Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ronish_Shrestha
New Contributor

BGP over IPSec VPN Tunnel Query

Hello Team,

 

So i have a query regarding IPSec VPN Tunnel over BGP.

 

There is BGP on the both side i.e, Remote and Local Site. whereas, the remote site has requested to establish IPSec VPN over BGP. But the problem arise when in the Local site BGP is announced in the Cisco Router.

 

Do we need to configure the VPN in the VPN Firewall or Cisco Router????

 

Please share us the solution.

Thank you

IPSec VPN over Bgp.png

Ronish
Ronish
3 REPLIES 3
ShaileshMdr
New Contributor III

Yes.. I have the same query. Can anyone help?

 

#nse4
#nse4
Toshi_Esumi
SuperUser
SuperUser

BGP is just for routing to provide the reachability between both ends of the IPsec tunnel. Nothing is different from you set the routing up all static routes. Based on the diagram, I'm assuming both sites are peering with each (or the same) ISP with BGP.  If the Cisco router on the local side is NATing traffic and the FGT doesn't have a (static) public IP, reachable from the remote end, itself, you need to configure aggressive mode (IKEv1) or dynamic (IKEv2) on the local side.

Toshi

Mrinmoy
Staff
Staff

In case of routing (Dynamic/ Static) between 2 VPN devices (Router/ Firewall) should be configured on those devices.

Other than those 2 devices all other intermediate devices are just ensuring the reachability between 2 devices. Those devices (in most cases ISP) may follow any routing protocol.

I am sharing the following article as a reference

https://community.fortinet.com/t5/FortiGate/Technical-Note-Dynamic-routing-BGP-over-IPsec-tunnel/ta-...

Mrinmoy Purkayastha
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors