<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OSPF drops on cluster failover since R81.10 upgrade from R80.30 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152842#M25525</link>
    <description>&lt;P&gt;I've tested and that did appear to do the trick &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; Thanks heaps!&amp;nbsp; Much better than what I was told to change was fwha_cluster_hide_active_only 0 kernel value.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this doesn't re-introduce the problem we had where another FW rebooting caused OSPF to drop on the check point but will cross that bridge if it still happens on R81.10 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; TAC advised for that case to enable GR and GR-Helper so touch wood we don't encounter that again.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jul 2022 00:03:35 GMT</pubDate>
    <dc:creator>cem82</dc:creator>
    <dc:date>2022-07-13T00:03:35Z</dc:date>
    <item>
      <title>OSPF drops on cluster failover since R81.10 upgrade from R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152083#M25145</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;After upgrading from R80.30 to R81.10 (active/standby ClusterXL) we have found that whenever the cluster is failed over we loose OSPF and advertised routes. This was working fine when on R80.30 with the same clish config with the router-ID set as the VIP on both cluster members.&amp;nbsp; When under stable conditions, we do see the OSPF routes sync'd to standby but historically if we did "show ospf neighbors" we would see the same as on the active.&amp;nbsp; Now we see none on the standby.&amp;nbsp; After a few min on either side of the cluster everything is fine again, is just upon failover for a few min things drop&lt;/P&gt;&lt;P&gt;Is there some other config or anything required for on R81.10?&amp;nbsp; I didn't notice anything in the clusterXL or advanced routing admin guides.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 03:04:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152083#M25145</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2022-06-30T03:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF drops on cluster failover since R81.10 upgrade from R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152095#M25146</link>
      <description>&lt;P&gt;R81.10 with JHF T55 is working well with OSPF in a cluster environment from customer testing that I've been involved with.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 06:54:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152095#M25146</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-06-30T06:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF drops on cluster failover since R81.10 upgrade from R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152097#M25147</link>
      <description>&lt;P&gt;We're also running JHF take 55.&amp;nbsp; Do you need to do anything additional above the type of thing below or clusterXL related&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;set router-id &amp;lt;cluster VIP&amp;gt;&lt;/P&gt;&lt;P&gt;set ospf instance default area backbone on&lt;BR /&gt;set ospf instance default interface &amp;lt;interface&amp;gt; area backbone on&lt;BR /&gt;set ospf instance default interface &amp;lt;interface&amp;gt; priority 1&lt;/P&gt;&lt;P&gt;and any associated route-filters / route redistribution.&amp;nbsp; There are a few other OSPF modifications along with "set ospf instance default" but nothing that I could imagine as causing problems since were also there prior to upgrade.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 07:24:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152097#M25147</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2022-06-30T07:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF drops on cluster failover since R81.10 upgrade from R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152098#M25148</link>
      <description>&lt;P&gt;What allowances have been made in the security policy itself for OSPF &amp;amp; IGMP?&lt;/P&gt;
&lt;P&gt;Is graceful restart configured in your case?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 07:24:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152098#M25148</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-06-30T07:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF drops on cluster failover since R81.10 upgrade from R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152099#M25149</link>
      <description>&lt;P&gt;FW policy hasn't changed at all for some time prior to or after the upgrade so would imagine that'd be fine.&amp;nbsp; Graceful restart and graceful-restart-helper are both enabled.&amp;nbsp; When looking at smartlog for src or dst of either cluster member or cluster object there are no drops.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 07:29:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152099#M25149</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2022-06-30T07:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF drops on cluster failover since R81.10 upgrade from R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152101#M25150</link>
      <description>&lt;P&gt;Graceful restart is new to R81.10 so if your comparing to R80.30 you should disable it for a like-for-like comparison.&lt;/P&gt;
&lt;P&gt;R81.10 "OSPFv2 Graceful Restart in ClusterXL (RFC standard)" Source&amp;nbsp;sk98226&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The above may seem contrary to what you might expect but you'll note the following stated in&amp;nbsp;&lt;SPAN&gt;sk95968&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OSPF CXL.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17076iBD7F0DA0F563663E/image-size/large?v=v2&amp;amp;px=999" role="button" title="OSPF CXL.png" alt="OSPF CXL.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 08:22:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152101#M25150</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-06-30T08:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF drops on cluster failover since R81.10 upgrade from R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152105#M25182</link>
      <description>&lt;P&gt;Thanks for pointing that out, when looking at the admin guide it seems to refer to that only for VRRP clusters?&amp;nbsp; As part of a TAC case it was recommended (and did) after enabling graceful-restart-helper (graceful restart was already enabled) to resolve an issue we had on another cluster running 80.30 to enable graceful-restart-helper.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully when I upgrade the other cluster the other issue doesn't break again if this is the fix to disable GR &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 08:49:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152105#M25182</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2022-06-30T08:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF drops on cluster failover since R81.10 upgrade from R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152842#M25525</link>
      <description>&lt;P&gt;I've tested and that did appear to do the trick &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; Thanks heaps!&amp;nbsp; Much better than what I was told to change was fwha_cluster_hide_active_only 0 kernel value.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this doesn't re-introduce the problem we had where another FW rebooting caused OSPF to drop on the check point but will cross that bridge if it still happens on R81.10 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; TAC advised for that case to enable GR and GR-Helper so touch wood we don't encounter that again.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 00:03:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152842#M25525</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2022-07-13T00:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF drops on cluster failover since R81.10 upgrade from R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152844#M25526</link>
      <description>&lt;P&gt;I understand why they would recommend that and perhaps warrants it's own TAC investigation to determine why GR didn't perform in the way indicated be it configuration on the peer (missing GR helper) or other issue (especially if it persists with T66 and higher).&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 06:37:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/m-p/152844#M25526</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-10-12T06:37:09Z</dc:date>
    </item>
  </channel>
</rss>

