Hello colleagues! I am a bit got lost within mp-bgp and vrfs on fortigates, let me explain in a nutshell.
Let's imagine the schema when we have a "core" multi role switch and several appliances connected as a star topology (or like a leafe spine , but let's skip the redundancy part for now). Links between the core and leafs all L3 and use mp-bgp with VRFs and address family ipv4 vrf plus the rt community. So nothing extra, everything works. It's not the vxlan+evpn example, just a simple campus. Then I would like to connect this core to a Fortigate by the same way for propagating the default gw route and providing some advanced traffic inspection. The FG can be considered also as a point of route leaking. The confusion is that I couldn't find any examples of this design and how to configure the mp-bgp. It might be the limitation that we can use only an "interface" for each vrf and can use only vrf-lite connection. In some sources I found that it should be organized via vdoms , but why do we need vdoms if we already have vrfs ? It looks like some extra level of abstraction. I've found only one video on YouTube when the guy try to do something similar , but it's not in English and without subs :(
https://youtu.be/vjuXEZ3dbfU?si=Q_PMvfFzRsUwai-_
So can anyone share an example of this config please? Summary: we need to connect the FG with a L3 switch using mp-bgp and vrfs and provide route leaking. If I am blind and this topic already exists please point out by finger.
thanks!
I believe FGTs don't support mp-bgp as you're thinking. If I'm not mistaken the current FGT's vrf is only internal, works inside of the unit. No way to connect with others, which have the same vrfs, unlike Cisco, Juniper, etc. would do.
Toshi
Perfect, it's 2025 outside, happy new ear. We are using 7.4.x brunch , but I also didn't find anything about the mp-bgp for 7.6. Seems the only way is using a trunk with dozens of sub.interfaces, it will work , but will look like an ugly hedgehog. I belive the alternative validated design exists.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1767 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.