Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BusinessUser
Contributor

Need vrrp configuration template for special case

FORTGATE FW1 ASN 65000 -- BGP link  --> ISP R1 with PUBLIC ASN 123 

FORTGATE FW2 ASN 65000 -- BGP link -->  ISP R2 with PUBLIC ASN 123

FORTGATE FW1 and FORTGATE FW2 have lan interface that are connected together with switch. 

 

hope this is clear enough.

5 REPLIES 5
xshkurti
Staff
Staff

@BusinessUser 

Check below links:
Technical Tip: FortiGate VRRP configuration and de... - Fortinet Community
VRRP failover | FortiGate / FortiOS 7.4.1 | Fortinet Document Library

Despite that, i assume you should do vrrp even between routers, otherwise how should fertigates connect to R1 or R2.
So you will need vrrp in fortigate where you can follow above links, and vrrp between R1 and R2.

But for routers we can't provide you guides on how to configure them because it depends on the vendor and config steps.

 

If you have found this as a solution, please like and accept it to make it easily accessible for others.

Regards!

@xshkurti 

BusinessUser

ISP is running bgp links with fortigate routers.

Static route with administrative distance wont work

esalija
Staff
Staff

Hi,

You can do a VRRP on the FortiGates and set the static routes with different priorities for R1 and R2, so you don't need to create VRRP for routers.

Best regards,

Erlin

geto25
New Contributor

Not the original commenter, but I believe the answer is that it's not necessary. VRRP specifically provides redundancy for routing/default gateways. If the switches are not routing packets, then there's no benefit or need for VRRP.

https://19216801.onl/ https://routerlogin.uno/
Toshi_Esumi
Esteemed Contributor III

Putting aside the VRRP issue I sense a potential problem with this set up; two FGTs standalone with two circuits from one ISP, depending on how those two circuits work, like active-standby or split traffic/load balance.

It's probably better/safer terminating both circuits on both FGTs by putting at least one switch inbetween then set up HA if those FGT models are the same. BGP peer IPs in ASN 123 have to be different though.

 

Again, it's depending on the operation of the ISP's two circuits.

 

Toshi

Labels
Top Kudoed Authors