BGP Site to site VPN learned routes still in table despite the BGP peer down for a week

Brendan Edward Richardson 0 Reputation points
2026-08-18T12:52:39.9666667+00:00

we see that the learned routes are still available with no BGP peer, this was notices as I wanted to be sure that the BGP filter on the remote end was working , We have a filter on the FortiGate this is working and confirmed by FortiGate support.

The issue is stale routes in BGP Site to Site VPN even though BGP is not configured on the remote FortiGate side

Azure VPN Gateway
Azure VPN Gateway

An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.

0 comments No comments

4 answers

Sort by: Newest
  1. Brendan Edward Richardson 0 Reputation points
    2026-08-24T07:46:41.54+00:00

    the hub reset

    Was this answer helpful?

    0 comments No comments

  2. Brendan Edward Richardson 0 Reputation points
    2026-08-24T07:32:44.1533333+00:00

    Hi

    I did do a reset of the VNG but this did not resolve the issue, at present I deconfigured the fortigate as we had another issue and wanted to eliminat the new additions of BGP. the current state is that the GBP routes are not imported to the active routing table on the Azure side

    Thanks for the help, I will try to get a slot to rest the VPN GW again and will let you know!!

    Was this answer helpful?

    0 comments No comments

  3. Jose Benjamin Solis Nolasco 12,036 Reputation points Volunteer Moderator
    2026-08-24T04:03:14.37+00:00

    Welcome to Microsoft Q&A!

    @Brendan Edward Richardson I hope you are doing well,

    Under normal circumstances, when a BGP peer goes down, the hold timer expires (usually within a few minutes) and the Azure VPN Gateway should automatically flush those learned routes from the routing table. If these routes have been stuck for a week after BGP was disabled on your FortiGate, the Azure VPN Gateway's internal routing service has likely encountered a state synchronization issue and failed to clear its cache.

    Recommended Next Step: To force the gateway to flush its routing table and rebuild the current routing state, the most effective self-service fix is to perform a Gateway Reset.

    In the Azure Portal, navigate to your Virtual Network Gateway.

    In the left-hand menu under the Help section, select Reset.

    1. Click the Reset button.

    Note: Resetting the gateway reboots the underlying infrastructure VMs. This will cause a brief drop in connectivity (usually a couple of minutes) for any other active VPN connections attached to this gateway while it reboots.

    Help make this community better for everyone: if this answer resolved your issue, please accept it or leave an upvote. If not, share more details in a comment so we can continue the discussion and find the right solution

    Was this answer helpful?


  4. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.