12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Router Dynamic<br />

BGP<br />

BGP updates advertise the best path to a destination network. When the<br />

<strong>FortiGate</strong> unit receives a BGP update, the <strong>FortiGate</strong> unit examines the Multi-Exit<br />

Discriminator (MED) attributes of potential routes to determine the best path to a<br />

destination network before recording the path in the <strong>FortiGate</strong> routing table.<br />

BGP has the capability to gracefully restart. This capability limits the effects of<br />

software problems by allowing forwarding to continue when the control plane of<br />

the router fails. It also reduces routing flaps by stabilizing the network.<br />

Note: Graceful restarting and other advanced settings cannot be configured through the<br />

web-based manager, only through CLI <strong>com</strong>mands. For <strong>com</strong>plete descriptions and<br />

examples of how to use CLI <strong>com</strong>mands to configure BGP settings, see the “router” chapter<br />

of the <strong>FortiGate</strong> CLI Reference.<br />

Viewing and editing BGP settings<br />

When you configure BGP settings, specify the AS that includes the <strong>FortiGate</strong> unit<br />

as a member and enter a router ID to identify the <strong>FortiGate</strong> unit to other BGP<br />

routers. You must also identify the <strong>FortiGate</strong> unit’s BGP neighbors and specify<br />

which of the networks local to the <strong>FortiGate</strong> unit should be advertised to BGP<br />

neighbors.<br />

To view and edit BGP settings, go to Router > Dynamic > BGP. The web-based<br />

manager offers a simplified user interface to configure basic BGP options. A large<br />

number of advanced BGP options can be configured through the CLI. For more<br />

information, see the “router” chapter of the <strong>FortiGate</strong> CLI Reference.<br />

Figure 160:Basic BGP options<br />

Local AS<br />

Router ID<br />

Neighbors<br />

Enter the number of the local AS that the <strong>FortiGate</strong> unit is a member of.<br />

Enter a unique router ID to identify the <strong>FortiGate</strong> unit to other BGP<br />

routers. The router ID is an IP address written in dotted-decimal format.<br />

If you change the router ID while BGP is running, all connections to BGP<br />

peers will be broken temporarily until they are re-established.<br />

The IP addresses and AS numbers of BGP peers in neighboring<br />

autonomous systems.<br />

IP Enter the IP address of the neighbor interface to the BGPenabled<br />

network.<br />

Remote AS Enter the number of the AS that the neighbor belongs to.<br />

Add/Edit Select to add the neighbor information to the Neighbors list,<br />

or edit an entry in the list.<br />

Neighbor The IP addresses of BGP peers.<br />

Remote AS The numbers of the autonomous systems associated with<br />

the BGP peers.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 257

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!