| Description |
This article describes an issue where FortiGate fails to share BGP routes after a device reboot due to an improperly configured connect-timer value. |
| Scope | FortiGate and FortiManager v7.4.6/v7.4.7 and ADOM v7.4. |
| Solution |
Problem Overview BGP sessions may fail to establish when a FortiGate is rebooted, and routes will not be shared. This occurs because the BGP connect-timer is set to its maximum value (65535), causing the FortiGate to wait over 18 hours before attempting to establish a BGP connection.
Troubleshooting Steps: Check BGP neighbor status.
get router info bgp summary VRF 0 BGP router identifier 4.4.4.4, local AS number 65000 BGP table version is 1 1 BGP AS-PATH entries 0 BGP community entries
Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 10.4.9.2 4 65000 0 0 1 0 0 00:02:07 Active
Analyze network traffic:
FW# diagnose sniffer packet any '10.4.9.2 and tcp and port 179' 4 10
Configuration Review:
config router bgp
Explanation: The issue can be seen when using FortiManager's BGP provisioning templates in v7.4.6 and 7v.4.7. When creating BGP templates, an invalid default connect-timer value is initially set. While FortiManager validates this and allows correction, the value typically defaults to 65535 seconds. This excessive delay prevents BGP connections from establishing in a reasonable timeframe. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.