12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

BGP<br />

Router Dynamic<br />

IP<br />

Enter the IP address that has been assigned to the OSPF-enabled<br />

interface. The interface be<strong>com</strong>es OSPF-enabled because its IP address<br />

matches the OSPF network address space.<br />

For example, if you defined an OSPF network of 172.20.120.0/24 and<br />

port1 has been assigned the IP address 172.20.120.140, type<br />

172.20.120.140.<br />

Authentication Select an authentication method for LSA exchanges on the specified<br />

interface:<br />

• Select None to disable authentication.<br />

• Select Text to authenticate LSA exchanges using a plain-text<br />

password. The password can be up to 35 characters, and is sent in<br />

clear text over the network.<br />

• Select MD5 to use one or more keys to generate an MD5 hash.<br />

This setting overrides the area Authentication setting.<br />

Password Enter the plain-text password. Enter an alphanumeric value of up to 15<br />

characters. The OSPF neighbors that send link-state advertisements to<br />

this <strong>FortiGate</strong> interface must be configured with an identical password.<br />

This field is available only if you selected plain-text authentication.<br />

MD5 Keys<br />

Hello Interval<br />

Dead Interval<br />

Enter the key identifier for the (first) password in the ID field (the range is<br />

from 1 to 255) and then type the associated password in the Key field.<br />

The password is an alphanumeric string of up to 16 characters. The<br />

OSPF neighbors that send link-state advertisements to this <strong>FortiGate</strong><br />

interface must be configured with an identical MD5 key. If the OSPF<br />

neighbor uses more than one password to generate MD5 hash, select the<br />

Add icon to add additional MD5 keys to the list. This field is available only<br />

if you selected MD5 authentication.<br />

Optionally, set the Hello Interval to be <strong>com</strong>patible with Hello Interval<br />

settings on all OSPF neighbors.<br />

This setting defines the period of time (in seconds) that the <strong>FortiGate</strong> unit<br />

waits between sending Hello packets through the interface.<br />

Optionally, set the Dead interval to be <strong>com</strong>patible with Dead Interval<br />

settings on all OSPF neighbors.<br />

This setting defines the period of time (in seconds) that the <strong>FortiGate</strong> unit<br />

waits to receive a Hello packet from an OSPF neighbor through the<br />

interface. If the <strong>FortiGate</strong> unit does not receive a Hello packet within the<br />

specified amount of time, the <strong>FortiGate</strong> unit declares the neighbor<br />

inaccessible.<br />

By convention, the Dead Interval value is usually four times greater than<br />

the Hello Interval value.<br />

BGP<br />

How BGP works<br />

Border Gateway Protocol (BGP) is an Internet routing protocol typically used by<br />

ISPs to exchange routing information between different ISP networks. For<br />

example, BGP enables the sharing of network paths between the ISP network and<br />

an autonomous system (AS) that uses RIP and/or OSPF to route packets within<br />

the AS. The <strong>FortiGate</strong> implementation of BGP supports BGP-4 and <strong>com</strong>plies with<br />

RFC 1771.<br />

When BGP is enabled, the <strong>FortiGate</strong> unit sends routing table updates to<br />

neighboring autonomous systems whenever any part of the <strong>FortiGate</strong> routing<br />

table changes. Each AS, including the local AS of which the <strong>FortiGate</strong> unit is a<br />

member, is associated with an AS number. The AS number references a particular<br />

destination network.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

256 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!