Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
andersonlima
New Contributor

Site-to-site VPN with BGP routing between FGT 100F and AWS

Hello!
I have three site-to-site VPNs with AWS using static route and I want to switch to BGP routing.
The articles I've read only deal with BGP with just a VPN, no redundancy.
How do I configure the FGT BGP routes to use the three VPNs?

 

FortiGate 

1 Solution
msanjaypadma
Staff
Staff

Hi andersonlima,

 

As I have understand you want to configure dynamic routing and need to have redundancy with  three VPN tunnels.

There are different scenario how you built your network topology. One of them explain as below


1) Over 3 VPN tunnel 3 BGP neighborship.

2) Advertised your routes to peer  with AS-PATH prepend (AS-path prepend is used for reverse route selection preference)
3) While received routes set weight in FortiGate specific bgp neighbors according to your forward route selection preference(exit interface selection)

Reference Document:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-BGP-AS-Path-Prepending-Configuration-Examp...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Use-BGP-Weight-attribute-to-prefer-default...

 

Above documents written for specific use case, you may refer specific configuration according to your requirement. 

Mayur Padma

View solution in original post

2 REPLIES 2
msanjaypadma
Staff
Staff

Hi andersonlima,

 

As I have understand you want to configure dynamic routing and need to have redundancy with  three VPN tunnels.

There are different scenario how you built your network topology. One of them explain as below


1) Over 3 VPN tunnel 3 BGP neighborship.

2) Advertised your routes to peer  with AS-PATH prepend (AS-path prepend is used for reverse route selection preference)
3) While received routes set weight in FortiGate specific bgp neighbors according to your forward route selection preference(exit interface selection)

Reference Document:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-BGP-AS-Path-Prepending-Configuration-Examp...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Use-BGP-Weight-attribute-to-prefer-default...

 

Above documents written for specific use case, you may refer specific configuration according to your requirement. 

Mayur Padma
andersonlima

Thansks @msanjaypadma

It helped me a lot in understanding the solution.

Labels
Top Kudoed Authors