Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
blason
New Contributor

Can we terminate MPLS on fortigate firewall?

Hey Guys, I have a fortigate 100D and other Side I am taking FG80c wondering if I can terminate MPLS on firewall since I am sure it need to have MPLS interface to decode the labels attached to every packet
5 REPLIES 5
emnoc
Esteemed Contributor III

In short no. Why do you think you need to terminate labels? If you have a MPLS provider they will provide you a hand-off from a edge router. Actually called a customer-edge router. This interface will be IP and does not swap/pop/add labels You would stick this interface , ip_address your enable and enable your dynamic routing protocol iaw with your mpls contract.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
blason
New Contributor

Absolutely this is what I wanted to confirm where general topology is. The MPLS will be terminated on router from there I can have eth pointed out to firewall, right?
emnoc
Esteemed Contributor III

yeap, that' s typically what they do. They should provide you the l3 address, type of hand-off, and most likely the BGP info to include; their AS@ and expected AS# from your side if your deploying BGP ( most like you are ) Did you get a deployment or layout design documentation, with your order.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
blason
New Contributor

So on the same basis, I have actually posted a similar question in other forum and would like to know if I can implement ECMP with MPLS as well as P2P link between my HO and branch office? or is ECMP can only be implemented on Wan1 and wan2 interfaces? I do have ISP configured on WAN1 and then planning to terminate MPLS on WAN2 and then p2P link on dmz and looking to configure load balancing between WAN2 and DMZ interface using ECMP, possible?
emnoc
Esteemed Contributor III

If the routes are Equal, than ECMP would care less if the interfaces are wan1 2 or port 3 or 4. Routes must be equal cost. Have you considered maybe pbr instead and direct some other traffics by protocol type over the p2p? Other option would be to use it as a spill over. Both of these are well documented on kb.fortinet site.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors