Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tnxxxx59
New Contributor II

How to steering BGP traffic on SDWAN Spoke to Hub

Dear all,

 

I have diagram as below:

       --------- tunnel 01 --------------

Hub (lo0)                                      (Lo0) Spoke

       ---------- tunnel 02 -------------

 

I am using BGP on loopback to set up routing via 2 Tunnels. (FortiOS 7.4.4)

And I try to set up SD-WAN Rule to steering BGP traffic (Keepalive, updates...) via tunnel02.

In the sd-wan rule: I set: source is Lo0 of spoke and destination is Lo0 of Hub, Outgoing interface: i used Manual : Tunnel02 is first order and tunnel 01 is last order. Member is 2 tunnel interface SD-WAN zone.

 

But after that, I can not see any hit count on the sd-wan rule, and diagnose packet port 179 : traffic still via tunne01.

 

I am wondering what is my mistaken ? (or BGP update processed by SDWAN rules ?)

 

(I have another sd-wan rule to allow all (all source and all destination), used SLA health-check, it's is working because I saw lot of hit count)

 

 

 

 

 

 

 

 

1 Solution
stroia

No, BGP traffic is considered local traffic so is not managed by SD-WAN rules, I suggest to remove the add route option from IPSec configuration https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-add-automatic-route-towards-the-rem... and add ad hoc static routes for the loopback address configuring a lower distance for the route pointing to the tunnel that you want to prefer.

BR

Seba

Sebastiano Troia
Certified: FCSS Network Security


View solution in original post

6 REPLIES 6
Jean-Philippe_P
Moderator
Moderator

Hello tnxxxx59, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
stroia
Staff
Staff

Hello,

Regarding you question have you created necessary firewall policy to permit the traffic between the loopback interface and the SD-WAN rule as explained here https://docs.fortinet.com/document/fortigate/7.6.1/administration-guide/853005/loopback-interface ?

 

If yes, have you checked if routing to reach the loopback of the remote peer is ok?

 

If yes I suggest to check the BGP traffic logs and the SD-WAN rule status as explained here: https://docs.fortinet.com/document/fortigate/7.6.1/administration-guide/818746/sd-wan-related-diagno... to understand what’s going wrong

Regards

Seba

Sebastiano Troia
Certified: FCSS Network Security


tnxxxx59
New Contributor II

Hi @stroia 

Thank for your information, 

 

I mean BGP is working fine, but I want to steering BGP traffic use SDWAN rules, example: I have 2 tunnels, 01 and 02. And I want to steering BGP traffic via Tunnel02. And I did as I mentioned above, and then check, then see BGP traffic still via Tunnel01 . So my question, SDWAN rule dont take care BGP traffic (BGP keepalive, update ....) ? 

stroia

No, BGP traffic is considered local traffic so is not managed by SD-WAN rules, I suggest to remove the add route option from IPSec configuration https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-add-automatic-route-towards-the-rem... and add ad hoc static routes for the loopback address configuring a lower distance for the route pointing to the tunnel that you want to prefer.

BR

Seba

Sebastiano Troia
Certified: FCSS Network Security


tnxxxx59
New Contributor II

Hi @stroia 

 

Thank you so much ! its make sense 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors