<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BGP routes are missing after ClusterXL failover in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128860#M18799</link>
    <description>&lt;P&gt;Make sure your 'import-routemap' configuration matches on both firewall members, it seems like your BGP peering is up but you're not accepting any BGP routes due to a missing routemap.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Sep 2021 11:43:41 GMT</pubDate>
    <dc:creator>Andre_K</dc:creator>
    <dc:date>2021-09-07T11:43:41Z</dc:date>
    <item>
      <title>BGP routes are missing after ClusterXL failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128768#M18770</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hi All,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;I am facing a strange issue whereby the BGP session is established successfully with fw02 after failover but are unable to get advertised BGP Routes from SDWAN VeloCloud. Both CheckPoint firewalls are enabled with graceful restart options.&lt;/P&gt;&lt;P&gt;BGP session and routes are working good when fw01 is the active member.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Below is my topology:&lt;BR /&gt;Cisco Nexus (AS X)&amp;lt;---&amp;gt; CheckPoint Cluster(AS X) &amp;lt;----&amp;gt; SDWAN VeloCloud (AS Y)&lt;/P&gt;&lt;P&gt;After searching the /var/log/routed.log , There are some lines showing that CP GAIA OS is not supporting some capabilites of BGP,&lt;/P&gt;&lt;P&gt;Please refer to log below:&lt;BR /&gt;Sep 6 11:05:30.940081 bgp_get_open(3073): peer 10.25.x.x+21144 (proto) has provided 4 Byte AS 6xxxx&lt;BR /&gt;Sep 6 11:05:30.940081 bgp_get_open: peer 10.25.x.x+21144 (proto) &lt;FONT color="#FF6600"&gt;received unrecognized capability 69. Ignoring capability 69&lt;/FONT&gt;&lt;BR /&gt;Sep 6 11:05:30.940081 bgp_get_open: peer 10.25.x.x+21144 (proto) &lt;FONT color="#FF6600"&gt;received unrecognized capability 73. Ignoring capability 73&lt;/FONT&gt;&lt;BR /&gt;Sep 6 11:05:30.940081 bgp_pp_recv: Receiving OPEN from peer 10.25.x.x +15501 [eBGP AS 6xxxx] in ESTABLISHED state, entering Graceful Restart Helper mode&lt;BR /&gt;Sep 6 11:05:30.940081 bgp_event: peer 10.25.x.x+15501 [eBGP AS 6xxxx] old state Established event RecvOpen new state Idle&lt;BR /&gt;Sep 6 11:05:30.940081 bgp_graceful_restart_close_stale_connection: &lt;FONT color="#FF6600"&gt;Peer 10.25.x.x+15501 [eBGP AS 6xxxx] does not support non-stop forwarding for any AFI/SAFI, remove all routes from him&lt;/FONT&gt;&lt;BR /&gt;CHANGE X.X.X.X /31 gw 10.25.x.x BGP&lt;BR /&gt;pref 170/- metric /100 bond2.43 &amp;lt;Ext|Delete|Gateway&amp;gt; as 6xxxx&lt;BR /&gt;CHANGE X.X.X.X /24 gw 10.25.x.x BGP&lt;BR /&gt;pref 170/- metric /100 bond2.43 &amp;lt;Ext|Delete|Gateway&amp;gt; as 6xxxx&lt;BR /&gt;CHANGE X.X.X.X /32 gw 10.25.x.x BGP&lt;BR /&gt;&lt;BR /&gt;It is resolved by disabled the graceful restart feature in fw02 only. So I having fw01 (enabled graceful restart) and fw02(disabled graceful restart).&lt;BR /&gt;&lt;BR /&gt;Hope someone enlighten on why it is still working at fw01 even this fw is enabled with graceful restart options?&lt;/P&gt;&lt;P&gt;FW version is R80.40 with jhf take 102.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 11:29:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128768#M18770</guid>
      <dc:creator>Wei_Soon_Heng</dc:creator>
      <dc:date>2021-09-06T11:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: BGP routes are missing after ClusterXL failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128773#M18772</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/ip/border-gateway-protocol-bgp/116189-problemsolution-technology-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/ip/border-gateway-protocol-bgp/116189-problemsolution-technology-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I am not sure if this will actually fix it, but I had a similar issue sone time back that got resolved setting the non-capabilities on the Cisco end..&amp;nbsp; Also, I think that there has been some fix for this in R81.10&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What CP version are you rinning ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 08:58:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128773#M18772</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2021-09-06T08:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: BGP routes are missing after ClusterXL failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128777#M18774</link>
      <description>&lt;P&gt;I had seen this before and firewall reboot had to be done to fix it.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 11:12:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128777#M18774</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-06T11:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: BGP routes are missing after ClusterXL failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128779#M18775</link>
      <description>&lt;P&gt;&lt;SPAN&gt;FW is running version R80.40 with jhf take 102.&lt;BR /&gt;Unfortunately, the peer is not Cisco, it is SDWAN VeloCloud device.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 11:30:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128779#M18775</guid>
      <dc:creator>Wei_Soon_Heng</dc:creator>
      <dc:date>2021-09-06T11:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: BGP routes are missing after ClusterXL failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128853#M18796</link>
      <description>&lt;P&gt;problem still exists after reboot of problematic secondary fw&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 10:01:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128853#M18796</guid>
      <dc:creator>Wei_Soon_Heng</dc:creator>
      <dc:date>2021-09-07T10:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: BGP routes are missing after ClusterXL failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128859#M18798</link>
      <description>&lt;P&gt;I would open TAC case...cant find much on those errors at all. If reboot did not clear it, there could be a bigger issue here.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 11:35:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128859#M18798</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-07T11:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: BGP routes are missing after ClusterXL failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128860#M18799</link>
      <description>&lt;P&gt;Make sure your 'import-routemap' configuration matches on both firewall members, it seems like your BGP peering is up but you're not accepting any BGP routes due to a missing routemap.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 11:43:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128860#M18799</guid>
      <dc:creator>Andre_K</dc:creator>
      <dc:date>2021-09-07T11:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: BGP routes are missing after ClusterXL failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128865#M18802</link>
      <description>&lt;P&gt;Another thing that came to my mind was maybe do a quick comparison of BGP on both members...just go to clish and run show bgp, hit tab and it will give you all the options to run the command. Its possible something might be missing on the fw2 member. Just a thought...&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 12:27:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/128865#M18802</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-07T12:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: BGP routes are missing after ClusterXL failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/129275#M18910</link>
      <description>&lt;P&gt;Is it a clean install or in-place upgrade from an older version?&lt;/P&gt;
&lt;P&gt;I would check the route-maps / filter lists are uniform on both but also verify FIBMGR traffic per sk109401.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 11:04:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routes-are-missing-after-ClusterXL-failover/m-p/129275#M18910</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-09-13T11:04:32Z</dc:date>
    </item>
  </channel>
</rss>

