hi,
i'm running IPSec VPN betwen HQ and a branch.
i need to add the BGP HA graceful restart in the branch dual internet edge router.
there's an iBGP between the branch's dual internet edge router and fortigate HA FW (which runs IPSec).
my question, is it "safe" to add "ha-mode graceful restart" between internet edge and FW. this is for fast failover/BGP convergence if primary fortigate or its BGP went down.
doing this remotely so i'm trying to avoid being cutoff or worst be lockout.
HQ --- INTERNET/IPSEC VPN --- BRANCH IGW1/2 --- iBGP --- FG HA
IGW1/2
router bgp 65000 <<< iBGP WITH FORTIGATE
neighbor 1.2.3.4 ha-mode graceful-restart
