<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bgp does not Established when Standby become Active in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126427#M18321</link>
    <description>&lt;P&gt;No problem. Yes, I see BGP routes like 1 that works.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Aug 2021 09:26:19 GMT</pubDate>
    <dc:creator>cstaffbrad</dc:creator>
    <dc:date>2021-08-11T09:26:19Z</dc:date>
    <item>
      <title>Bgp does not Established when Standby become Active</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/125688#M18246</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4400 Next Generation Firewall HA Appliance&lt;BR /&gt;Cluster Mode HA (Active,Standby) R80.40 Take 118&lt;BR /&gt;Configuration in place a per sk108958&lt;/P&gt;&lt;P&gt;We have implemented Dynamic routing protocol&lt;BR /&gt;as per sk108958 but when Cluster-1 is in the active state, the bgp traffic is processed&lt;BR /&gt;according to the implicit rule 0. But when Cluster-2 became active,&lt;BR /&gt;I see bgp traffic being drop by rule 100.&lt;/P&gt;&lt;P&gt;The workaround is to create a rule and allow the bgp traffic rule&lt;BR /&gt;in order to have the bgp status in the established state.&lt;/P&gt;&lt;P&gt;The question now is why is BGP traffic handled with implicit rule&lt;BR /&gt;when cluster-1 is Active? and does not apply to cluster-2 when&lt;BR /&gt;this becomes active?&lt;/P&gt;&lt;P&gt;Is this specific BGP rule necessary? is this official solution ?&lt;BR /&gt;is it by design or is it a bug?&lt;/P&gt;&lt;P&gt;sk39960 explained how to allow bgp traffic&lt;BR /&gt;How to allow dynamic routing protocols (OSPF, BGP, PIM, RIP, IGRP) traffic through Check Point Security Gateway&lt;BR /&gt;If this is the right solution, then why is the bgp traffic handled by an implicit rule?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 12:33:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/125688#M18246</guid>
      <dc:creator>cstaffbrad</dc:creator>
      <dc:date>2021-08-04T12:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: Bgp does not Established when Standby become Active</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/125908#M18277</link>
      <description>&lt;P&gt;What precise traffic is being allowed by the implicit rule on the primary versus an explicit rule on the secondary when it is active?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 22:35:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/125908#M18277</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-06T22:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Bgp does not Established when Standby become Active</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126205#M18306</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ImpliedRule.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12928i4A2D536465E3458A/image-size/large?v=v2&amp;amp;px=999" role="button" title="ImpliedRule.JPG" alt="ImpliedRule.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 10:18:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126205#M18306</guid>
      <dc:creator>cstaffbrad</dc:creator>
      <dc:date>2021-08-10T10:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: Bgp does not Established when Standby become Active</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126241#M18308</link>
      <description>&lt;P&gt;Looks like the traffic is sourced from the GW itself on the implied rule. Outgoing traffic is an implied rule.&lt;/P&gt;&lt;P&gt;Is the dropped traffic also sourced locally? That would be unexpected.&lt;/P&gt;&lt;P&gt;You need a BGP rule to accept the traffic for incoming BGP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 13:50:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126241#M18308</guid>
      <dc:creator>Albin</dc:creator>
      <dc:date>2021-08-10T13:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Bgp does not Established when Standby become Active</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126262#M18310</link>
      <description>&lt;P&gt;Yes, The Dropped traffic is also sourced locally.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 14:58:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126262#M18310</guid>
      <dc:creator>cstaffbrad</dc:creator>
      <dc:date>2021-08-10T14:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: Bgp does not Established when Standby become Active</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126265#M18311</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/51798"&gt;@Albin&lt;/a&gt;&amp;nbsp;gave a good explanation. Do you have an actual rule that would accept incoming BGP? Something for protocol 179?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 16:45:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126265#M18311</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-08-10T16:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: Bgp does not Established when Standby become Active</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126268#M18313</link>
      <description>&lt;P&gt;I don't know if I understand your question correctly, but I think the description of the problem should answer your question.&lt;/P&gt;&lt;P&gt;"The workaround is to create a rule and allow the bgp traffic rule in order to have the bgp status in the established state. The question now is why is BGP traffic handled with implicit rule when cluster-1 is Active? and does not apply to cluster-2 when this becomes active?"&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 16:53:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126268#M18313</guid>
      <dc:creator>cstaffbrad</dc:creator>
      <dc:date>2021-08-10T16:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: Bgp does not Established when Standby become Active</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126269#M18314</link>
      <description>&lt;P&gt;My bad, missed that part, sorry about that. Cant say I ever seen that before, does not make a whole lot of sense, since rule would apply to the cluster regardless. Im wondering, when member 2 is active, what does clish -c "show route bgp" show? Do you see all the BGP routes there like on member 1 that works?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 17:01:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126269#M18314</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-08-10T17:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: Bgp does not Established when Standby become Active</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126427#M18321</link>
      <description>&lt;P&gt;No problem. Yes, I see BGP routes like 1 that works.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 09:26:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126427#M18321</guid>
      <dc:creator>cstaffbrad</dc:creator>
      <dc:date>2021-08-11T09:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: Bgp does not Established when Standby become Active</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126538#M18324</link>
      <description>&lt;P&gt;I would probably open TAC case...I find that behavior very odd. Not sure if you tried rebooting &amp;nbsp;member 2 or not, but it might be worth a shot.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 11:30:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/126538#M18324</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-08-11T11:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Bgp does not Established when Standby become Active</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/176806#M32375</link>
      <description>&lt;P&gt;This was a old discussion without solution in checkmates. And I know nearly nothing about BGP.&lt;BR /&gt;My idea and question is:&lt;BR /&gt;Is a actual connection droped during failover or is it impossible to establish a new connection after failover?&lt;BR /&gt;The accepted outgoing connection is originating from member gateway-1 IP?&lt;BR /&gt;So I think a actual connection originating from member gateway IP cannot survive a cluster failover. How could state table entry change its source IP to member gateway-2 IP to work on the new active cluster member?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 18:55:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/176806#M32375</guid>
      <dc:creator>Joerg_Schneider</dc:creator>
      <dc:date>2023-03-30T18:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: Bgp does not Established when Standby become Active</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/176821#M32385</link>
      <description>&lt;P&gt;There isn't enough config detail here for a clear&amp;nbsp; picture. Granted there is also a VPN involved.&lt;/P&gt;
&lt;P&gt;Is Graceful restart configured?&lt;/P&gt;
&lt;P&gt;Is the Router_ID set the same on both members?&lt;/P&gt;
&lt;P&gt;Were the BGP peer "local address" settings manipulated on one member compared to the other?&lt;/P&gt;
&lt;P&gt;What do the precise rules allowing the traffic look like?&lt;/P&gt;
&lt;P&gt;Do the remote devices correctly target the VIP as the BGP peer?&lt;/P&gt;
&lt;P&gt;What version &amp;amp; JHF was the gateway etc&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 23:18:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bgp-does-not-Established-when-Standby-become-Active/m-p/176821#M32385</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-30T23:18:01Z</dc:date>
    </item>
  </channel>
</rss>

