Description | This article provides info on how to allow EIGRP packets to traverse through the Virtual wire pair interfaces on FortiGate. |
Scope | FortiGate |
Solution |
Virtual Wire Pair: The Virtual Wire Pair allows to configure 2 interfaces with no IP address configuration in them.
All the traffic received by one interface in the pair can only be forwarded out to the other interface which is controlled by the firewall policy.
The CLI configuration for the Virtual Wire Pair config is as below :
erbium-kvm140 (test) # show
EIGRP uses the Multicast IP address 224.0.0.10 to send the hello packets which establishes the neighbourship. The Multicast traffic has to be allowed on the Virtual Wire Pair interfaces for a successful neighbourship.
The CLI configuration for the Multicast policy is as below :
erbium-kvm140 (1) # show
Once the Multicast policy is configured the EIGP packets can traverse via the configured interfaces:
diagnose sniffer packet port5 "proto 88" 4 0 interfaces=[port5] |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.