Hi all,
Do Fortigate Firewalls support "BGP peer groups" by sharing the same outbound policies and setting instead of configuring each BGP neighbor individually and updates replicated to all peer group members.
I can't seem to find any docs or commands that support BGP peer group config on a Fortigate like a Cisco or Arista Switch.
Solved! Go to Solution.
or, look at this recent conversation for examples.
https://community.fortinet.com/t5/Support-Forum/BGP-neighbor-group-implementation/m-p/393281#M269803
Toshi
There only seems to be a range option; i.e., you cannot stipulate the neighbor-group association under a peer config. With Cisco and Arista, however, you can do this. I would need to test to see if the range covers multiple /32 networks and how many entries can be added. In my setup, I don't want to add subnet ranges. This may be a FortiGate limitation.
As mentioned in the thread, this part of BGP configuration feature is not in the standards. Each implementation by vendors can be different based on their own interpretation how this should work. As @Yurisk mentioned, you eventually need to test yourself to confirm the behaviors of FGT. No surprise if it's different from other vendors or your expectation.
Toshi
User | Count |
---|---|
2403 | |
1290 | |
778 | |
528 | |
454 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.