Created on
09-12-2025
03:57 AM
Edited on
11-22-2025
05:44 AM
By
Jean-Philippe_P
| Description | This article describes issues with the Graceful Restart feature when used with BGP neighbor groups and neighbor-range commands. |
| Scope | FortiGate, FortiOS. |
| Solution |
When multiple BGP neighbors must be configured, administrators may streamline the process by creating BGP neighbor groups and neighbor-range commands.
As an example:
config router bgp
Administrators typically also enable the Graceful Restart feature to prevent network disruptions and packet loss during an HA failover or when the primary FortiGate in an HA cluster is rebooted.
When using a BGP neighbor-group is used, packet loss may occur during failover testing.
Conclusion: Since neighbor-groups are passive and cannot trigger a re-connection, it is expected that neighbor-groups defined with neighbor-range cannot perform Graceful Restart when it is the side that initiates a restart.
To prevent packet loss using BGP neighbor-groups on SD-WAN Hubs, each spoke must activate the route-stale option on BGP neighborship with each Hub:
config router bgp config neighbor edit Y.Y.Y.Y set stale-route enable next end
Instead, in order to benefit fully from the Grace Restart feature, BGP configuration would need to be modified to manually configure neighbors instead of neighbor-groups defined with neighbor-range.
Related articles: Technical Tip: Configuring FortiGate HA and BGP graceful-restart to avoid traffic interruption durin... |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.