<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BGP issues after upgrade 80.10 -&amp;gt; 80.30 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107749#M14447</link>
    <description>&lt;P&gt;BGP is not supported on non-clustered interfaces in a clustered environment. Thanks for checking routed.log. If this is a clustered environment and eth1 is not configured with cluster VIP then please configure it.&amp;nbsp; If eth1 is configured with clustered VIP then please check the output of:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cphaprob -a if ---&amp;gt; this should show whether VIP is configured and installed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show routed cluster-state detailed -------&amp;gt; this should show whether routing daemon has the VIP.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jan 2021 17:22:07 GMT</pubDate>
    <dc:creator>Sundeep_Mudgal</dc:creator>
    <dc:date>2021-01-13T17:22:07Z</dc:date>
    <item>
      <title>BGP issues after upgrade 80.10 -&gt; 80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107163#M14347</link>
      <description>&lt;P&gt;Hi all&amp;nbsp;&lt;BR /&gt;We are stuck into a strange issue when upgrading a cluster from 80.10 to 80.30&amp;nbsp;&lt;BR /&gt;Short description:&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have two 80.10 GW appliances, facing two internet connections with BGP, advertising one /24 with equal metric via both providers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both BGP sessions are Established on the primary cluster member (confirmed in HA and LS mode).&amp;nbsp;&lt;/P&gt;&lt;P&gt;After upgrading to 80.30 one of the BGP comes up without issues, the other stays in Active state.&amp;nbsp;&lt;/P&gt;&lt;P&gt;routed.log says:&amp;nbsp;interface eth1 has NO IPv4 CLUSTER address&lt;/P&gt;&lt;P&gt;Error is logged even though cluster addresses are properly configured and the BGP won't move to Established state.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shutting down the working BGP (disable interface) and waiting for the other to come up did not help/&amp;nbsp;&lt;/P&gt;&lt;P&gt;We tested this on 4600 appliances then did the config from scratch on a brand new 6400 - same issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would appreciate any suggestions &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2021 22:45:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107163#M14347</guid>
      <dc:creator>Kaloyan_Metodie</dc:creator>
      <dc:date>2021-01-06T22:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: BGP issues after upgrade 80.10 -&gt; 80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107557#M14395</link>
      <description>&lt;P&gt;Did you try:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk130273" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk130273&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 02:19:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107557#M14395</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-12T02:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: BGP issues after upgrade 80.10 -&gt; 80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107566#M14398</link>
      <description>&lt;P&gt;Yep, and the result of&amp;nbsp;&lt;SPAN&gt;cphaprob -a if is looking good.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 07:33:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107566#M14398</guid>
      <dc:creator>Kaloyan_Metodie</dc:creator>
      <dc:date>2021-01-12T07:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: BGP issues after upgrade 80.10 -&gt; 80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107637#M14416</link>
      <description>&lt;P&gt;TAC case is probably in order then:&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 17:24:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107637#M14416</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-12T17:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: BGP issues after upgrade 80.10 -&gt; 80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107678#M14426</link>
      <description>&lt;P&gt;We scheduled a meeting with TAC for tonight as this is impacting prod firewalls and downtime is a bit tricky.&amp;nbsp;&lt;BR /&gt;I was hoping that someone ran into the same issue and could help reduce the time to resolve it.&amp;nbsp;&lt;BR /&gt;Will share results after debug digging&amp;nbsp;&lt;BR /&gt;Anyways - thank you for the reply &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 13:21:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107678#M14426</guid>
      <dc:creator>Kaloyan_Metodie</dc:creator>
      <dc:date>2021-01-13T13:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: BGP issues after upgrade 80.10 -&gt; 80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107749#M14447</link>
      <description>&lt;P&gt;BGP is not supported on non-clustered interfaces in a clustered environment. Thanks for checking routed.log. If this is a clustered environment and eth1 is not configured with cluster VIP then please configure it.&amp;nbsp; If eth1 is configured with clustered VIP then please check the output of:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cphaprob -a if ---&amp;gt; this should show whether VIP is configured and installed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show routed cluster-state detailed -------&amp;gt; this should show whether routing daemon has the VIP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 17:22:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107749#M14447</guid>
      <dc:creator>Sundeep_Mudgal</dc:creator>
      <dc:date>2021-01-13T17:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: BGP issues after upgrade 80.10 -&gt; 80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107906#M14488</link>
      <description>&lt;P&gt;Hi, I was involved also in debugging this issue and we ran the both commands.&lt;/P&gt;&lt;P&gt;cphaprob -a if - shows that eth1 exists and VIP is configured and installed, also VIP was accessible from outside world.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;show routed cluster-state detailed - eth1 is missing from here. Only 3 from 4 VIP interfaces were shown here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We had a remote session with TAC and issue was resolved, but it was not very clear what was the problem a how it was resolved.&lt;BR /&gt;The last thing that we do before resolving, was aligning host name of the machine and object name in policy.&lt;BR /&gt;After rebooting the device, BGP sessions to both providers were established and working.&lt;/P&gt;&lt;P&gt;I am still curious what could be the reason for VIP address missing in routed configuration and how to fix it&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 09:40:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107906#M14488</guid>
      <dc:creator>Dilian_Chernev</dc:creator>
      <dc:date>2021-01-15T09:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: BGP issues after upgrade 80.10 -&gt; 80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107992#M14504</link>
      <description>&lt;P&gt;&lt;SPAN&gt;the new sk171555 looks alot like your issue&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jan 2021 09:17:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/107992#M14504</guid>
      <dc:creator>JanVC</dc:creator>
      <dc:date>2021-01-16T09:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: BGP issues after upgrade 80.10 -&gt; 80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/108045#M14515</link>
      <description>&lt;P&gt;Most likely cluster did not update the routing daemon with the VIP. This usually happens when policy is not pushed. I assume you pushed the policy.&amp;nbsp;&lt;SPAN&gt;sk171555&amp;nbsp; explains how to resolve the issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Since there were 3 VIPs out of 4 in routing daemon so could it be possible that eth1 was configured later? &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 03:11:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/108045#M14515</guid>
      <dc:creator>Sundeep_Mudgal</dc:creator>
      <dc:date>2021-01-18T03:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: BGP issues after upgrade 80.10 -&gt; 80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/108054#M14521</link>
      <description>&lt;P&gt;Hi, as Dilian noted - the only change we did in order to have it up and running was aligning the hostname with it's object name&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still not sure why it only affected one o the two bgp sessions but now it works like charm..&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 07:00:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/108054#M14521</guid>
      <dc:creator>Kaloyan_Metodie</dc:creator>
      <dc:date>2021-01-18T07:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: BGP issues after upgrade 80.10 -&gt; 80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/108061#M14523</link>
      <description>&lt;P&gt;It seems&amp;nbsp;sk171555&amp;nbsp; is based on our issue&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;BR /&gt;Unfortunately, I am not 100% sure that this procedure has solved the issue, as we have done it before opening the ticket.&lt;BR /&gt;Also it didn't work when support guy told us to do it again, but at the end we have a working cluster with bgp.&lt;/P&gt;&lt;P&gt;eth1 was configured on time of upgrade, also we build a new cluster object with new devices (but same Cluster IPs) and the issue was the same.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 08:17:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/108061#M14523</guid>
      <dc:creator>Dilian_Chernev</dc:creator>
      <dc:date>2021-01-18T08:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: BGP issues after upgrade 80.10 -&gt; 80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/108063#M14524</link>
      <description>&lt;P&gt;I see the sk has been updated yesterday, the first iteration had your full public IP address visible for everyone&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 08:20:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/108063#M14524</guid>
      <dc:creator>JanVC</dc:creator>
      <dc:date>2021-01-18T08:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: BGP issues after upgrade 80.10 -&gt; 80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/108232#M14590</link>
      <description>&lt;P&gt;Dilian,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;In that case I will take this up with clustering team as clustering module is supposed to update routing daemon for all VIPs. Can you please open a SR as well so support can try to reproduce the issue inhouse?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 23:24:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/108232#M14590</guid>
      <dc:creator>Sundeep_Mudgal</dc:creator>
      <dc:date>2021-01-19T23:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: BGP issues after upgrade 80.10 -&gt; 80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/108256#M14594</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/24175"&gt;@Sundeep_Mudgal&lt;/a&gt;&amp;nbsp;, but the issue is currently resolved and cannot reproduce the the problem.&lt;/P&gt;&lt;P&gt;We have opened a SR and can send you the number to review the communication, logs and debugs provided.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 07:30:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-issues-after-upgrade-80-10-gt-80-30/m-p/108256#M14594</guid>
      <dc:creator>Dilian_Chernev</dc:creator>
      <dc:date>2021-01-20T07:30:52Z</dc:date>
    </item>
  </channel>
</rss>

