FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
AmirZ
Staff
Staff
Article Id 264019
Description

 

This article describes how to configure multiple local-as on FortiGate for eBGP peering and using the global local-as for iBGP peering.

 

Scope

 

FortiGate supports multiple local-as, but saving the BGP configuration fails when local-as is used when adding iBGP neighbors.

 

Error in CLI (using local-as value as remote-as in neighbor configuration level):

 

BGP_Error.JPG

 

Error in GUI:

 

Picture1.png

 

Solution

 

CLI.

Configure the iBGP as the global BGP and use the set local-as command for eBGP neighbors. 

 

bgp_configured.JPG

 

GUI

Under local BGP options, configure the local AS as the AS to be used for iBGP peering. Under Neighbors -> Create New, for iBGP peering, keep the local AS field blank. For eBGP peering, add the local AS required for peering.

 

Picture2.png

 

In the above configuration, neighbor 192.168.1.1 is an iBGP neighbor while 192.168.1.2 and 192.168.1.3 are eBGP neighbors with a different local-as '6500'.

 

Related article:

Technical Note: BGP multiple local-AS configuration and advertisement