122
Fortinet Inc.
Configuring RIP for FortiGate interfaces
RIP configuration
Configuring RIP for FortiGate interfaces
You can create a unique RIP configuration for each FortiGate interface. This allows
you to customize RIP for the network to which each interface is connected. For
example:
• If you have a complex internal network containing devices that use the RIP2
protocol, you might want to configure RIP2 send and receive for the internal
interface.
• If the WAN1 interface is connected to the Internet you may not want to enable RIP
send for this interface so that the internal routes are not exposed to the Internet.
However, you may want to configure RIP receive so that the FortiGate unit
receives routes from your ISP.
• If the WAN2 interface is connected to the Internet using a different ISP, this ISP
may use different RIP routing protocols, requiring a custom RIP configuration for
the WAN2 interface.
• If the DMZ interface is connected to a small DMZ network you may not need to
configure RIP for this interface.
To configure RIP for FortiGate interfaces
1
Go to
System > RIP > Interface
.
On this page you can view a summary of the RIP settings for each FortiGate interface.
2
Select Modify
for the interface for which to configure RIP settings.
3
Configure the following RIP settings:
RIP1 Send
This interface can send RIP1 routing broadcasts to routers on its network.
The routing broadcasts are UDP packets with a destination port of 520.
RIP1 Receive
This interface can receive RIP1 routing broadcasts. The interface listens on
port 520 for broadcast RIP1 messages.
RIP2 Send
This interface can send RIP2 routing broadcasts to its network. The routing
broadcasts are UDP packets with a destination port of 520.
RIP2 Receive
This interface can receive RIP2 routing broadcasts. The interface listens on
port 520 for broadcast RIP2 messages.
Split-Horizon
Configure split-horizon to prevent routing loops. By default, split horizon is
enabled. This option should only be disabled if you are sure that routing
loops cannot be created from this interface.
Authentication
Enable authentication for RIP2 packets sent and received by this interface.
Authentication is only supported by RIP2. Do not select authentication if you
are configuring the interface for RIP1.
Password
Enter the password to be included in RIP2 requests. The password can be
up to 16 characters long.
Mode
Defines how the FortiGate authenticates RIP2 packets. Select None, Clear,
or MD5.
None means do not send the password.
Clear means send the password is plain text.
MD5 means use MD5 authentication.
Summary of Contents for FortiGate 60R
Page 12: ...Contents 12 Fortinet Inc...
Page 26: ...26 Fortinet Inc Customer service and technical support Introduction...
Page 42: ...42 Fortinet Inc Next steps Getting started...
Page 138: ...138 Fortinet Inc Customizing replacement messages System configuration...
Page 228: ...228 Fortinet Inc Logging attacks Network Intrusion Detection System NIDS...
Page 242: ...242 Fortinet Inc Exempt URL list Web filtering...
Page 256: ...256 Fortinet Inc Configuring alert email Logging and reporting...
Page 260: ...260 Fortinet Inc Glossary...
Page 270: ...270 Fortinet Inc Index...