12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Router Dynamic<br />

OSPF<br />

Selecting operating parameters for an OSPF interface<br />

An OSPF interface definition contains specific operating parameters for a<br />

<strong>FortiGate</strong> OSPF-enabled interface. The definition includes the name of the<br />

interface (for example, external or VLAN_1), the IP address assigned to the<br />

interface, the method for authenticating LSA exchanges through the interface,<br />

and timer settings for sending and receiving OSPF Hello and dead-interval<br />

packets.<br />

You can enable OSPF on all <strong>FortiGate</strong> interfaces whose IP addresses match the<br />

OSPF-enabled network space. For example, define an area of 0.0.0.0 and the<br />

OSPF network is defined as 10.0.0.0/16. Then define vlan1 as 10.0.1.1/24, vlan2<br />

as 10.0.2.1/24 and vlan3 as 10.0.3.1/24. All three VLANs will run OSPF in area<br />

0.0.0.0. To enable all interfaces, you would create OSPF network 0.0.0.0/0 having<br />

an area that matches a specific IP address.<br />

You can configure different OSPF parameters for the same <strong>FortiGate</strong> interface<br />

when more than one IP address has been assigned to the interface. For example,<br />

the same <strong>FortiGate</strong> interface could be connected to two neighbors through<br />

different subnets. You could configure an OSPF interface definition containing one<br />

set of Hello and dead-interval parameters for <strong>com</strong>patibility with one neighbor’s<br />

settings, and a second OSPF interface definition for the same interface to ensure<br />

<strong>com</strong>patibility with the second neighbor’s settings.<br />

To select OSPF operating parameters for a <strong>FortiGate</strong> interface, go to Router ><br />

Dynamic > OSPF, and then under Interfaces, select Create New. To edit the<br />

operating parameters of an OSPF-enabled interface, go to Router > Dynamic ><br />

OSPF and select the Edit icon in the row that corresponds to the OSPF-enabled<br />

interface.<br />

Figure 159 shows the New/Edit OSPF Interface dialog box belonging to a<br />

<strong>FortiGate</strong> unit that has an interface named “port1”. The interface names on your<br />

<strong>FortiGate</strong> unit may differ.<br />

Figure 159:New/Edit OSPF Interface<br />

Add<br />

Name<br />

Interface<br />

Enter a name to identify the OSPF interface definition. For example, the<br />

name could indicate to which OSPF area the interface will be linked.<br />

Select the name of the <strong>FortiGate</strong> interface to associate with this OSPF<br />

interface definition (for example, port1, external, or VLAN_1). The<br />

<strong>FortiGate</strong> unit can have physical, VLAN, virtual IPSec or GRE interfaces<br />

connected to the OSPF-enabled network.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 255

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!