Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
v_nikolaev
New Contributor

ospf over ipsec

Hello. I need help with ospf. I have done ipsec tunnel and i try to add grey ip for routing on the ipsec tunnel. I need to add ip addresses on the  both side with mask /30, for example 172.17.250.80/30, 81/30 on the one side and 82/30 on the other side.

I can add:

ip 172.17.250.81

Netmask 255.255.255.255

Remote IP/Netmask 172.17.250.82 255.255.255.252

and

ip 172.17.250.82

Netmask 255.255.255.255

Remote IP/Netmask 172.17.250.81 255.255.255.252

That is normal? After i have added ip over ipsec i add this into ospf by classical scem. I have added interface and network 172.17.250.80/30 one the one side and transfer this prefix to  other segment on the other equipment(cisco). I got  preffix 

172.17.250.81/32, than is normal? I did't have done ospf on the other side yet. If i will have done ospf on the other side, i will get  172.17.250.82/32 and are these will be working? You have to get network address as usually and these type of getting preffix from ospf is strange for me. I need some advice. that is normal for fortigate and that wiil be working? i need exchange preffixes between ospf devices

1 REPLY 1
Toshi_Esumi
SuperUser
SuperUser

Yes, that's (/32s) normal with FGTs for IPSec interface IPs. You can use /30 for ospf network prefix statement.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors