Configuring FortiGate IPsec Site-to-Site VPN with Dynamic BGP Routing
Build a route-based IPsec tunnel between two FortiGates and exchange routes automatically with eBGP so site changes do not need manual static routes.
Common Symptoms and Quick Fixes
| Symptom | Likely Cause | Quick Fix |
|---|---|---|
| Phase 1 never comes up | Mismatched proposals or pre-shared key | Match IKE version, encryption and key on both sides |
| Tunnel up but no user traffic | Missing firewall policy | Add policies in both directions |
| BGP neighbor stuck in Active | No route to tunnel IP or ACL blocking TCP 179 | Assign tunnel IPs; allow BGP on the interface |
Method 1: Create the Route-Based Tunnel
Site A example. Mirror the values on Site B with the peer IP reversed.
config vpn ipsec phase1-interface
edit "to-siteB"
set interface "wan1"
set ike-version 2
set remote-gw 198.51.100.2
set psksecret ChangeMe!
set proposal aes256-sha256
next
end
config vpn ipsec phase2-interface
edit "to-siteB"
set phase1name "to-siteB"
set proposal aes256-sha256
next
end
Method 2: Assign Tunnel IPs and Add eBGP
Give each tunnel end an address, then peer across it.
config system interface
edit "to-siteB"
set ip 10.255.0.1 255.255.255.255
set remote-ip 10.255.0.2 255.255.255.255
set allowaccess ping
next
end
config router bgp
set as 65001
config neighbor
edit "10.255.0.2"
set remote-as 65002
next
end
config network
edit 1
set prefix 192.168.10.0 255.255.255.0
next
end
end
Pro Tip for AdministratorsAdd a firewall policy for each direction or BGP will establish but user traffic will drop.
Method 3: Verify
Check the tunnel and the BGP session.
diagnose vpn ike gateway list
get router info bgp summary
get router info routing-table bgp
Frequently Asked Questions (FAQ)
Q: Why BGP instead of static routes?
Routes update automatically when a site or link changes, so you maintain less by hand.
Q: Can I use OSPF instead?
Yes for internal sites, but BGP gives better control over what each side advertises.