<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BGP peering is not coming up - Please help in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117436#M16591</link>
    <description>&lt;P&gt;Is the 169.254.189.45 BGP peer arrive through the IPSec tunnel ?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would also look into VTI's in order to configure BGP over VPN , something like&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108958" target="_blank" rel="noopener"&gt;this&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In order to create a VRRP IP , you would need to have interface(s) in that network.&lt;/P&gt;</description>
    <pubDate>Sun, 02 May 2021 07:19:40 GMT</pubDate>
    <dc:creator>funkylicious</dc:creator>
    <dc:date>2021-05-02T07:19:40Z</dc:date>
    <item>
      <title>BGP peering is not coming up - Please help</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117390#M16588</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I am configuring dynamic routing with AWS and on-prem check point gws in R80.30 using vti tunnels. CP is in VRRP cluster mode&lt;/P&gt;&lt;P&gt;This is eBGP and both are having different AS numbers. Now surprising thing is ipsec with AWS is up but somehow BGP peers are not coming up and at check point it still shows idle state.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;I have proper policy configured to allow port 179 and can see packets coming in from AWS side&lt;/LI&gt;&lt;LI&gt;wanted to know if there is any way to capture the packets for port 179 so that I can see the udpates on Check Point firewall&lt;/LI&gt;&lt;LI&gt;What are other possibilities behind BGP not coming up?&lt;/LI&gt;&lt;LI&gt;If I see using netstat and port 179 is listening but tcpdump -nni any port 179 is not showing any packets.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone pls help?&lt;/P&gt;</description>
      <pubDate>Sat, 01 May 2021 05:36:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117390#M16588</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-05-01T05:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: BGP peering is not coming up - Please help</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117391#M16589</link>
      <description>&lt;P&gt;So , while debugging BGP I found below messages&lt;/P&gt;&lt;P&gt;May 1 11:18:20.840573 bgp_ifaddr_change(7101): Checking if interface change affects any peers&lt;BR /&gt;May 1 11:18:20.840573 bgp_set_nexthop_addresses(9735): 169.254.189.45 [eBGP AS 64512] No IPv4 address found to connect&lt;BR /&gt;May 1 11:18:20.840573 bgp_set_peer_ifaps(5383): 169.254.189.45 [eBGP AS 64512] Setting local nexthop addresses failed&lt;/P&gt;&lt;P&gt;Now since this is a VRRP cluster do I need to VPNt cluster IP in mcvr or in vrrp as well?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even I tried adding but I am getting below error&lt;/P&gt;&lt;P&gt;add mcvr vrid 10 backup-address 169.254.189.46&lt;BR /&gt;WARNING this may take a while; please be patient&lt;BR /&gt;NMSMVR0266 No interface with net address 169.254.189.46&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 May 2021 06:07:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117391#M16589</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-05-01T06:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: BGP peering is not coming up - Please help</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117436#M16591</link>
      <description>&lt;P&gt;Is the 169.254.189.45 BGP peer arrive through the IPSec tunnel ?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would also look into VTI's in order to configure BGP over VPN , something like&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108958" target="_blank" rel="noopener"&gt;this&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In order to create a VRRP IP , you would need to have interface(s) in that network.&lt;/P&gt;</description>
      <pubDate>Sun, 02 May 2021 07:19:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117436#M16591</guid>
      <dc:creator>funkylicious</dc:creator>
      <dc:date>2021-05-02T07:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: BGP peering is not coming up - Please help</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117445#M16592</link>
      <description>&lt;P&gt;Well yes!! It is arriving through tunnel and I am seeing decrypted in logs.&lt;/P&gt;&lt;P&gt;The setup is done exactly as said here.&lt;/P&gt;&lt;P&gt;And to my surprise and I am not sure if I need to add mcvr address in the configuration for VTI with BGP?&lt;/P&gt;</description>
      <pubDate>Sun, 02 May 2021 13:44:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117445#M16592</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-05-02T13:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: BGP peering is not coming up - Please help</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117448#M16593</link>
      <description>&lt;P&gt;Honestly, I'm just taking a wild guess here, but i think you need to create a tunnel interface like below and maybe then try the mcvr ip address.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Screenshot 2021-05-02 at 18.53.25.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11594iD1CB93C03955D4D0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2021-05-02 at 18.53.25.png" alt="Screenshot 2021-05-02 at 18.53.25.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 May 2021 15:57:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117448#M16593</guid>
      <dc:creator>funkylicious</dc:creator>
      <dc:date>2021-05-02T15:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: BGP peering is not coming up - Please help</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117803#M16670</link>
      <description>&lt;P&gt;Well there must be a issue with VRRP solution for sure. I converted this cluster to Cluster XL and bgp peering happened immediately. That means in vrrp cluster mode firewall was not able to pick up the cluster ip however it did with cluster xl.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again would really apperciate if someone can confirm if this is a known limitation or if I hit any bug here?&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2021 08:03:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117803#M16670</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-05-06T08:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: BGP peering is not coming up - Please help</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117833#M16674</link>
      <description>&lt;P&gt;BGP over VTIs with VRRP is not supported. Just bumped into similar issue with one of my clients recently.&lt;/P&gt;
&lt;P&gt;You'll have to switch to CLusterXL to get it going.&lt;/P&gt;
&lt;P&gt;Also, in our case, we were not trying to establish tunnels with AWS, but with one of our peers, but another issue appeared to be that the use of arbitrary IPs on VTIs that are not adjacent (i.e. belong to a different network) did not work.&lt;/P&gt;
&lt;P&gt;We've had to use IPs with identical first three octets, otherwise, tunnels would come up, but BGP peering would not.&lt;/P&gt;
&lt;P&gt;From TAC:&lt;/P&gt;
&lt;P&gt;"&lt;SPAN style="caret-color: #000000; color: #000000; font-family: 'Times New Roman', serif; font-size: 16px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;"&gt;I spoke with our dynamic routing focal today and we got confirmation from R&amp;amp;D that VTIs and &lt;/SPAN&gt;&lt;SPAN style="font-family: inherit !important; font-size: inherit !important; font-style: inherit !important; font-variant-caps: inherit !important; font-weight: inherit !important; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; background-color: #ffee94 !important; color: #070706 !important; display: inline !important; position: static !important; margin: 0px !important; padding: 0px !important; opacity: 1 !important; float: inherit !important; font-stretch: inherit !important; line-height: inherit !important;"&gt;VRRP&lt;/SPAN&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: 'Times New Roman', serif; font-size: 16px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;"&gt; are not supported together because &lt;/SPAN&gt;&lt;SPAN style="font-family: inherit !important; font-size: inherit !important; font-style: inherit !important; font-variant-caps: inherit !important; font-weight: inherit !important; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; background-color: #ffee94 !important; color: #070706 !important; display: inline !important; position: static !important; margin: 0px !important; padding: 0px !important; opacity: 1 !important; float: inherit !important; font-stretch: inherit !important; line-height: inherit !important;"&gt;VRRP&lt;/SPAN&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: 'Times New Roman', serif; font-size: 16px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;"&gt; can't work with point to point interfaces. It seems that in order to get this configuration to work we would need to use clusterXL. We will make sure that we get the documentation updated to make this clear.&lt;/SPAN&gt;"&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2021 13:00:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117833#M16674</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-05-06T13:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: BGP peering is not coming up - Please help</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117834#M16675</link>
      <description>&lt;P&gt;This is really surprising. There is no Sk neither any official limitation confirms that BGP does not support over VRRP.&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2021 13:40:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117834#M16675</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-05-06T13:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: BGP peering is not coming up - Please help</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117837#M16676</link>
      <description>&lt;P&gt;Yeah, I've spent some significant time trying to make it work in the absence of relevant SK.&lt;/P&gt;
&lt;P&gt;One was promised as a result of thie SR opened for the case, but since you still cannot find anything, it was not published yet.&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2021 14:08:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-peering-is-not-coming-up-Please-help/m-p/117837#M16676</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-05-06T14:08:15Z</dc:date>
    </item>
  </channel>
</rss>

