Description |
This article describes how to avoid static route invalidation when using BFD.
BFD neighborship can be established on the IPsec VPN tunnel interface's IP address.
The requirement is to ensure that the remote IP subnet mask is set to /32. If the subnet mask is configured with other values, the BFD neighbor will still come up, but as soon as it becomes attached to the static route, it will automatically invalidate the route (put it in an inactive state). As a result, the route will not be installed in the routing table.
See more details in the example below. |
Scope | FortiOS. |
Solution |
Topology:
show system interface FWB
show router static 2
get router info bfd neighbor OurAddress NeighAddress State Interface LDesc/RDesc
get router info routing-table database | grep 192.168.40.0
get router info routing-table database | grep 192.168.40.0
Related documents: Technical Tip: Configuring Bidirectional Forwarding Detection (BFD) for static routes |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.