Tuesday, January 7, 2020

[Maybe Fortigate-Cisco specific] Disable BGP dynamic capabilities in Cisco, or upgrade router OS in Fortigate?

Been running into issues between Fortigate and Cisco routers "talking" BGP, due to the fact that Fortigate disables dynamic capability (see here, as well as the unrecognized capability code 70 len 0).

My Q: how critical are these dynamic capabilities, vs the risk we would take by upgrading to a new (6.0) version of Fortigate, which supposedly fixes this, but who knows what else may bring along?



No comments:

Post a Comment