FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
nkorea
Staff
Staff
Article Id 404605
Description This article describes a known issue with BGP diagnostic commands.
Scope FortiGate v7.6 and earlier.
Solution

On earlier firmware versions, the command 'diagnose ip router bgp <module> <enable | disable>' has a known issue.

 

When enabling or disabling debugging for a specific module, such as 'dampening', all BGP debug categories are enabled or disabled instead, which is not correct.

 

First # diagnose ip router bgp dampening enable

Debug messages will be on for 30 minutes.

 

First # diagnose ip router bgp show

BGP debugging status:

  BGP debugging is on

  BGP nsm debugging is on

  BGP events debugging is on

  BGP keepalives debugging is on

  BGP updates debugging is on

  BGP fsm debugging is on

  BGP filter debugging is on

  BGP Route Flap Dampening debugging is on

  BGP debug level: ERROR

timestamp disabled

 

First # diagnose ip router bgp nsm disable

 

First # diagnose ip router bgp show
BGP debugging status:
BGP debug level: ERROR
timestamp disabled

 

The 'diagnose ip router bgp updates <enable | disable>' command is not affected by this issue. This command correctly enables or disables only BGP updates debugging.

 

The internal issue ID number is 1165424, and the issue is scheduled for fix in FortiOS v7.6.4.