Hey everyone!We are trying to limit distributed BGP routes to neighbors
using "set match-interface" for the source of the route. The issue we
are having is that this does not seem to work together with neighbor
route-map-out. As a work around, we are...
Hey everyone, We are trying to setup a "weird" scenario for a customer.
They have a "one armed" situation where the FortiGate has an internet
link and will receive VPN connections, however before routing the
traffic to the internet, it has to PBR to ...
Good morning everyone! We have an interesting routing problem. The
scenario is a single hub location and several branches. Each location
has an MPLS link and an internet link. The MPLS link is preferred and is
running BGP to get all the location addr...
Hi everyone. We have an FG200B and I am trying to set up an internal
server that can be accessed by a VIP from inside or outside the network.
I can access it fine using the local address internally or the VIP
externally. I followed the KB article bel...
Thanks Toshi! Guess I was hoping it was more like Cisco's and allow me
to skip the step of having two route-maps
https://www.cisco.com/c/m/en_us/techdoc/dc/reference/cli/n5k/commands/match-ip-address.html
match interface Distributes any routes that h...
Ah, forgot to mention an important point. The MPLS link is a different
AS, managed by the SP. So some attributes will get dropped in the MPLS
link, which is why we are using local weights to set the main link as
the MPLS one.
Hey guys, thanks for the replies! So after the answers I did a little
more digging. It turns out that if you already have policy route in
place for that server to the internet, you need to add a new policy
route so that the hairpin works!
http://kb.f...
You are leaving our website
You are leaving our site and we cannot be held responsible for the content of external websites