Monday, October 28, 2019

Howto reduce BGP capabilities advertisements FortiOS

FortiOS has this weird behavior that by default it advertises ipv6 capabilities to any neighboring bgp router, even if you're not using ipv6 for that bgp-neighbor. You can get the list of capabilities sent via "get router info bgp neighbor" command executed from the cli

To disable the advertisement of ipv6 to a bgp-neighbor you will need to disable this capability from the cli per each neighbor


e.g





Here's a before and after screenshot of a neighbor output once the above command has been set to disable



As you can see the output is reduced and eliminates ipv6 advertisements. You can read more at one of my early posted blog

http://socpuppet.blogspot.com/2013/05/bgp-capabilities.html











NSE ( network security expert) and Route/Switching Engineer
kfelix  -----a----t---- socpuppets ---dot---com
     ^      ^
=(  @  @ )=
         o

        /  \


No comments:

Post a Comment