12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Bi-directional Forwarding Detection (BFD)<br />

Router Dynamic<br />

Configuring BFD on your <strong>FortiGate</strong> unit<br />

For this example BFD is enabled on the <strong>FortiGate</strong> unit using the default values.<br />

This means that once a connection is established, your <strong>FortiGate</strong> unit will wait for<br />

up to 150 milliseconds (50 x 3) for a reply from a BFD router before declaring that<br />

router down and rerouting traffic. The port that BFD traffic originates from will be<br />

checked for security purposed.<br />

config system settings<br />

set bfd enable<br />

set bfd-desired-min-tx 50<br />

set bfd-required-min-rx 50<br />

set bfd-detect-mult 3<br />

set bfd-dont-enforce-src-port disable<br />

end<br />

Note: The minimum receive interval (bfd-required-min-rx) and the detection<br />

multiplier (bfd-detect-mult) <strong>com</strong>bine to determine how long a period your <strong>FortiGate</strong><br />

unit will wait for a reply before declaring the neighbor down. The correct value for your<br />

situation will vary based on the size of your network and the speed of your <strong>FortiGate</strong> unit’s<br />

CPU. The number used in this example may not work for your network.<br />

Configure BFD off on a specific interface<br />

The above example configured BFD to be on for your <strong>FortiGate</strong> unit. If there is an<br />

interface that is not connected to any BFD enabled routers, you can reduce<br />

network traffic by turning BFD off just for that interface. For this example, BFD is<br />

turned off for the internal interface using CLI <strong>com</strong>mands. It could just as easily<br />

have been turned on (enable) or set to use the <strong>FortiGate</strong> unit’s default settings<br />

(global).<br />

config system interface<br />

edit internal<br />

set bfd disable<br />

end<br />

Configuring BFD on BGP<br />

Configuring BFD on a BGP network is very straight forward - turn it on. In BGP,<br />

you enable BFD for each neighbor that is running the protocol. This allows a twoway<br />

<strong>com</strong>munication to be established.<br />

Configuring BFD on OSPF<br />

Configuring BFD on an OSPF network is very much like enabling BFD on your<br />

<strong>FortiGate</strong> unit - you can enable it globally, and you can override the global settings<br />

at the interface level.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

262 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!