-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
PCNSE
NSE
StrongSwan
-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
ORIGINAL: ddskier Thanks for the input. Of all the routing protocols, I have not implemented OPSF before so I will need to learn as I go. I' m hoping to keep it a simple as possible. Couple of questions: 1. If I leave the default setup for the timers, would it really take 40 seconds for OSPF to figure out the link is not working and adjust the routing tables? What values do you guys recommend?I have never messed with the timers or tested that. Can' t say for sure.
2. OSPF Networks: Do I want to define a network of 0.0.0.0 at the office side so that all internet requests get routed over to the collocation? (like in static routing) Then create a network of 10.10.x.x at the collocation side so that it routes office traffic back? Or do I have it reversed?The 0.0.0.0 area (A.K.A. ' the backbone' ) is shared between the two. It needs to be common. Any other area(s) may hang off that one.
3. OSPF Interfaces: Do I need to create one interface for IPv4 and another for IPv6 even though it is the same physical route?Don' t use IPv6 myself, can' t say.
4. Can I use policy routing with this method? Or some how control that certain traffic from a source IP goes down the backup line?There should be no reason you can' t use policy routing. You have different interfaces to point the traffic down, so in theory, you should be OK.
I would appreciate any additional insight.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
2. OSPF Networks: Do I want to define a network of 0.0.0.0 at the office side so that all internet requests get routed over to the collocation? (like in static routing) Then create a network of 10.10.x.x at the collocation side so that it routes office traffic back? Or do I have it reversed? The 0.0.0.0 area (A.K.A. ' the backbone' ) is shared between the two. It needs to be common. Any other area(s) may hang off that one.I thought the areas were seperate from the " Networks" ? At least it looks like that from the OSPF GUI. If it is, is my reasoning for the networks correct?
-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.