FORTGATE FW1 ASN 65000 -- BGP link --> ISP R1 with PUBLIC ASN 123
FORTGATE FW2 ASN 65000 -- BGP link --> ISP R2 with PUBLIC ASN 123
FORTGATE FW1 and FORTGATE FW2 have lan interface that are connected together with switch.
hope this is clear enough.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
@BusinessUser
Check below links:
Technical Tip: FortiGate VRRP configuration and de... - Fortinet Community
VRRP failover | FortiGate / FortiOS 7.4.1 | Fortinet Document Library
Despite that, i assume you should do vrrp even between routers, otherwise how should fertigates connect to R1 or R2.
So you will need vrrp in fortigate where you can follow above links, and vrrp between R1 and R2.
But for routers we can't provide you guides on how to configure them because it depends on the vendor and config steps.
If you have found this as a solution, please like and accept it to make it easily accessible for others.
Regards!
ISP is running bgp links with fortigate routers.
Static route with administrative distance wont work
Hi,
You can do a VRRP on the FortiGates and set the static routes with different priorities for R1 and R2, so you don't need to create VRRP for routers.
Best regards,
Erlin
Not the original commenter, but I believe the answer is that it's not necessary. VRRP specifically provides redundancy for routing/default gateways. If the switches are not routing packets, then there's no benefit or need for VRRP.
Putting aside the VRRP issue I sense a potential problem with this set up; two FGTs standalone with two circuits from one ISP, depending on how those two circuits work, like active-standby or split traffic/load balance.
It's probably better/safer terminating both circuits on both FGTs by putting at least one switch inbetween then set up HA if those FGT models are the same. BGP peer IPs in ASN 123 have to be different though.
Again, it's depending on the operation of the ISP's two circuits.
Toshi
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1561 | |
1034 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.