11/12/2020
Configure ADVPN with BGP routing protocol on Firewall FortiGate
Overview:
This Lab describes how to configure ADVPN with BGP as the routing protocol. The following options must be enabled for this configuration:
- On the hub FortiGate, IPsec phase1-interface net-device disable must be run.
- IBGP must be used between the hub and spoke FortiGates.
- bgp neighbor-group/neighbor-range must be reused.
- Configure system link monitor to monitor two links ISP to backup.
Configuration Task:
- Setup connection, ip address, dhcp on three Firewalls.
- Configure link monitor Internet links on three Firewalls.
- Configure IPsec interface tunnel on three Firewalls for hub-spoke.
- Configure IBGP routing on HUB and SPOKE Firewall.
- Configure policy for VPN traffic between HUB-to-SPOKE, SPOKE-to-SPOKE, SPOKE-to-HUB
Link to download:
- Lab, Task, IOS shared here: https://lnkd.in/g6xSi_m
- Download Platform: https://lnkd.in/g9nBxK7
- Join the group PNETLab: https://t.me/PNETLab
- All PNETLab Workbooks: https://lnkd.in/gC5Zd9T