Description | This article describes steps to use firewall address objects and address groups (of the ipmask or interface-subnet type) as BGP network prefixes. This feature simplifies BGP configuration by leveraging existing firewall objects, ensuring alignment between firewall and routing policies, and enabling dynamic prefix updates. |
Scope | FortiOS 7.6+. |
Solution |
Manually defining BGP prefixes can lead to configuration errors and inconsistencies, especially in dynamic environments like SD-WAN or multi-tenant setups. By linking firewall address objects and groups to BGP, administrators can:
Define an address object and enable routing support.
Combine multiple address objects for scalable prefix advertisement.
Reference the address object or group in the BGP network configuration.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.