Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HS08
Contributor

ADVPN, BGP, SDWAN Route

I ADVPN with BGP and SDWAN enabled, is add route in the VPN Phase1 Interface should be enabled or diasbled?

 

1 Solution
Dhruvin_patel

Greetings!

 

In an ADVPN setup with BGP and SD-WAN enabled, the "add-route" setting in the VPN phase1 interface should be disabled. This allows BGP or another dynamic routing protocol to handle route announcements instead of IKE injecting the route.

 

Please refer the document: http://docs.fortinet.com/document/fortigate/7.6.3/administration-guide/820072/advpn-with-bgp-as-the-...

 

Best Regards!

Dhruvin Patel

View solution in original post

4 REPLIES 4
Dhruvin_patel

Greetings!

 

In an ADVPN setup with BGP and SD-WAN enabled, the "add-route" setting in the VPN phase1 interface should be disabled. This allows BGP or another dynamic routing protocol to handle route announcements instead of IKE injecting the route.

 

Please refer the document: http://docs.fortinet.com/document/fortigate/7.6.3/administration-guide/820072/advpn-with-bgp-as-the-...

 

Best Regards!

Dhruvin Patel
HS08

how about 'update static route' in SDWAN, should be enabled or disabled?

djp
New Contributor III

Update static route should be disabled as you do not care about tearing down sessions as you are in a shared session state with just different transits.

^ may be too much info, but "update static route should be disabled"

Toshi_Esumi
SuperUser
SuperUser

Since you already have it set up, and if you just want to know the current config,

config vpn ipsec phase1-interface
    edit [phase1-interface-name]
        get | grep add-route
 end

Toshi

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors