Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
CLI Command to add OSPF Passive Interface
Right now, in order to add a passive interface to OSPF I need to enumerate all of the existing passive interfaces, plus the new one. Am I missing an easier way, perhaps a passive-interface-default or passive-interface-default-except option?
Example:
I currently have this config:
config router ospf
set passive-interface VLAN10 VLAN20 VLAN30
end
in order to add VLAN40, I need to know all of the existing passive interfaces, and tack on VLAN40
config router ospf
set passive-interface VLAN10 VLAN20 VLAN30 VLAN40
end
Is there a way to simply tack on VLAN40 to the existing config?
3 REPLIES 3
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I' m pretty sure you' re thinking of the equivalent Cisco or Juniper commands where you set OSPF to have all interfaces passive by default and then enable specific interfaces.
I combed through the CLI reference and it appears that with the Fortinet implementation you have to manually make each interface passive and there is no easier, default passive way.
A Real World Fortinet Guide
Configuration Examples & Frequently Asked Questions
http://firewallguru.blogspot.com
A Real World Fortinet Guide Configuration Examples & Frequently Asked
Questions http://firewallguru.blogspot.com
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I can confirm there' s no easier way to do this. You have to make a procedure (mental note) to add a network to the passive interfaces every time you add new network that doesn' t participate in the OSPF network.
Rackmount your Fortinet --> http://www.rackmount.it/fortirack
Rackmount your Fortinet --> http://www.rackmount.it/fortirack
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
In FOS 5.0 there is a new CLI command " append"
You can use like this:
config router ospf
append passive-interface VLAN40
end
This will simply add VLAN40 to the interface.
FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C
FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice,
60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail
100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B,
11C
