<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ClusterXL OSPF in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-OSPF/m-p/122171#M17480</link>
    <description>&lt;P&gt;If Router-id is not configured as Cluster IP then LSA on peer device are not updated. I could see router LSA with unreachable metric as soon as I changed the router-id to Cluster IP, it is working fine.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jun 2021 12:26:21 GMT</pubDate>
    <dc:creator>vinodsh</dc:creator>
    <dc:date>2021-06-25T12:26:21Z</dc:date>
    <item>
      <title>ClusterXL OSPF</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-OSPF/m-p/19748#M1521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team.&lt;/P&gt;&lt;P&gt;I have a question about OSPF work in HA pair (R80.10).&lt;/P&gt;&lt;P&gt;Do I need configure graceful restart or other special settings for seamless failover?&lt;/P&gt;&lt;P&gt;I tested failover scenario and&amp;nbsp;after I disable current active&lt;SPAN&gt;&amp;nbsp;member with clusterxl admin down new active member stopped forwarding traffic because&amp;nbsp;of lack of routing information&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 17:08:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-OSPF/m-p/19748#M1521</guid>
      <dc:creator>Dmitry_Barantse</dc:creator>
      <dc:date>2018-08-16T17:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL OSPF</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-OSPF/m-p/19749#M1522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know, you do not need Graceful Restart unless you are using VRRP.&lt;/P&gt;&lt;P&gt;With regular ClusterXL, routing information should sync between cluster members.&lt;/P&gt;&lt;P&gt;The router-id should be configured as the Cluster IP, though.&lt;/P&gt;&lt;P&gt;See also:&amp;nbsp;&lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk95968" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk95968"&gt;OSPF on Gaia&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2018 01:30:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-OSPF/m-p/19749#M1522</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-17T01:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL OSPF</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-OSPF/m-p/19750#M1523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like OSPF synchronization is not working for you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is done on TCP port 2010. You can start troubleshooting with this SK:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk62570&amp;amp;partition=Advanced&amp;amp;product=ClusterXL,#FIBMGR" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk62570&amp;amp;partition=Advanced&amp;amp;product=ClusterXL,#FIBMGR"&gt;How to troubleshoot failovers in ClusterXL - Advanced Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some additional recommendations concerning FW rules you may need to put in place are here:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31243" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31243"&gt;ClusterXL member is "Down" due to Critical device "FIB"&lt;/A&gt;&amp;nbsp;Mind this SK is not directly applicable to your case, but the FW rules mentioned there are.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2018 07:56:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-OSPF/m-p/19750#M1523</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-17T07:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL OSPF</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-OSPF/m-p/122171#M17480</link>
      <description>&lt;P&gt;If Router-id is not configured as Cluster IP then LSA on peer device are not updated. I could see router LSA with unreachable metric as soon as I changed the router-id to Cluster IP, it is working fine.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 12:26:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-OSPF/m-p/122171#M17480</guid>
      <dc:creator>vinodsh</dc:creator>
      <dc:date>2021-06-25T12:26:21Z</dc:date>
    </item>
  </channel>
</rss>

