Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ForgetItNet
Contributor

Connection across Hub and Spoke BGP

Hi all,

 

We've got a number of sites using Fortigate 60E routers and they are connected via Hub and Spoke to our Head Office which uses a Fortigate 100F using BGP. There is currently no connection between the sites themselves across the HUB (that I'm told) so site A can't connect to Site B but Head Office can connect to both but I've been asked to allow a connection for CCTV (the CCTV is on the normal LAN.... no VLAN) from Site A to Site B which I can't seem to get to work in that as there are IPSEC tunnels from the sites to Head Office then do I need any static routing in place on any of the sites routers (although I've tried this) and where do I need Firewall rules (again I've tried various ones)? I've tried every combination that I can think of without success however there does seem to be a connection between site A and site C that was already setup as I can ping site C from site A but again I can't see ANY static routing or firewall rules in place for this so I can't see how this is working to replicate it ?

I've also ran packet tracer on all 3 routers (site A,B and head office) and I can't see any traffic coming from or to the device on site A that I can ping site C from so I'm a little lost.

Any broad idea would be helpful.

Thanks

 

EDIT: Just found on site A router in the routing table that site C is in there as "recursive is directly connected NAME_1" but the other sites (i.e B etc) is in there as "recursive via NAME tunnel" NAME being the name of our company so i suspect this is how one site is connected but how/where do i do this for the other sites ?

7 REPLIES 7
Toshi_Esumi
SuperUser
SuperUser

You must be using iBGP without knowing the basic design concept of the protocol, the router doesn't re-advertise iBGP-learned routes to another iBGP neighbor. For that reason, we use eBGP for this kind of topology.


Either you need to convert them to eBGP, which is very simple by changing all spoke's APNs to a unique one in 64512-65535 range and match them at HQ's neighbor config, or you need to learn how to set up a route reflector at HQ.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-BGP-route-reflector/ta-p/19150...
Please note at the bottom of the KB saying you can't manipulate some BGP route attributes at the route reflector.


Actually I haven't used a route reflector before because we always use eBGP due to those restrictions coming with the reflector.

Toshi

ForgetItNet
Contributor

Thanks, I'll look at that but if it doesn't re-advertise the routes then how come ONE of the connections works ? would this have been edited manually ?

Toshi_Esumi

As in the KB's first diagram, iBGP assumes all members in the domain (org) are connected each other in mesh topology. That's why a router doesn't re-advertise to another member.

Toshi

ForgetItNet
Contributor

I think I've "partly" figured this out....I've added the IPSEC widget on the 2 sites that are connected and it's showing 2 IPSEC tunnels, one from the site to Head Office (the Hub) and then another to the other site so this is how they're connected however if I going into the VPN menu on the left and choose IPSEC tunnels then the second one (between the 2 remote sites) doesn't show, only the one to the HUB shows ?

tanostu7
New Contributor

Appreciate the info. I was able to get the routing working by enabling 'ebgp-multipath' on the hubs. This allowed both WAN interfaces to show up on the routing table, whereas before I wwas only seeing one https://omegle.onl/ .

Toshi_Esumi

That's called ECMP (Equest Cost Multiple Paths) with BGP. BGP always decides the best path without it.
By the way, as you already know, once you start using routing protocols like BGP, you need to use CLI all the time to troubleshoot or monitor. GUI's capability is limited.

Toshi

ForgetItNet
Contributor

so are you saying that BGP has created this second IPSEC tunnel ?

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors