12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Router Dynamic<br />

RIP<br />

Redistribute<br />

Garbage<br />

Enter the amount of time (in seconds) that the<br />

<strong>FortiGate</strong> unit will advertise a route as being<br />

unreachable before deleting the route from the<br />

routing table. The value determines how long an<br />

unreachable route is kept in the routing table.<br />

Enable or disable RIP updates about routes that were not learned<br />

through RIP. The <strong>FortiGate</strong> unit can use RIP to redistribute routes<br />

learned from directly connected networks, static routes, OSPF,<br />

and/or BGP.<br />

Connected<br />

Static<br />

OSPF<br />

BGP<br />

Select to redistribute routes learned from directly<br />

connected networks. If you want to specify a hop<br />

count for those routes, select Metric, and in the<br />

Metric field, enter the hop count. The range is from<br />

1 to 16.<br />

Select to redistribute routes learned from static<br />

routes. If you want to specify a hop count for those<br />

routes, select Metric, and in the Metric field, enter<br />

the hop count. The range is from 1 to 16.<br />

Select to redistribute routes learned through OSPF.<br />

If you want to specify a hop count for those routes,<br />

select Metric, and in the Metric field, enter the hop<br />

count. The range is from 1 to 16.<br />

Select to redistribute routes learned through BGP. If<br />

you want to specify a hop count for those routes,<br />

select Metric, and in the Metric field, enter the hop<br />

count. The range is from 1 to 16.<br />

Overriding the RIP operating parameters on an interface<br />

RIP interface options enable you to override the global RIP settings that apply to<br />

all Fortinet interfaces connected to RIP-enabled networks. For example, if you<br />

want to suppress RIP advertising on an interface that is connected to a subnet of<br />

a RIP-enabled network, you can enable the interface to operate passively.<br />

Passive interfaces listen for RIP updates but do not respond to RIP requests.<br />

If RIP version 2 is enabled on the interface, you can optionally choose password<br />

authentication to ensure that the <strong>FortiGate</strong> unit authenticates a neighboring router<br />

before accepting updates from that router. The <strong>FortiGate</strong> unit and the neighboring<br />

router must both be configured with the same password. Authentication<br />

guarantees the authenticity of the update packet, not the confidentiality of the<br />

routing information in the packet.<br />

To set specific RIP operating parameters for a RIP-enabled interface, go to<br />

Router > Dynamic > RIP and select Create New.<br />

Note: Additional options such as split-horizon and key-chain settings can be configured per<br />

interface through the CLI. For more information, see the “router” chapter of the <strong>FortiGate</strong><br />

CLI Reference.<br />

Figure 154 shows the New/Edit RIP Interface dialog box belonging to a <strong>FortiGate</strong><br />

unit that has an interface named “internal”. The names of the interfaces on your<br />

<strong>FortiGate</strong> unit may be different.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 247

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!