Options

OSPF Over IPSEC

NightShade1NightShade1 Member Posts: 433 ■■■□□□□□□□
Hello everyone
im on a proyect right now in which we will run OSPF over iPSEC
And i was wondering if anyone got any experience doing that....

Anyways here is my Scenario and what i though i should do ill try to make a summary buti can be more specific if its needed.

I got a STAR topology

A central Fortigate and like 30 remote sites

We doing OSPF on it we will start with a STAR topology and maybe we will move to a Partial mesh.

Anyways
I got some questions about the configuration of the OSPF

Everything will go in one Area, Area 0

What network type you recomend? i was thinking in Point to multipoint and putting all of my OSPF link in one subnet
I could also just leave it on nonbraodcast and put all my remote routers with priority 0 so the Central one be the DR.

What time for hello time and dead time should i put? i was thinking 30 secs for hello time and 120 for dead time

I ll configure passive interface in all my LAN interface of all my fortiagates
Ill configure Loopbacks for network stability(which i dont know well as we are not doing partial mech neitherfull mesh yet so no DR or BDR election) O_o but it would be good having it... because we planning on moving to that later.

If anyone used fortigates berfore there is a question for them
About the Bandwitch... well at least in cisco routers you could configure that... setting the bw to whatever your link was..
But in fortinet i just see a inbound BW and outbound BW option.... is this is the one im looking for it?
I mean i need to configure it becasue Because it use that for the best route calculation, plus i dont know if its like EIGRP that uses part of the % of the BW for its protocol thing... at least as far i remenber EIGRP uses part of the % of the BW for its own... and if its not well configured well... you can imaging...

Those are some of the considaration im taking...
Any other consideration is welcome...
Also any suggestion
Also if you got any question about what im planning to do ask me.

Im doing everything with Fortigates yeah no cisco... but these questions are more design questions...

Other thing that got me worried is all the BW that will be used for the IPSEC + OSPF traffic( i really have no idea how much BW ill need) yeah everything going trhough one connection of 2mbs O_o how much BW i would need for it?

Thank you

Comments

Sign In or Register to comment.