Since original "Eigrp throug the fortigate in transparent mode" thread is locked, I wanted to correct it for posterity.
In it, the statement "EIGRP is multicast protocol IP 88" is partially incorrect - indeed EIGRP is BOTH Multicast and Unicast. (For explanation, see "EIGRP startup process - Unicast and multicast Updates containing topology information".)
So, enabling multicast-skip-policy is insufficient - a (Unicast) firewall policy to cover protocol 88 is needed.
Your 100% correct that it's not 100% mcast. In fact, OSPF is ALSO the same and many mistakes that it uses mcast only. Typically neighbor discovery is mcast and updates are unicast for both protocols.
Ken Felix
PCNSE
NSE
StrongSwan
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.