<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BGP configuration for Expressroute in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179183#M378</link>
    <description>&lt;P&gt;We have customer using exact this setup and has been working for 2 years without issues. I can give you some screenshots of how its configured, will just need to blur out the sensitive info.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Apr 2023 00:13:58 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-04-26T00:13:58Z</dc:date>
    <item>
      <title>BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179017#M374</link>
      <description>&lt;P&gt;Looking for&amp;nbsp; advice on BGP configuration on checkpoint for Azure ExpressRoute, we are using two checkpoint devices and it is working as a cluster&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 07:09:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179017#M374</guid>
      <dc:creator>HBK</dc:creator>
      <dc:date>2023-04-25T07:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179019#M375</link>
      <description>&lt;P&gt;With or without VPN and are there specific elements of the config that you need help with or all of it?&lt;/P&gt;
&lt;P&gt;Note the BGP Router-ID needs to be configured with the same value on both cluster members, also Graceful restart is recommended.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 07:43:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179019#M375</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-25T07:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179020#M376</link>
      <description>&lt;P&gt;Thank you Chis for your quick response.&lt;/P&gt;&lt;P&gt;I am looking for complete steps, it is without VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some of the points I have noted. RID should be the VIP and&amp;nbsp;configure eBGP multi-hop option and define the TTL value...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 07:50:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179020#M376</guid>
      <dc:creator>HBK</dc:creator>
      <dc:date>2023-04-25T07:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179182#M377</link>
      <description>&lt;P&gt;For those reading and able to offer assistance, which side of the connection are the Check Point gateways located: on-prem | cloud | both ?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 00:10:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179182#M377</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-26T00:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179183#M378</link>
      <description>&lt;P&gt;We have customer using exact this setup and has been working for 2 years without issues. I can give you some screenshots of how its configured, will just need to blur out the sensitive info.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 00:13:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179183#M378</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-26T00:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179184#M379</link>
      <description>&lt;P&gt;Btw, to add to my previous response, we never really followed any special steps, simply whats outlined below and it worked fine.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_Advanced_Routing_AdminGuide/Topics-GARG/BGP-Configuring-in-Gaia-Portal-BGP-Remote-Peers.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_Advanced_Routing_AdminGuide/Topics-GARG/BGP-Configuring-in-Gaia-Portal-BGP-Remote-Peers.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 00:16:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179184#M379</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-26T00:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179192#M380</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;Gateway is located on-prem.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 03:16:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179192#M380</guid>
      <dc:creator>HBK</dc:creator>
      <dc:date>2023-04-26T03:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179193#M381</link>
      <description>&lt;P&gt;Hi Rock,&lt;/P&gt;&lt;P&gt;Could you please share the screenshots, if possible. Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 02:56:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179193#M381</guid>
      <dc:creator>HBK</dc:creator>
      <dc:date>2023-04-26T02:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179195#M382</link>
      <description>&lt;P&gt;I will see what I can send tomorrow.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 03:09:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179195#M382</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-26T03:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179231#M383</link>
      <description>&lt;P&gt;Heya&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/93037"&gt;@HBK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had a quick look at customer's config and honestly, as I thought, there is no special instructions we followed, its literally from the link I gave you, so I am sure screenshots wont help. You just need to make sure that BGP peer settings match on the other side and then verify by running show bgp commands in clish what the state is. IF you cant get it going, you can run zdebug for affected peer IP and port 179.&lt;/P&gt;
&lt;P&gt;If you need help, let me know, happy to do remote.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 12:43:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/179231#M383</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-26T12:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/181629#M384</link>
      <description>&lt;P&gt;We will be considering an ER backup link as well to Azure through BGP. AS number is the same, but we will be having 2 connections to Azure, so how it would be the configuration in this scenario?&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 10:12:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/181629#M384</guid>
      <dc:creator>HBK</dc:creator>
      <dc:date>2023-05-22T10:12:34Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182361#M385</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;Could you please advise me on the above?&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 04:31:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182361#M385</guid>
      <dc:creator>HBK</dc:creator>
      <dc:date>2023-05-29T04:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182377#M386</link>
      <description>&lt;P&gt;Should not be a problem and worked well; I configured at least couple scenarios with Express route and DX connectivity with AWS. Yes BGP listens on cluster interface. You need to define a rule specifically open port 179 and this needs to be added above stealth rule. You can can define neighbor IPs though in rule base. And then you will have to add inbound route-filter else CP will not accept and install routes.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 08:23:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182377#M386</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2023-05-29T08:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182380#M387</link>
      <description>&lt;P&gt;Hi Blason,&lt;/P&gt;&lt;P&gt;Thank you very much for your response.&lt;/P&gt;&lt;P&gt;If you don't mind, can I have the relevant screenshots for the same?&lt;/P&gt;&lt;P&gt;The second peer details also we will mentioned in the peer group as a secondary IP ?&lt;/P&gt;&lt;P&gt;what about the peer IP in the CP side, since the CPs are clustered we have to use the VIP as peer IP right.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 09:05:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182380#M387</guid>
      <dc:creator>HBK</dc:creator>
      <dc:date>2023-05-29T09:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182381#M388</link>
      <description>&lt;P&gt;Here is the config - This should give you hint. As I said before ensure to add a rule above stealth rule where source is your Peer IP and destination is your Cluster Object and port is TCP/179&lt;/P&gt;
&lt;P&gt;I enabled ECMP here; it may or may not needed in your scenario&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;set bgp ecmp on
set bgp external remote-as 97xxx on
set bgp external remote-as 97xxx import-routemap "ACCEPTAWSDX" preference 10 on
set bgp external remote-as 97xxx peer 172.43.xx.xx on
set bgp external remote-as 97xxx peer 172.43.xx.xx holdtime 15
set bgp external remote-as 97xxx peer 172.43.xx.xx keepalive 5
set bgp external remote-as 65001 on
set bgp external remote-as 65001 peer 192.168.xx.xx on
set bgp external remote-as 65001 peer 192.168.xx.xx allowas-in-count 5
set bgp external remote-as 65001 peer 192.168.xx.xx holdtime 15
set bgp external remote-as 65001 peer 192.168.xx.xx keepalive 5

set route-redistribution to bgp-as 97xxx from static-route 10.30.10.0/28 on
set route-redistribution to bgp-as 97xxx from static-route 172.16.0.0/12 on
set route-redistribution to bgp-as 97xxx from static-route 192.168.0.0/16 on
set route-redistribution to bgp-as 65001 from static-route 10.30.10.0/28 on
set route-redistribution to bgp-as 65001 from static-route 172.16.0.0/12 on
set route-redistribution to bgp-as 65001 from static-route 192.168.0.0/16 on
set routemap ACCEPTAWSDX id 10 on
set routemap ACCEPTAWSDX id 10 allow
set routemap ACCEPTAWSDX id 10 match network 10.100.0.0/16 exact
set routemap ACCEPTAWSDX id 30 on
set routemap ACCEPTAWSDX id 30 allow
set routemap ACCEPTAWSDX id 30 match network 10.120.10.0/24 exact
set routemap ACCEPTAWSDX id 35 on
set routemap ACCEPTAWSDX id 35 allow
set routemap ACCEPTAWSDX id 35 match network 10.120.11.0/24 exact
set routemap ACCEPTAWSDX id 50 on
set routemap ACCEPTAWSDX id 50 restrict
set inbound-route-filter bgp-policy 512 based-on-as as 97xxx on
set inbound-route-filter bgp-policy 512 accept-all-ipv4
set inbound-route-filter bgp-policy 516 based-on-as as 65001 on
set inbound-route-filter bgp-policy 516 accept-all-ipv4


&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 09:20:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182381#M388</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2023-05-29T09:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182386#M389</link>
      <description>&lt;P&gt;I also have some examples if needed.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 11:18:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182386#M389</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-29T11:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182413#M390</link>
      <description>&lt;P&gt;Hi Blason,&lt;/P&gt;&lt;P&gt;Thank you very much for sharing the configurations.&lt;/P&gt;&lt;P&gt;Currently we are not enabling ECMP and the second link will only for the redundancy if incase of any failure.&lt;/P&gt;&lt;P&gt;As i mentioned in the previous chat, still i have confussion about RID which IP should we need to define, I saw in many post, if the CPs are clusterd the RID must be VIP, in my sceanario i will be having two VIPs. In addition the back up peer ip details where should i need to define. If you will be able to share screen shot, it would be much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In cisco I know that, we can create one loop and define the update source as loop back interface, it is bit easy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;to&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 15:06:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182413#M390</guid>
      <dc:creator>HBK</dc:creator>
      <dc:date>2023-05-29T15:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182472#M391</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I have the same?&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 06:15:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182472#M391</guid>
      <dc:creator>HBK</dc:creator>
      <dc:date>2023-05-30T06:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182496#M392</link>
      <description>&lt;P&gt;You can, but it all depends what part specifically you need? Prefix-list, routemaps?&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 11:07:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182496#M392</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-30T11:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: BGP configuration for Expressroute</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182498#M393</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I mentioned in the previous conversation, which IP should be my RID?&amp;nbsp; can I create a loopback and assign the loop back as RID?&lt;/P&gt;&lt;P&gt;Since we have two IP for peering where should I need to add the secondary IP?&amp;nbsp; Advanced routing-&amp;gt; BGP-&amp;gt; under the peer group -&amp;gt; add both peer IPs its it right way ? Screenshot attached.&lt;/P&gt;&lt;P&gt;Thanks.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CP_ER.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21132i1FA52D0637256DF0/image-size/large?v=v2&amp;amp;px=999" role="button" title="CP_ER.PNG" alt="CP_ER.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 11:23:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/BGP-configuration-for-Expressroute/m-p/182498#M393</guid>
      <dc:creator>HBK</dc:creator>
      <dc:date>2023-05-30T11:23:47Z</dc:date>
    </item>
  </channel>
</rss>

