<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best method to advertise BGP from ClusterXL VIP? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147334#M23513</link>
    <description>&lt;P&gt;I actually only created the interface (which is actually in the same vmware portgroup) just to have an IP in that range to work with.&lt;/P&gt;&lt;P&gt;So, I think what you're saying is - I can potentially remove the interface all together and use something like NAT Pool - and that will probably work.&lt;/P&gt;&lt;P&gt;I should then be able to create NAT rules for this subset of IPs;&lt;/P&gt;&lt;P&gt;and probably enable automatic proxy arp --&amp;gt; since this is ClusterXL - static arps for the same IP on 2 members probably won't work?&lt;/P&gt;</description>
    <pubDate>Thu, 28 Apr 2022 13:17:15 GMT</pubDate>
    <dc:creator>Rob_Shears</dc:creator>
    <dc:date>2022-04-28T13:17:15Z</dc:date>
    <item>
      <title>Best method to advertise BGP from ClusterXL VIP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147119#M23439</link>
      <description>&lt;P&gt;I have a clusterxl interface setup between 2 gateways.&lt;/P&gt;&lt;P&gt;I have a /30 to advertise (yes, I know. Small for BGP but this is the ISPs requirement).&lt;/P&gt;&lt;P&gt;After arguing with a vendor and doing a bunch of reading, the docs lead me to believe ClusterXL will support BGP just fine.&lt;/P&gt;&lt;P&gt;What is my best option to advertise the /30 from the cluster?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since it's a /30 (only allowing 2 ips), I established an interface VIP with 72.131.248.249/30 between members on a private subnet - 172.17.1.5 and 172.17.1.6.&lt;/P&gt;&lt;P&gt;Redistribute interface seems to work perfectly, but I'm unable to filter out the 172.17.x.x on the CP side.&lt;/P&gt;&lt;P&gt;Should I be setting up a static route for 72.131.248.249/30 with an interface gateway only and redistribute that?&lt;BR /&gt;&lt;BR /&gt;Or a NAT pool?&lt;BR /&gt;&lt;BR /&gt;Both of the last two options seemingly don't work for me. BGP is established but the route is not pushed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cp-gw-1&amp;gt; show bgp peer 172.17.0.1 adj-rib-out&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;... shows routes when "Interface" is selected, but not when a static route or NAT pool is used for redistribution in Gaia.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 02:29:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147119#M23439</guid>
      <dc:creator>Rob_Shears</dc:creator>
      <dc:date>2022-04-27T02:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to advertise BGP from ClusterXL VIP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147122#M23440</link>
      <description>&lt;P&gt;You have few options:&lt;/P&gt;
&lt;P&gt;1) Using NAT-Pools.&lt;/P&gt;
&lt;P&gt;2) Using static routes.&lt;/P&gt;
&lt;P&gt;3) Using routemaps and match on an exact prefix and protocol direct. Check sk100501.&lt;/P&gt;
&lt;P&gt;Last option is the most standard way of redistributing routes.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 02:51:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147122#M23440</guid>
      <dc:creator>Sundeep_Mudgal</dc:creator>
      <dc:date>2022-04-27T02:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to advertise BGP from ClusterXL VIP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147203#M23476</link>
      <description>&lt;P&gt;For some reason I can't get NAT Pools or static routes to work.&lt;BR /&gt;&lt;BR /&gt;Using "interfaces" works. If I use the same route that "interfaces" pushed but via NAT-Pools or static routes, the bgp session is established but no route is advertised by the CP. Will continue to play.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 14:26:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147203#M23476</guid>
      <dc:creator>Rob_Shears</dc:creator>
      <dc:date>2022-04-27T14:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to advertise BGP from ClusterXL VIP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147217#M23485</link>
      <description>&lt;P&gt;You will have to explicitly redistribute NAT pools to the destination AS. If you are using routemaps then route-redistribution commands will not work.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 15:53:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147217#M23485</guid>
      <dc:creator>Sundeep_Mudgal</dc:creator>
      <dc:date>2022-04-27T15:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to advertise BGP from ClusterXL VIP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147249#M23493</link>
      <description>&lt;P&gt;No routemap commands issued, so they shouldn't be overriding my attempts.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Using "interfaces" redistribution, the routes&amp;nbsp;&lt;SPAN&gt;72.131.248.249/30 and 172.17.1.4/30 are redistributed as seen with "show bgp peers adj-rib-out". I would like to use Gaia web ui and find a way to only push&amp;nbsp;72.131.248.249/30.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I've tried creating a static route blackhole for&amp;nbsp;72.131.248.249/30 and using the "static" option. "show bgp peers adj-rib-out" says "no route advertised".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I've tried creating a NAT Pool with&amp;nbsp;72.131.248.249/30 and using the NAT Pool redistribution option. Same.&amp;nbsp;"show bgp peers adj-rib-out" says "no route advertised".&lt;BR /&gt;&lt;BR /&gt;I also tried the "Kernel" option, and it is the same. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Nothing stands out in /var/log/routed* to signify a problem and a bgp session IS established, just no routes advertised.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 21:31:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147249#M23493</guid>
      <dc:creator>Rob_Shears</dc:creator>
      <dc:date>2022-04-27T21:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to advertise BGP from ClusterXL VIP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147251#M23494</link>
      <description>&lt;P&gt;I think I know whats happening.&amp;nbsp; The C route is the only active route and therefore static and NAT pools do not become active. You can check in "show route". Only active routes get redistributed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don;t think there is any other way besides routemaps to achieve the granularity that you are aiming form.&amp;nbsp; We will try to get this in next maintrain. Would it be possible for you to open a RFE request?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 22:01:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147251#M23494</guid>
      <dc:creator>Sundeep_Mudgal</dc:creator>
      <dc:date>2022-04-27T22:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to advertise BGP from ClusterXL VIP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147334#M23513</link>
      <description>&lt;P&gt;I actually only created the interface (which is actually in the same vmware portgroup) just to have an IP in that range to work with.&lt;/P&gt;&lt;P&gt;So, I think what you're saying is - I can potentially remove the interface all together and use something like NAT Pool - and that will probably work.&lt;/P&gt;&lt;P&gt;I should then be able to create NAT rules for this subset of IPs;&lt;/P&gt;&lt;P&gt;and probably enable automatic proxy arp --&amp;gt; since this is ClusterXL - static arps for the same IP on 2 members probably won't work?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 13:17:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147334#M23513</guid>
      <dc:creator>Rob_Shears</dc:creator>
      <dc:date>2022-04-28T13:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to advertise BGP from ClusterXL VIP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147348#M23515</link>
      <description>&lt;P&gt;You can try but this is not what I was suggesting. I was trying to reason out why the relevant prefix is not being redistributed. It would just be simpler if you use routemaps. You can open a configuration task so TAC can help you.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 14:27:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147348#M23515</guid>
      <dc:creator>Sundeep_Mudgal</dc:creator>
      <dc:date>2022-04-28T14:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to advertise BGP from ClusterXL VIP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147446#M23517</link>
      <description>&lt;P&gt;If I removed the interface, it would no longer be a Connected route is what I was getting at.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would route-maps display on GUI and are they supported on ClusterXL?&lt;BR /&gt;&lt;BR /&gt;Edit: based on your analysis, I removed the interface and the NAT pool instantly started working! Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2022 09:55:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147446#M23517</guid>
      <dc:creator>Rob_Shears</dc:creator>
      <dc:date>2022-04-29T09:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to advertise BGP from ClusterXL VIP?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147480#M23518</link>
      <description>&lt;P&gt;I am glad that it works for you. Regarding your questions:&lt;/P&gt;
&lt;P&gt;- Routemaps are not on Web-UI. They are only CLI commands.&lt;/P&gt;
&lt;P&gt;- Routemaps work with clustering.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2022 15:43:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-method-to-advertise-BGP-from-ClusterXL-VIP/m-p/147480#M23518</guid>
      <dc:creator>Sundeep_Mudgal</dc:creator>
      <dc:date>2022-04-29T15:43:18Z</dc:date>
    </item>
  </channel>
</rss>

