This is my first foray into using BGP and I am implementing it on my FortiGates setting up a SD-WAN hub and spoke VPN setup. My existing routing protocol is OSPF with all of my L3 devices using unique router IDs, of course. My question is, is it ok to use the same router ID for BGP as well? So FortiGate would have OSPF and BGP router ID of 1.1.1.1 for example. My initial thought was yes as it's two different routing protocols; however, I know I will have to turn on redistribution between the two, and just wanted to confirm...you know what assuming will get you :)
Thanks.
Solved! Go to Solution.
Hello Cajutank!
It is possible to use the same ID in OSPF and BGP, but care must be taken in relation to route redistribution, so that there is no network loop. Ideally, create a prefix-list of networks that you don't want to receive via BGP and block them, for example.
Hello Cajutank!
It is possible to use the same ID in OSPF and BGP, but care must be taken in relation to route redistribution, so that there is no network loop. Ideally, create a prefix-list of networks that you don't want to receive via BGP and block them, for example.
Good to hear. I have some testing to do for sure. In regards to the network loop situation, and forgive my ignorance on the matter, since iBGP admin distance is 200 and OSPF is 110, why would there be a loop?
The loop would be in relation to IBGP itself, for example if you have spoke 1 sending the network 192.168.1.0/24 to the HUB, this HUB sends it to spoke2 and spoke2 already has the network configured. I think I expressed myself badly, it wouldn't be a loop in OSPF, but between the spokes themselves.
Created on 06-30-2023 07:42 PM Edited on 06-30-2023 07:43 PM
I ended up not having to do redistribution between OSPF and BGP. I just added network summations to the BGP network and it updated the routing table. So now I have network with route through one path at distance of 110 and same network with route though my VPN path at distance 200 as expected. Static blackhole route established for said network summation with distance set at 254 and all seems good. Now just have to setup SD-WAN rules. Thanks for your help.
Created on 06-27-2023 05:11 PM Edited on 06-27-2023 05:11 PM
up
User | Count |
---|---|
2101 | |
1185 | |
770 | |
451 | |
344 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.