Hi all,
Do Fortigate Firewalls support "BGP peer groups" by sharing the same outbound policies and setting instead of configuring each BGP neighbor individually and updates replicated to all peer group members.
I can't seem to find any docs or commands that support BGP peer group config on a Fortigate like a Cisco or Arista Switch.
Solved! Go to Solution.
or, look at this recent conversation for examples.
https://community.fortinet.com/t5/Support-Forum/BGP-neighbor-group-implementation/m-p/393281#M269803
Toshi
There only seems to be a range option; i.e., you cannot stipulate the neighbor-group association under a peer config. With Cisco and Arista, however, you can do this. I would need to test to see if the range covers multiple /32 networks and how many entries can be added. In my setup, I don't want to add subnet ranges. This may be a FortiGate limitation.
As mentioned in the thread, this part of BGP configuration feature is not in the standards. Each implementation by vendors can be different based on their own interpretation how this should work. As @Yurisk mentioned, you eventually need to test yourself to confirm the behaviors of FGT. No surprise if it's different from other vendors or your expectation.
Toshi
Unfortunately this is what I'm seeing as well. The only reference to a set neighbor-group is within config neighbor range. After checking the CLI reference, it does look like you'd be forced to create a unique neighbor-range for each /32 peer.
That is kinda disappointing, I know as @Toshi_Esumi Tosh_Esumi mentioned every vendor has their own BGP implementation, but Fortinet should look at what major networking vendors are doing, such as Arista and Cisco, and follow the same. After all FortiGates connect to Cisco and such, makes the configuration/design more straightforward and much easy to manage.
| User | Count |
|---|---|
| 2895 | |
| 1449 | |
| 850 | |
| 825 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.