Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
canoas
New Contributor III

Fortigate - BGP peer groups

Hi all,

 

Do Fortigate Firewalls support "BGP peer groups" by sharing the same outbound policies and setting instead of configuring each BGP neighbor individually and updates replicated to all peer group members.

 

I can't seem to find any docs or commands that support BGP peer group config on a Fortigate like a Cisco or Arista Switch.

 

 

1 Solution
funkylicious
SuperUser
SuperUser

hi,

maybe neighbor-group command is what you are looking here 

"jack of all trades, master of none"

View solution in original post

"jack of all trades, master of none"
6 REPLIES 6
funkylicious
SuperUser
SuperUser

hi,

maybe neighbor-group command is what you are looking here 

"jack of all trades, master of none"
"jack of all trades, master of none"
Toshi_Esumi
SuperUser
SuperUser

canoas
New Contributor III

There only seems to be a range option; i.e., you cannot stipulate the neighbor-group association under a peer config. With Cisco and Arista, however, you can do this. I would need to test to see if the range covers multiple /32 networks and how many entries can be added. In my setup, I don't want to add subnet ranges. This may be a FortiGate limitation. 

Toshi_Esumi

As mentioned in the thread, this part of BGP configuration feature is not in the standards. Each implementation by vendors can be different based on their own interpretation how this should work. As @Yurisk mentioned, you eventually need to test yourself to confirm the behaviors of FGT. No surprise if it's different from other vendors or your expectation.

Toshi    

brandonziots
New Contributor II

Unfortunately this is what I'm seeing as well. The only reference to a set neighbor-group is within config neighbor range. After checking the CLI reference, it does look like you'd be forced to create a unique neighbor-range for each /32 peer. 

canoas
New Contributor III

That is kinda disappointing, I know as @Toshi_Esumi Tosh_Esumi mentioned every vendor has their own BGP implementation, but Fortinet should look at what major networking vendors are doing, such as Arista and Cisco, and follow the same. After all FortiGates connect to Cisco and such, makes the configuration/design more straightforward and much easy to manage.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors