Created on 10-01-2024 11:57 PM Edited on 11-28-2024 11:50 PM By Jean-Philippe_P
Description |
This article describes that there may be times when the BGP neighbors may show up as Idle (Admin).
This is usually seen when the neighbor, interface has been administratively disabled or shut down. Sometimes this is even when the interface is Up and the BGP neighbor is not in a shutdown state. Running a sniffer packet on port 179 results in 1-way BGP TCP traffic with FortiGate sending the FIN packet to BGP TCP traffic.
BGP debug shows the following message:
BBGP: [NETWORK] Accept Thread: Incoming conn from host 10.201.99.254 (FD=28 VRF=0) |
Scope | FortiGate. |
Solution |
To fix this, shut down and unshut the BGP neighbor as such:
Shutdown the BGP neighbor first:
config router bgp
Wait for 30 seconds and Unshut:
config router bgp config neighbor edit <bgp-peer> unset shutdown end end |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.