Hello!
I have three site-to-site VPNs with AWS using static route and I want to switch to BGP routing.
The articles I've read only deal with BGP with just a VPN, no redundancy.
How do I configure the FGT BGP routes to use the three VPNs?
Solved! Go to Solution.
Hi andersonlima,
As I have understand you want to configure dynamic routing and need to have redundancy with three VPN tunnels.
There are different scenario how you built your network topology. One of them explain as below
1) Over 3 VPN tunnel 3 BGP neighborship.
2) Advertised your routes to peer with AS-PATH prepend (AS-path prepend is used for reverse route selection preference)
3) While received routes set weight in FortiGate specific bgp neighbors according to your forward route selection preference(exit interface selection)
Reference Document:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-BGP-AS-Path-Prepending-Configuration-Examp...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Use-BGP-Weight-attribute-to-prefer-default...
Above documents written for specific use case, you may refer specific configuration according to your requirement.
Hi andersonlima,
As I have understand you want to configure dynamic routing and need to have redundancy with three VPN tunnels.
There are different scenario how you built your network topology. One of them explain as below
1) Over 3 VPN tunnel 3 BGP neighborship.
2) Advertised your routes to peer with AS-PATH prepend (AS-path prepend is used for reverse route selection preference)
3) While received routes set weight in FortiGate specific bgp neighbors according to your forward route selection preference(exit interface selection)
Reference Document:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-BGP-AS-Path-Prepending-Configuration-Examp...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Use-BGP-Weight-attribute-to-prefer-default...
Above documents written for specific use case, you may refer specific configuration according to your requirement.
Thansks @msanjaypadma
It helped me a lot in understanding the solution.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.