
Learn BGP basics on FortiGate: understand AS numbers, EBGP and IBGP, and how subnets are advertised across ISP peering, with public and private 16-bit and 32-bit options.
Learn how BGP route selection on FortiGate prioritizes paths using weight, local preference, and shortest as path, then considers origin code, MID, and ECMP to pick the best route.
Explore the BGP finite state machine on FortiGate, tracing idle, active, open, and establish states as peers establish TCP connections, exchange open and keepalive messages, and process updates and notifications.
Explore how to troubleshoot BGP on FortiGate using Wireshark, including configuring neighbors, networks, and AS numbers, reading notification messages, and analyzing update messages to verify a stable BGP session.
Create a GNS3 account and download GNS3 and GNS3 VM, then install VMware. Enable GNS3 VM, set network adapters to bridge, obtain an IP, and prepare FortiGate VM in GNS.
Install FortiGate VM in GNS3 by adding the FortiGate appliance and configuring a static 192.168.161.160/24 management interface. Then initiate a BGP lab in GNS3.
Create a simple BGP lab in GNS3 with FortiGate devices, configure loopbacks, and advertise networks while verifying BGP up and routes learned.
Explore how route reflectors simplify iBGP by removing the need for full mesh, forming clusters of reflectors and clients, and propagating updates between hub and spokes.
Configure BGP route reflectors on FortiGate across HQ and branches. Advertise networks 192.168.1.0/24, 192.168.2.0/24, and 192.168.3.0/24 with redistribution and verify reachability.
Explore additional path and BGP ECMP design on FortiGate with dual ISPs, HQ and branch topology, IBGP multipath, and a lab scenario to ensure redundancy and load balancing.
Enable additional path on FortiGate route reflectors to advertise multiple BGP paths per prefix, identify unique paths, and select how many to advertise from hub to branch.
practice configuring route reflectors and additional path in bgp on FortiGate to enable ecmp multi-path across multiple isps, and verify with bgp summary and routing table checks.
Explore BGP attributes and status codes, including origin codes, AS path, next hop, and the effects of transitive versus non-transitive attributes, with data scope and internal ibgp considerations.
Master BGP and OSPF IPv4 redistribution in this lab, configuring connected, OSPF, and static sources, understanding BGP attributes, status codes, next-hop self, and route-reflector behavior.
Explain how to configure prefix lists and access lists to filter IP routes and traffic with permit or deny actions on IP addresses and subnets, including greater-than and less-than operators.
Explore RootMap, a flexible FortiGate feature for BGP, using match and set rules to filter or redistribute routes, and to permit or deny, while adjusting metrics, next hop, and origin.
Execute a FortiGate route-map lab to advertise 192.168.2.0/24 with local preference 200 and weight 10, then apply access-list rules and compare routing tables before and after deployment.
Configure BGP peering with neighbor range and group to simplify large-scale deployments, using auto-discovered neighbors and MD5 authentication, plus route maps, prefix lists, and IP filtering across branches.
Learn BGP timer and reset sessions on FortiGate, covering keep alive, hold time, background scan, administrative distance, cluster ID, default local preference, and soft and hard resets.
Simulate a multi-branch FortiGate lab that integrates BGP and OSPF across headquarters and disaster recovery sites, with MPLS, root reflector, redistribution, and ECMP for resilient connectivity.
In this course we will learn to understand BGP and OSPF routing protocol and how to deploy BGP and OSPF in FortiGate devices and build real labs based on real environments in companies, Most useful in this course to build HQ and DR FortiGate LABs with branches and clarification how traffic Crossing through HQ and DR, solve the exercise when separating link branches with HQ and DR, and most importantly build a stable connection network in the routing table and check all predictable indicators of what is happening in the links between HQ and DR, the routing protocol No less important than protection procedures Make sure using network encrypted, use BPG and OSPF over IPsec VPN to ensure all traffic encrypted between branches to prevent sniffing attack.
-The BGP course will learn BGP route selection, status and show traffic using Wireshark because the Wireshark program this important to know what is the problem when BGP status still down.
-Using GNS3 will install FortiGate VM.
-explaining route reflector and what is the important to using that feature to share network and advertise networks to all branches to create network full mesh
-Additional Path feature integrate with Route Reflector and uses Access-List and Route-Map
-Peer Group that feature the simplification when have many of peers and difficult to add peer separately in the HQ and DR