Skip to main content
GonzaloArroyoRey
New Member
November 15, 2018
Question

Route Policy in Dynamic VPN Tunnel

  • November 15, 2018
  • 1 reply
  • 2690 views

Hello Everybody

 

I have several firewalls Fortigate F60D/F60E worldwide and central F200E configured as HUB-spokes and have BGP as routing protocol so, remote firewalls can set up dynamic VPN's and communicate their internals network.

 

My question is if it is possible to configure a Route Policy using this scenario, I tried to configure it but it only allow me physicals interfaces or tunnels-manually configured

 

best regards

 

Gonzalo

    1 reply

    Toshi_Esumi
    SuperUser
    SuperUser
    November 15, 2018

    Do you have only one dialup IPsec phase1-interface on the HUB side and terminating all IPSecs from other FGTs? You probably need to separate the phase1-interface for each peer to set policy routes.

    But BGP generally doesn't work well with policy routes because it always decides the best path for one destination prefix unless you use tricks described below:

    https://www.noction.com/blog/equal-cost-multipath-ecmp

    To make policy routes to work you need to have multiple parallel routes in your routing table ("priority" can be different), like two 0/0 routes pointing to two ISPs and a policy route specify one of them.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!