Skip to main content
v_nikolaev
New Member
July 7, 2021
Question

ospf over ipsec

  • July 7, 2021
  • 1 reply
  • 1736 views

Hello. I need help with ospf. I have done ipsec tunnel and i try to add grey ip for routing on the ipsec tunnel. I need to add ip addresses on the  both side with mask /30, for example 172.17.250.80/30, 81/30 on the one side and 82/30 on the other side.

I can add:

ip 172.17.250.81

Netmask 255.255.255.255

Remote IP/Netmask 172.17.250.82 255.255.255.252

and

ip 172.17.250.82

Netmask 255.255.255.255

Remote IP/Netmask 172.17.250.81 255.255.255.252

That is normal? After i have added ip over ipsec i add this into ospf by classical scem. I have added interface and network 172.17.250.80/30 one the one side and transfer this prefix to  other segment on the other equipment(cisco). I got  preffix 

172.17.250.81/32, than is normal? I did't have done ospf on the other side yet. If i will have done ospf on the other side, i will get  172.17.250.82/32 and are these will be working? You have to get network address as usually and these type of getting preffix from ospf is strange for me. I need some advice. that is normal for fortigate and that wiil be working? i need exchange preffixes between ospf devices

    1 reply

    Toshi_Esumi
    SuperUser
    SuperUser
    July 7, 2021

    Yes, that's (/32s) normal with FGTs for IPSec interface IPs. You can use /30 for ospf network prefix statement.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!