Technical Tip: FortiGate BFD implementation and examples (Bidirectional Forwarding Detection for OSPF and BGP)
Description
This article describes the Bidirectional Forwarding Detection implementation and examples.
A few words about BFD:
Mechanism detecting a one-way device failure.
Used for faster convergence of routing protocols.
Independent interface media, routing, or data protocol.
Draft RFCs with multiple encapsulation types.
FortiGate uses unicast packets, UDP port 3784 (not routable).
BFD vs 'Fortinet Dead Gateway Detection' (DGD).
Â
DGD:
Simple mechanism, and no specific protocol is needed on the 'ping server'.
Based on ping, hence an L3 routable packet that can detect problems on a far-end network.
Â
BFD:
Fast convergence (<1s).
Devices must be on the same subnet.
Interoperable support of BFD is required between vendors.
Designed for OSPF and BGP.
Â
BFD can be configured at multiple levels:
Device level: Enables BFD for all interfaces and protocols on the FortiGate.
Interface level: Overrides the device-level setting, allowing BFD to be enabled or disabled on specific interfaces.
Protocol level: Enables BFD for a specific routing protocol, such as BGP, regardless of interface settings.
Â
The configuration hierarchy allows each lower level to override the BFD setting of the upper level. For example, if BFD is enabled at the device level, it can still be disabled at the interface or protocol level. This allows for flexible control over BFD behavior.
Â
To configure BFD:
Enable BFD at the required level (device, VDOM, or interface).
Define a BFD neighbor.
Enable BFD on the relevant route or routing protocol.
Â
FortiGate BFD/OSPF operation is described in the following scenarios.
If BFD is configured but not OSPF, no BFD packets are sent.

When OSPF is operational, it is possible to see BFD neighbors together with OSPF neighbors.

BFD failure due to remote router (neighbor) failure.
Â
Starting from the previous state (BFD neighbor is up), the BFD failure detection in this case is immediately followed by a withdrawal of the failed OSPF neighbor, triggering route reconvergence.

BFD packets are seen from the CLI sniffer:
Â
FGT # diagnose sniffer packet any "udp port 3784" 6
0.514603 port7 in 192.168.11.53.49161 -> 192.168.11.54.3784: udp 24
0x0000Â Â 0000 0000 0001 0009 0f12 b95e 0800 4500Â Â Â Â Â Â Â ...........^..E.
0x0010Â Â 0034 508b 0000 ff11 d371 c0a8 0b35 c0a8Â Â Â Â Â Â Â .4P......q...5..
0x0020Â Â 0b36 c009 0ec8 0020 ee8f 20c0 0318 0000Â Â Â Â Â Â Â .6..............
0x0030Â Â 000a 0000 000d 0000 c350 0000 c350 0000Â Â Â Â Â Â Â .........P...P..
0x0040Â Â 0000Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â ..
0.530202 port7 out 192.168.11.54.49164 -> 192.168.11.53.3784: udp 24
0x0000Â Â 0000 0000 0000 0009 0f12 bcfe 0800 4500Â Â Â Â Â Â Â ..............E.
0x0010Â Â 0034 c08f 0000 ff11 636d c0a8 0b36 c0a8Â Â Â Â Â Â Â .4......cm...6..
0x0020Â Â 0b35 c00c 0ec8 0020 ee8c 20c0 0318 0000Â Â Â Â Â Â Â .5..............
0x0030Â Â 000d 0000 000a 0000 c350 0000 c350 0000Â Â Â Â Â Â Â .........P...P..
0x0040  0000                                          ..                                       Â
BFD packets are seen with a packet decoder:

Scope
Â
FortiGate or VDOM operating in NAT Mode and running OSPF or BGP.
Solution
Â
Step 1: BFD must be configured globally and per interface (per neighbor if used for BGP).
Default = 250ms ; threshold = 3.
Â
FGT # config system settings
FGT(settings) # set bfd enable
FGT # config system interface
FGT(interface) # edit port7
FGT(port7) # set bfd enableÂ
Step 2: Configuration at the protocol level.
Configuration example at the OSPF level.
Â
config router ospf
  set bfd enable --> Default = disabled.
    config ospf-interface
      edit dmz
        set bfd enableÂ
Configuration example at the BGP level:
Â
config router bgp
set as 65250
  config neighbor
    edit 192.168.3.254
      set bfd enable
           set remote-as 65254
  Â
Verification with CLI commands:
TestFGT_5 # get router info bgp neighbors --> Shows details of the neighbors, including: Peer IP address, router ID, remote AS, BGP state, and the negotiated capabilities.
BGP neighbor is 192.168.3.254, remote AS 65254, local AS 65250, external link
TestFGT_5 # get router info bfd neighbor
OurAddr        NeighAddr      LD/RD  State  Int
192.168.3.250Â Â 192.168.3.254Â Â 4/1Â Â Â Â UPÂ Â Â Â Â port7
Â
BFD troubleshooting commands (CLI):
 For IPv4:
get router info bfd neighbor
get router info bfd neighbor detail
get router info bfd requests
diagnose test application bfd 1Â Â Â
For IPv6:
get router info6 bfd neighbor
get router info6 bfd neighbor detail
get router info6 bfd requests   Â
BFD debug (CLI):
diagnose debug reset
diagnose ip router bfd all enable
diagnose debug app bfdd -1
diagnose debug console timestamp enable
diagnose debug enable   To stop debug:
diagnose ip router bfd all disable
diagnose debug disable
diagnose debug reset  Â
Notes:
State: returns the current state of BFD (UP).
LD/RD: BFD Local Discriminator / Remote Discriminator used in this BFD session.
From v7.2.0 onward, it is possible to configure the multi-hop BFD.
Â
Related documents:
Technical Tip: Configuring Bidirectional Forwarding Detection (BFD) for static routesÂ
