Hi,
We are planning to run VRRP on vlan interfaces between two fortigate and is there possibility to use VRRP IP address as BGP endpoint?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Using BGP and VRRP won't work properly in case of failover. Indeed, the BGP establishment will be up and running on the first FortiGate, but the BGP context are not synchronized between the FortiGate. If you are running in HA (FGCP or FGSP), then the routes will be synchronized, but not the BGP information. Generally, the best solution to have a good failover time using BGP is : * run FortiGate in HA (FGCP or FGSP) * enable session synchronization (if you want a stateful failover with a continuity of the TCP sessions) * enable BGP Graceful-Restart on the FortiGate and the remote-peer. * tune the route-ttl (under config system ha) to have the traffic going through the slave unit without interruption after the failover, while the BGP graceful-restart is going on.
This is document in HA documentation, and in KB: https://kb.fortinet.com/k....do?externalID=FD31743
Best regards,
Benoit
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.