I'm having some trouble to change my OSPF topology.
Firewall site4-fw1 is in Area 1 and everything else in Area 0.
At this time site4-fw1 prefered to used direct VPN to contact 10.10.1.0/24 on site1 (blue square).
Interface cost is ok. 100 for VPN and 1 for L2 link.
In OSPF database, LSA for both network is the same (metric 10)
Do you have any idea ? Should I tried to set a route map to force metric ?
Can you check the routing table by running "get router info routing-table detail 10.10.1.1" in the CLI?
FortiGate-VM64-KVM # get router info routing-table details 10.10.1.0
Routing table for VRF=0Routing entry for 10.10.1.0/24Known via "ospf", distance 110, metric 10, bestLast update 00:01:50 ago* 100.65.0.5, via vpn1 distance 0
FortiGate-VM64-KVM # get router info routing-table details 10.10.1.1
Routing table for VRF=0Routing entry for 10.10.1.0/24Known via "ospf", distance 110, metric 10, bestLast update 00:01:56 ago* 100.65.0.5, via vpn1 distance 0
Is the VPN route a static route?
Static route would have lower AD if compare to OSPF.
Lower AD would be preferred.
Checked the routing database table 'get router info routing-table database' and see the ADs.
No, the only static route is the fake public ip for the vpn
FortiGate-VM64-KVM # sh router staticconfig router staticedit 1set dst 188.8.131.52 255.255.255.252set gateway 184.108.40.206set device "port2"nextend
This lab has been done on Eve NG with :
You can find all config change/add below to reproduce
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.