Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
smorty11
New Contributor

FortiGate BGP Route leaks

Hi, I am hoping someone may be able to help. I currently have BGP peers set up for the Internal network and then the DMZ, separate VRFs in the DC but same VRF on the FortiGate.

Servers in the DMZ currently can’t access the internal networks because they are not learning the routes so I need to leak the learned routes from the Internal BGP peers so traffic coming from the DMZ knows which way to route via the FortiGate.

I can see the DMZ traffic hitting the DMZ interface but then not traversing the firewall. IPv4 policies are in place.

I’ve been reading forums and the advice is route-maps but unsure how to go about this.

Any help would be greatly appreciated.

showbox speed test
21 REPLIES 21
Adam19892000

Will it specify whether iBGP or eBGP is used in the config? 

The other side of the BGP is Cisco ACI and uses MP-BGP so this should be fine. I would have to check with the service provider regarding the Internet peer. 

So, in theory, if I change from iBGP (which we assume is being used) to eBGP then that will automatically allow for routes to traverse or will I then have to add route-maps etc still? 

Adam

Toshi_Esumi
SuperUser
SuperUser

What makes it iBGP or eBGP is what ASN both sides of peering have. If both are like 64512, it's iBGP.  But if 64512 one side and 64513 on the other, it's eBGP.
As you said before peering with the FGT has nothing to do with MP-BGP. That's just for inside of Cisco ACI network (I think, because I have no knoledge about Cisco ACI) and peering with FGT is just one instance of VRF on the Cisco to the FGT in plain BGP. We do this between Cisco 7600 MPLS network with multiple FGT clusters.

In our case, the Cisco side has our company's public ASN then we set a private ASN on the FortiGate side (64512-65535 range). So that the peering is always eBGP.

 

Yes, when you have eBGP peering both sides advertise basically everything it has to the peer. Likely you have to filter them with route-maps.

 

You might want to get support from Cisco how to configure eBGP peering with an outside device like the FGT on the Cisco side.

 

Toshi

 

Labels
Top Kudoed Authors