<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how to properly run BFD over VSX virtual Switches? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-properly-run-BFD-over-VSX-virtual-Switches/m-p/151041#M24596</link>
    <description>&lt;P&gt;Hello Check Mates,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;i have following situation:&lt;BR /&gt;&lt;BR /&gt;we have created a VSX Setup.&lt;BR /&gt;5 VS Systems&amp;nbsp;&lt;BR /&gt;they are connected over a virtual switch acting as a "backbone link"&lt;BR /&gt;&lt;SPAN&gt;this 5 VS systems connects to a bunch of Cisco Routers and do dynamic routing with OSPF.&lt;BR /&gt;we distribute all routes from the Cisco world to the Check Point world and we redistribute default routes to the Cisco Routers.&lt;BR /&gt;&lt;SPAN&gt;this works so far.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;for fast convergence we use BFD to speed up the OSPF, this works very well.&lt;BR /&gt;also we want(ed) to use BFD to communicate between the VSX Systems, but this seems not to work.&lt;BR /&gt;&lt;BR /&gt;output from one the VS looks like this:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;show ip-reachability-detection&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Ping Count: 3&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Ping Interval: 3&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;BFD Minimum TX Interval: 300 ms&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;BFD Minimum RX Interval: 900 ms&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;BFD Detect Multiplier: 3&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;*Only the cluster master can send or accept ICMP packets.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Remote Address Protocol Reachable* &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;x.x.x.1 _ _ _ _ _ _ _ _ _ _ BFD (S) Yes &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;x.x.x.2 _ _ _ _ _ _ _ _ _ _ BFD (S) Yes &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;x.x.x.81 _ _ _ _ _ _ _ _ _ BFD (S) Yes &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;x.x.x.82 _ _ _ _ _ _ _ _ _ BFD (S) Yes &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;x.x.x.105 _ _ _ _ _ _ _ _ _ BFD (S) Yes &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;x.x.x.106 _ _ _ _ _ _ _ _ _ BFD (S) Yes &lt;/EM&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;y.y.y.210 _ _ _ _ _ _ _ _ _ BFD (S) Unknown &amp;lt;- Check Point VS, it should see at least 5 i see only 2 ?&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;y.y.y.211 _ _ _ _ _ _ _ _ _ BFD (S) Unknown&amp;nbsp;&amp;lt;- Check Point VS, it should see at least 5 i see only 2 ?&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;this is configured as BFD Singlehop. i dont got BFD Multihop running. if i choose PING for &lt;EM&gt;"ip-reachability-detection"&lt;BR /&gt;&lt;/EM&gt;then it is showing as UP.&lt;BR /&gt;Between the VS is just a a flat transit network made via a VSX switch.&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;we also figured out, if the BFD is configured not the same over all VS the OSPF process is flapping when adding or removing interfaces to a VS which is in fact very dramatic. we deleted and added interfaces on the VS´s via SmartConsole and the OSPF routes got totally lost.&lt;BR /&gt;we saw not all BFD settings, were configured equally, some had BFD and some had PING for IP&amp;nbsp;&lt;EM&gt;"ip-reachability-detection".&lt;BR /&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;SPAN&gt; After deleting all BFD configuration between the VS the OSPF routes did not disappear when adding/deleting interfaces to an VS, via SmartConsole ...&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Question: what would you do?&lt;BR /&gt;&lt;/STRONG&gt;&lt;EM&gt;BFD between the VS, YES/NO&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;use PING for IP-REACHABILITY instead of BFD? YES/NO&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;is it BFD Multihop? YES/NO&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;software version is of couse the latest and greatest, R81.10 + Take 55&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;best regards&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jun 2022 09:56:08 GMT</pubDate>
    <dc:creator>Thomas_Eichelbu</dc:creator>
    <dc:date>2022-06-16T09:56:08Z</dc:date>
    <item>
      <title>how to properly run BFD over VSX virtual Switches?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-properly-run-BFD-over-VSX-virtual-Switches/m-p/151041#M24596</link>
      <description>&lt;P&gt;Hello Check Mates,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;i have following situation:&lt;BR /&gt;&lt;BR /&gt;we have created a VSX Setup.&lt;BR /&gt;5 VS Systems&amp;nbsp;&lt;BR /&gt;they are connected over a virtual switch acting as a "backbone link"&lt;BR /&gt;&lt;SPAN&gt;this 5 VS systems connects to a bunch of Cisco Routers and do dynamic routing with OSPF.&lt;BR /&gt;we distribute all routes from the Cisco world to the Check Point world and we redistribute default routes to the Cisco Routers.&lt;BR /&gt;&lt;SPAN&gt;this works so far.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;for fast convergence we use BFD to speed up the OSPF, this works very well.&lt;BR /&gt;also we want(ed) to use BFD to communicate between the VSX Systems, but this seems not to work.&lt;BR /&gt;&lt;BR /&gt;output from one the VS looks like this:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;show ip-reachability-detection&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Ping Count: 3&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Ping Interval: 3&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;BFD Minimum TX Interval: 300 ms&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;BFD Minimum RX Interval: 900 ms&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;BFD Detect Multiplier: 3&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;*Only the cluster master can send or accept ICMP packets.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Remote Address Protocol Reachable* &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;x.x.x.1 _ _ _ _ _ _ _ _ _ _ BFD (S) Yes &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;x.x.x.2 _ _ _ _ _ _ _ _ _ _ BFD (S) Yes &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;x.x.x.81 _ _ _ _ _ _ _ _ _ BFD (S) Yes &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;x.x.x.82 _ _ _ _ _ _ _ _ _ BFD (S) Yes &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;x.x.x.105 _ _ _ _ _ _ _ _ _ BFD (S) Yes &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;x.x.x.106 _ _ _ _ _ _ _ _ _ BFD (S) Yes &lt;/EM&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;y.y.y.210 _ _ _ _ _ _ _ _ _ BFD (S) Unknown &amp;lt;- Check Point VS, it should see at least 5 i see only 2 ?&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;y.y.y.211 _ _ _ _ _ _ _ _ _ BFD (S) Unknown&amp;nbsp;&amp;lt;- Check Point VS, it should see at least 5 i see only 2 ?&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;this is configured as BFD Singlehop. i dont got BFD Multihop running. if i choose PING for &lt;EM&gt;"ip-reachability-detection"&lt;BR /&gt;&lt;/EM&gt;then it is showing as UP.&lt;BR /&gt;Between the VS is just a a flat transit network made via a VSX switch.&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;we also figured out, if the BFD is configured not the same over all VS the OSPF process is flapping when adding or removing interfaces to a VS which is in fact very dramatic. we deleted and added interfaces on the VS´s via SmartConsole and the OSPF routes got totally lost.&lt;BR /&gt;we saw not all BFD settings, were configured equally, some had BFD and some had PING for IP&amp;nbsp;&lt;EM&gt;"ip-reachability-detection".&lt;BR /&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;SPAN&gt; After deleting all BFD configuration between the VS the OSPF routes did not disappear when adding/deleting interfaces to an VS, via SmartConsole ...&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Question: what would you do?&lt;BR /&gt;&lt;/STRONG&gt;&lt;EM&gt;BFD between the VS, YES/NO&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;use PING for IP-REACHABILITY instead of BFD? YES/NO&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;is it BFD Multihop? YES/NO&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;software version is of couse the latest and greatest, R81.10 + Take 55&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;best regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 09:56:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-properly-run-BFD-over-VSX-virtual-Switches/m-p/151041#M24596</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2022-06-16T09:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: how to properly run BFD over VSX virtual Switches?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-properly-run-BFD-over-VSX-virtual-Switches/m-p/151044#M24599</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/24246"&gt;@Thomas_Eichelbu&lt;/a&gt;&amp;nbsp;in the past we tried something similar with probing different VSs as destination from other VSs. It was a nightmare, somtimes working some not, running VSLS and moving active VS from one node to another node results in a desaster.&lt;/P&gt;
&lt;P&gt;I don't know how exactly the communication works internal if you have only inter VS traffic but it feels like something "magic"&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt; Debugging such a communication will be too problematic, because you don't see all of the packets on the internal wrp interfaces.&lt;/P&gt;
&lt;P&gt;Good luck and hope someone from Check Point can help&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 11:14:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-properly-run-BFD-over-VSX-virtual-Switches/m-p/151044#M24599</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-06-16T11:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: how to properly run BFD over VSX virtual Switches?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-properly-run-BFD-over-VSX-virtual-Switches/m-p/151234#M24652</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;i fear you are right. The more i think about this topic the more iam convinced BFD makes me sense between the VS instances over a Virtual Switch since the OSPF has nothing to converge too.&lt;BR /&gt;if a VS becomes unavailable it has no second path either to fail over too.&lt;BR /&gt;so better to remove the&amp;nbsp;&lt;EM style="color: #6d6e71;"&gt;ip-reachability-detection" &lt;/EM&gt;between the VS and leave it only for the OSPF peers.&lt;/P&gt;
&lt;P&gt;Check Point TAC is already working on it ... but more on the issue with the lost OSPF routes when adding/removing interfaces.&lt;BR /&gt;&lt;BR /&gt;best regards&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 08:00:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-to-properly-run-BFD-over-VSX-virtual-Switches/m-p/151234#M24652</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2022-06-20T08:00:02Z</dc:date>
    </item>
  </channel>
</rss>

