I am running a SDWAN infrastructure with one Hub and several spoke (15 spokes). All sites are equipped with FGT clusters running 7.2.x. we have ADVPN configured with iBGP running over it for route advertisement .On 4-5 spoke sites I have a strange behavior that is every 2-3 days have this error in router events logs as below:
BGP: %BGP-5-ADJCHANGE: VRF 0 neighbor 192.168.88.254 Down Hold Timer Expired
BGP: %BGP-3-NOTIFICATION: sending to 192.168.88.254 4/0 (Hold Timer Expired/Unspecified Error Subcode) 0 data-bytes []
BGP: %BGP-5-ADJCHANGE: VRF 0 neighbor 192.168.88.254 Down BGP Notification FSM-ERR
BGP: %BGP-5-ADJCHANGE: VRF 0 neighbor192.168.88.254 Up
The problem is that during this event all connections from spoke to hub are shut during roughly 60 or 120 sec
We did that in addition to removing "redistributed connected" and "redistribute static", our thought process was we needed to make sure the only things we put into the route table were intended to be in the route table. We are wrapping up our deployment now and I still see BGP flap's in our logs, but 99% of those are chalked up to cheap broadband / cellular connections.
User | Count |
---|---|
2593 | |
1382 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.