Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ivan90
New Contributor

mp-bgp vrf route leaking

Hello colleagues! I am a bit got lost within mp-bgp and vrfs on fortigates, let me explain in a nutshell.

Let's imagine the schema when we have a "core" multi role switch and several appliances connected as a star topology (or like a leafe spine , but let's skip the redundancy part for now). Links between the core and leafs all L3 and use mp-bgp with VRFs and address family ipv4 vrf plus the rt community. So nothing extra, everything works. It's not the vxlan+evpn example, just a simple campus. Then I would like to connect this core to a Fortigate by the same way for propagating the default gw route and  providing some advanced traffic inspection. The FG can be considered also as a point of route leaking. The confusion is that I couldn't find any examples of this design and how to configure the mp-bgp. It might be the limitation that we can use only an "interface" for each vrf and can use only vrf-lite connection. In some sources I found that it should be organized via vdoms , but why do we need vdoms if we already have vrfs ? It looks like some extra level of abstraction. I've found only one video on YouTube when the guy try to do something similar , but it's not in English and without subs :(

https://youtu.be/vjuXEZ3dbfU?si=Q_PMvfFzRsUwai-_

So can anyone share an example of this config please?  Summary: we need to connect the FG with a L3 switch using mp-bgp and vrfs and provide route leaking. If I am blind and this topic already exists please point out by finger.

thanks!

 

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

I believe FGTs don't support mp-bgp as you're thinking. If I'm not mistaken the current FGT's vrf is only internal, works inside of the unit. No way to connect with others, which have the same vrfs, unlike Cisco, Juniper, etc. would do.

Toshi

Ivan90

Perfect,  it's 2025 outside,  happy new ear. We are using 7.4.x brunch , but I also didn't find anything about the mp-bgp for 7.6.  Seems the only way is using a trunk with dozens of sub.interfaces, it will work , but will look like an ugly hedgehog. I belive the alternative validated design exists.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors