Hello!
I have multiple VRFs configured on a Fortigate device and I can see that OSPF creates a separate process per VRF:
OSPF Router with ID (10.10.10.10) (Process ID 1, VRF 1)
OSPF Router with ID (10.10.10.10) (Process ID 2, VRF 2)
OSPF Router with ID (10.10.10.10) (Process ID 3, VRF 3)
...
Each VRF should be isolated but when enabling "Redistribute Connected", OSPF starts advertising all directly connected networks across all VRFs, causing routing loops.
I have tried using route-maps to filter the redistribution, but the issue persists. It seems that Fortigate treats redistribution as global per VDOM rather than per OSPF process/VRF.
Questions:
* Is there a way to ensure that "Redistribute Connected" only applies within its respective VRF and does not affect other VRFs?
* If this is expected behavior, what is the recommended best practice for redistributing directly connected networks while maintaining VRF isolation?
Thanks in advance for your help!
Currently, FGT has some limitations in configuring separate OSPF instances for each VRF. To achieve fully independent OSPF configurations, you should consider using VDOMs.
User | Count |
---|---|
2625 | |
1400 | |
810 | |
672 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.