

Toshi_Esumi
SuperUser
SuperUser
October 9, 2025

I see. You never mentioned you use SD-WAN. 
Or, maybe my knowledge is old and all FGTs now have SD-WAN enabled and the balancing setting is under SD-WAN config by default.

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!