Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Eigrp throug the fortigate in transparent mode

Hi Guys, Am stuck in a problem, am placing the fortigate 1000A firewall in tranparent mode in between cisco router and cisco switch, there is a dynamic routing in between router and the switch i.e EIGRP now i want to pass this traffic through the firewall, though the policy is INT-ALL to EXT-ALL its not working
2 REPLIES 2
OnTheEdge
New Contributor

Hello, EIGRP is multicast protocol IP 88. To allow it passing through the fortigate you will need to do this : config system setting set multicast-skip-policy enable end H@ns
H@ns
H@ns
Not applicable

Dear Sameer, I tested Eigrp through Transparent firewall with the following two versions of FortiOS; (The appliance is Fortinet 100A) 1: Fortigate-100A 3.00,build158,060113 There is simply NO need to add the commands mentioned by OnTheEdge. Just permit the eigrp traffic on both sites anf it will work perfectly. i tested it. 2: Fortigate-100A 3.00-b0733(MR7 Patch 2)[This is the exact version which you have in your 1000A firewalls] I upgraded the version mentioned in point 1 to the newer version i.e. Fortigate-100A 3.00-b0733(MR7 Patch 2) and EIGRP Stops working. I entered the the following commands (Thanks to OnTheEdge) config system setting set multicast-skip-policy enable end After entering above commands EIGRP start working just perfectly fine. There is SIMPLY NO NEED to permit EIGRP (224.0.0.10 address) or EIGRP IP Protcol 88 on the firewall becasue the command set multicast-skip-policy enable will not check for the policies for mulitcast address and all the EIGRP traffice to pass through Transparent Fortinet. Hope this helps and clear things up. Thanks OnTheEdge for you help
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors