Skip to main content
arismonty_beato
New Member
September 8, 2019
Question

OSPF over IPSec VPN : Interface cost not being respected

  • September 8, 2019
  • 3 replies
  • 3741 views

Hello,

 

I am able to configure OSPF over IPSec tunnel, but:

 

- I have another OSPF interface (through a physical interface) with lower cost that is Up and routes in the routing table are using this preferred link with correct cost.

- When the IPSec tunnel comes Up, the routing table is modified; routes are now using the IPSec interface although I have defined a higher cost for the VPN interface... looks like something is forced.

 

Has anyone come across a similar situation?

 

 

Thanks,

 

Monty.

3 replies

emnoc
New Member
September 8, 2019

No ,but you could use a . route-map and tag the routes and over the  ipsec-tunnel you adjust the metric.

 

With out seeing the cfg and route-table we will not know how to adjust the issue. Are the two routes 100% the same ( same prefix same prefix-length ) ?

 

Ken Felxi

 

arismonty_beato
New Member
September 8, 2019

Thanks Ken, 

 

The routes are exactly the same, as both links are between the same 2 fortigates.

 

I will check into the route map and tagging, but I've never seen this behavior with multiple Ethernet or VLAN links, even if it is between the same 2 fortigates... it seems to be something special with VPN.

 

 

 

Regards,

 

Monty

Timur
New Member
August 11, 2026

I have same issue, routes between directly connected OSPF neighbors  through physical interface replaced by routes received through another area member connected though IPSec. 

arismonty_beato Have you find the solution?

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!