Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RichardH
New Contributor

IPSec - Int Mode - best dynamic routing protocol

I configured iBGP for 7 locations, I have a partially meshed interface mode ipsec vpn. What should I configure and what has given you the best results? I' m running 4.1.9, 110C, 80C, 60B, 4 x 50B' s. 110C - INT mode to all locations 80C - INT mode to 110C and 2 x 50B' s. All others just have a connection to the 110C and maybe 80C.
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
4 REPLIES 4
emnoc
Esteemed Contributor III

So why do you have iBGP configured? Unless you have an external BGP sessions, than there' s no reasoin to have iBGP enable and it would be a very bad ideal to try to use it as a IGP ( doesn' t scale very well with building out, reflected route adv, no direct automatic neighborship discovery, never was designed as a IGP and so on....) Now to answer your other questions, 1st we need more info and you should think about what you want and need to achieve & understand the difference between dynamic routing protocols RIP would be great for simplicity, but lacks scalability if you networks grows over 20 or so routes ( IMHO). Convergence times sucks and so on. If you need routing on classless boundaries, you could get by with RIPv2, but still it' s not great at growth with higher number of l3-routing devices or heavy numbers of routes [:' (] & like with RIPv1, convergence times sucks. EIGRP is a cisco only, so I can safely rule that out for your question & since we are speaking about Fortigates IS-IS it' s hardly every used , even tho it' s similar to OSPF and in fact easier to understand, due to it only has 2 areas ( levels) & not as complex, convergence times are much faster and as fast or can be tweak fast or faster than OSPF so that leaves OSPF Widely used in the enterprise support by most all vendors hardware ( open protocol), it' s speedy, quick to detect failures and foring route around redundant paths OSPF works very well on Fortigates and I' ve only seen a few problems and bugs with distribution list and methods used within it and when used on a firewall acting as a L3 device.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
rwpatterson
Valued Contributor III

We have been using OSPF here between our FGTs and our other core switches for at least 4 years without issue. Add a new FGT VPN, and walk away. Nice!

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
RichardH
New Contributor

Thanks for the reply emnoc and rwpatterson, I dumped BGP and created static routes. If any growth, I can see 1 location every 3 years due to M&A. I don' t have " reliable" internet connections and 3 out of 7 get packet loss throughout the day. Will I be causing unnecessary network traffice using OSPF with unreliable connections?
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
emnoc
Esteemed Contributor III

Will here' s a suggestion; " the OSPF timers can be adjusted" . So you can have some room with lost of adj over the internet. Just make sure if you adjust the hello and dead timers on one side, that you do the same for the opposite side.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors