FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ddabhade
Staff
Staff
Article Id 219035
Description This article provides information regarding the supported option for BGP extended community RT and SOO in FortiGate.
Scope FortiGate, BGP.
Solution

The extended community RT and SOO can be set in a route-map, but the route-map cannot match the remote peer.


By design, FortiGate does not support an extended community match in a route-map.

 

BGP Test Topology:

 

FG101F-6 (10.109.16.249) --------- BGP ------ (10.109.21.109) universe-esx21 (FortiGate VM)

 

ddabhade_0-1659104158426.png

 

Route-map config on FG101F-6: The Extended community RT and SOO can be set.

 

ddabhade_1-1659104242587.png

 

BGP config and Remote end:

 

ddabhade_2-1659104381905.png

 

Getting extended community SOO and RT from the neighbor 10.109.16.249:

 

ddabhade_3-1659104451472.png

 

There is no option in the route-map to match extended community. There is only an option to set extended community.

 

Note: FortiOS v7.2.0 and above FortiGates support the L3VPN(RD, RT) feature. Refer to the following document for more information.

https://docs.fortinet.com/document/fortigate/7.2.0/new-features/810981/sd-wan-segmentation-over-a-si...

 

Contributors