Hello guys,
I need some help about routing between my core router and segmentation firewall.
My topology:
Asr920>iBGP>fortigate seg.fw>iBGP>perimter cisco frp with fmc
Portchannel as trunk with service ethernet instacne to fw, allowed BDI.
Comunication in and out works but I want to firewalling internal trafic. For example site A branch to site B branch. I dont move l3 interfaces to fw beacause i have ospf and eigrp routing on the core router and i want to all trafic routing on the core router.
I try it PBR but not working beacause BDI interfaces as bridge not supported and try it other solutions but without succes. My communication was turned to router not fw.
Thank you for helpthanks for the advice
Best Regards
Brontek