Skip to main content
noxka
New Member
July 11, 2025
Question

SDWAN BGP not failing over

  • July 11, 2025
  • 4 replies
  • 1604 views

Our hub and spoke have two ISP's. However when one of our wan connections fails over on a spoke, BGP will continue to try to send the routes to the hub over the downed interface. The only way to make it flip to the correct interface is by editing an SDwan SLA rule or a reboot. I worked with TAC for 4 hours tonight, but didn't have any luck solving it.

We are using BGP over loopback and on version 7.4.8. Anyone else have this issue? If you have a working config, could you post it?

Thank you

4 replies

BillH_FTNT
Staff
Staff
July 11, 2025

Hi noxka,

Could you please share the ticket number? I will try to reproduce the issue in my lab. I believe all the necessary information is already included in the ticket. Thanks

Bill

Potato168
Explorer
July 11, 2025

Can you show me your Routing table when the issue comes up?

I wonder if you should not add any route to the SDWAN interface.

But add those BGP interfaces to an SDWAN zone only.

 

Also, don't make any SDWAN rules, but use "Metric/MED" to control the traffic

toshi-esumi
New Member
July 11, 2025

I really think it's about your strategy/design how to utilize BGP in addition to SD-WAN, or vice versa in your network.
BGP does provide path selection based on the destination addresses/subnets (so-called routes). But can't do this with either source addresses/subnets or applications/traffic types, which can be done by SD-WAN.
So general strategy of using BGP with SD-WAN is
1) get all possible routes via BGP as muti-path instead of having static routes enumerating those manually.
2) use SD-WAN to set fail-over, load-balance, or whatever the rules are to select one of possible paths you would like to set.
Based on this, the admin guide like below is using iBGP to all neighbors (meshed) with multi-path option.
https://docs.fortinet.com/document/fortigate/7.4.8/administration-guide/773406/bgp-multiple-path-support

However, if you just want the paths to certain destinations to fail-over to the other path when a tunnel goes down by using BGP's metric's, such as community+local-preference, MED, ASPath length, you don't need SD-WAN. Just use BGP for those interfaces.

Toshi

toshi-esumi
New Member
July 11, 2025

Forgot to mention, BGP can't do SLA either, which is any SD-WAN's big selling point, not only for FGT's SD-WAN.

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!