FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
amrit
Staff
Staff
Article Id 367221
Description This article explains the configuration steps required for OSPF with virtual wire pair interfaces.
Scope FortiGate.
Solution

Router 1 and 2 exchange OSPF hello packets through the FortiGate virtual wire pair interfaces (port9, port10).

 

OSPF VWP.JPG 

Virtual Wire Pair (VWP) Configuration:

 VWP Interfaces.JPG

 

VWP Policy:

 

VWP Policy.JPG

 

By default, FortiGate does not forward multicast traffic. Due to this, OSPF hello packets sent over multicast addresses 224.0.0.5 and 224.0.0.6  will be dropped at the firewall. To configure the multicast forwarding, make sure the multicast policy is enabled. In the GUI Navigate to the System -> Feature Visibility -> Multicast Policy and enable the option.

 

Feature Visibility.JPG

 

Create a Multicast Policy between VWP Interfaces:

 

Multicast Policy.JPG

 

OSPF will established between routers.

 

Related articles:

Technical Tip: Creating a virtual wire pair

Technical Tip: Virtual Wire Pair (VWP) and connectivity with Non-VWP interfaces

Technical Tip: Virtual wire pairs