How to Optimize BGP Route Switching and HA Failover with BGP over IPSEC
Dear Sir,
I have a Fortigate Cluster consisting of two units in the main center, and another Fortigate Cluster with two units in the backup center. There is also a single Fortigate unit at a branch location. IPSec VPN tunnels are established between the branch, main center, and backup center. They have implemented iBGP routing on these devices. I have observed that when the primary node in the main center fails, the BGP routes on the branch Fortigate device switch to the primary node in the backup center, and it takes several tens of seconds to switch back to the BGP routes on the main center node. Is it possible to configure the branch Fortigate device not to switch its BGP routes during the main center's HA failover? Alternatively, can the downtime during the switch be reduced to less than 5 seconds?
