Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Martyfish
New Contributor

BGP Setup

I apologize for the length of the post. And I will say that I am not a networking genius.

I have a 200F. We recently had to get a p2p connection to one of our clients in another state. It was decided to go with Lumen (That is a whole another story). Lumen set up an IP VPN circuit between the two locations.

Turns out that a static route will not work, we need to set up BGP. I already have BGP set up for out main internet connection.

I know that I can set up a new neighbor with different Remote and Local AS's and add it to the interface of the p2p. What I not familiar with is setting up the route map.

I have an ip pool setup so that all traffic coming from my end looks like it is coming from 10.10.15.xxx and needs to route to 192.168.40.100 on the other end.

Any links to any docs will be really appreciated.

7 REPLIES 7
funkylicious
SuperUser
SuperUser

so, you SNAT all your traffic from A.A.A.A with 10.10.15.x towards 192.168.40.100.

basically, on this BGP setup you need to make sure that you receive that subnet ( 192.168.40.x/y) and you advertise the NAT pool ( 10.10.15.x ) so the traffic know where to return.

"jack of all trades, master of none"
"jack of all trades, master of none"
Martyfish

Yes, that is correct. I am trying to figure out how to advertise the NAT pool.

funkylicious

two options in my opinion, could be others.

1. create a static route towards blackhole and then advertise the prefix in BGP

or

2. https://community.fortinet.com/t5/FortiGate/Technical-Tip-Advertise-a-BGP-route-not-present-in-the-r... w/o needing a static route

"jack of all trades, master of none"
"jack of all trades, master of none"
TE
New Contributor II

for option 1, don't forget to redistribute static.

Toshi

Martyfish
New Contributor

Thanks all, this is a good start. When I might do for ease is not do the ippool/snat.

TE
New Contributor II

That's a completely different issue why you need the SNAT, or not.
Once start using BGP, it's inevitable to use route-maps, prefix-lists, etc. Or that's the reason you want to use BGP instead of OSPF, which is limited for route filtering within an area. It's a good opportunity for you to learn BGP.

Toshi 

Toshi_Esumi

Looks like I accidentally logged in with a different email address. But it's me.

Toshi

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors