<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Not advertising IPv6 subnet to BGP peer in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-advertising-IPv6-subnet-to-BGP-peer/m-p/159414#M27899</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;From our cluster we have set up an IPv6 BGP peering connection with the ISP which is working fine. We receive the IPv6 default route from the ISP.&lt;/P&gt;&lt;P&gt;But we do not manage to advertise our local IPv6 connected subnet to the BGP peer of the ISP with our export routemap.&lt;/P&gt;&lt;P&gt;Any suggestions? Maybe an error in the routemap? (Reference to actual config/ip's have been altered or contains placeholder)&lt;/P&gt;&lt;P&gt;R81.10&lt;/P&gt;&lt;P&gt;CheckPoint fw&amp;gt;&lt;/P&gt;&lt;P&gt;set bgp external remote-as &amp;lt;ISP AS&amp;gt; peer 2001:x:x:x::1 on&lt;BR /&gt;set bgp external remote-as &amp;lt;ISP AS&amp;gt; peer 2001:x:x:x::1 capability ipv6-unicast on&lt;BR /&gt;set bgp external remote-as &amp;lt;ISP AS&amp;gt; peer 2001:x:x:x::1 holdtime 90&lt;BR /&gt;set bgp external remote-as &amp;lt;ISP AS&amp;gt; peer 2001:x:x:x::1 keepalive 30&lt;BR /&gt;set bgp external remote-as &amp;lt;ISP AS&amp;gt; peer 2001:x:x:x::1 authtype md5 secret &amp;lt;md5 secret&amp;gt;&lt;BR /&gt;set bgp external remote-as &amp;lt;ISP AS&amp;gt; peer 2001:x:x:x::1 export-routemap "EXP-IPV6-routemap" preference 10 on&lt;BR /&gt;set bgp external remote-as &amp;lt;ISP AS&amp;gt; peer 2001:x:x:x::1 import-routemap "IMP-IPV6-routemap" preference 10 on&lt;/P&gt;&lt;P&gt;CheckPoint fw&amp;gt; &lt;STRONG&gt;show configuration routemap EXP-IPV6-routemap&lt;/STRONG&gt;&lt;BR /&gt;set routemap EXP-IPV6-routemap id 10 on&lt;BR /&gt;set routemap EXP-IPV6-routemap id 10 allow&lt;BR /&gt;set routemap EXP-IPV6-routemap id 10 match network 2a07:2240:17f8::/48 exact&lt;BR /&gt;set routemap EXP-IPV6-routemap id 10 match protocol direct&lt;/P&gt;&lt;P&gt;CheckPoint fw&amp;gt; &lt;STRONG&gt;show bgp peers established&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Flags: R - Peer restarted, W - Waiting for End-Of-RIB from Peer&lt;BR /&gt;PeerID AS Routes ActRts State InUpds OutUpds Uptime&lt;BR /&gt;2001:x:x:x::1 &amp;lt;ISP AS&amp;gt; 1 0 Established 2 0 2d9h&lt;/P&gt;&lt;P&gt;CheckPoint fw&amp;gt; &lt;STRONG&gt;show bgp peer 2001:x:x:x::1 received&lt;/STRONG&gt;&lt;BR /&gt;IPv6 Route MED LocalPref Nexthop Communities&lt;BR /&gt;::/0 None N/A(EBGP) 2001:x:x:x::1 (link-local: fe80::da24:bcff:fec7:a7c2)&lt;/P&gt;&lt;P&gt;CheckPoint fw&amp;gt; &lt;STRONG&gt;show bgp peer 2001:x:x:x::1 advertise&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;EMPTY&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;CheckPoint fw&amp;gt; &lt;STRONG&gt;show ipv6 route destination 2a07:2200:13f8::&lt;/STRONG&gt;&lt;BR /&gt;Codes: C - Connected, S - Static, B - BGP, Rg - RIPng, A - Aggregate,&lt;BR /&gt;O - OSPFv3 IntraArea (IA - InterArea, E - External),&lt;BR /&gt;K - Kernel Remnant, H - Hidden, P - Suppressed,&lt;BR /&gt;NP - NAT Pool, U - Unreachable, i - Inactive&lt;/P&gt;&lt;P&gt;C 2a07:2200:13f8::/48 is directly connected, bondx.xxx&lt;/P&gt;</description>
    <pubDate>Thu, 13 Oct 2022 05:09:12 GMT</pubDate>
    <dc:creator>Arend</dc:creator>
    <dc:date>2022-10-13T05:09:12Z</dc:date>
    <item>
      <title>Not advertising IPv6 subnet to BGP peer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-advertising-IPv6-subnet-to-BGP-peer/m-p/159414#M27899</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;From our cluster we have set up an IPv6 BGP peering connection with the ISP which is working fine. We receive the IPv6 default route from the ISP.&lt;/P&gt;&lt;P&gt;But we do not manage to advertise our local IPv6 connected subnet to the BGP peer of the ISP with our export routemap.&lt;/P&gt;&lt;P&gt;Any suggestions? Maybe an error in the routemap? (Reference to actual config/ip's have been altered or contains placeholder)&lt;/P&gt;&lt;P&gt;R81.10&lt;/P&gt;&lt;P&gt;CheckPoint fw&amp;gt;&lt;/P&gt;&lt;P&gt;set bgp external remote-as &amp;lt;ISP AS&amp;gt; peer 2001:x:x:x::1 on&lt;BR /&gt;set bgp external remote-as &amp;lt;ISP AS&amp;gt; peer 2001:x:x:x::1 capability ipv6-unicast on&lt;BR /&gt;set bgp external remote-as &amp;lt;ISP AS&amp;gt; peer 2001:x:x:x::1 holdtime 90&lt;BR /&gt;set bgp external remote-as &amp;lt;ISP AS&amp;gt; peer 2001:x:x:x::1 keepalive 30&lt;BR /&gt;set bgp external remote-as &amp;lt;ISP AS&amp;gt; peer 2001:x:x:x::1 authtype md5 secret &amp;lt;md5 secret&amp;gt;&lt;BR /&gt;set bgp external remote-as &amp;lt;ISP AS&amp;gt; peer 2001:x:x:x::1 export-routemap "EXP-IPV6-routemap" preference 10 on&lt;BR /&gt;set bgp external remote-as &amp;lt;ISP AS&amp;gt; peer 2001:x:x:x::1 import-routemap "IMP-IPV6-routemap" preference 10 on&lt;/P&gt;&lt;P&gt;CheckPoint fw&amp;gt; &lt;STRONG&gt;show configuration routemap EXP-IPV6-routemap&lt;/STRONG&gt;&lt;BR /&gt;set routemap EXP-IPV6-routemap id 10 on&lt;BR /&gt;set routemap EXP-IPV6-routemap id 10 allow&lt;BR /&gt;set routemap EXP-IPV6-routemap id 10 match network 2a07:2240:17f8::/48 exact&lt;BR /&gt;set routemap EXP-IPV6-routemap id 10 match protocol direct&lt;/P&gt;&lt;P&gt;CheckPoint fw&amp;gt; &lt;STRONG&gt;show bgp peers established&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Flags: R - Peer restarted, W - Waiting for End-Of-RIB from Peer&lt;BR /&gt;PeerID AS Routes ActRts State InUpds OutUpds Uptime&lt;BR /&gt;2001:x:x:x::1 &amp;lt;ISP AS&amp;gt; 1 0 Established 2 0 2d9h&lt;/P&gt;&lt;P&gt;CheckPoint fw&amp;gt; &lt;STRONG&gt;show bgp peer 2001:x:x:x::1 received&lt;/STRONG&gt;&lt;BR /&gt;IPv6 Route MED LocalPref Nexthop Communities&lt;BR /&gt;::/0 None N/A(EBGP) 2001:x:x:x::1 (link-local: fe80::da24:bcff:fec7:a7c2)&lt;/P&gt;&lt;P&gt;CheckPoint fw&amp;gt; &lt;STRONG&gt;show bgp peer 2001:x:x:x::1 advertise&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;EMPTY&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;CheckPoint fw&amp;gt; &lt;STRONG&gt;show ipv6 route destination 2a07:2200:13f8::&lt;/STRONG&gt;&lt;BR /&gt;Codes: C - Connected, S - Static, B - BGP, Rg - RIPng, A - Aggregate,&lt;BR /&gt;O - OSPFv3 IntraArea (IA - InterArea, E - External),&lt;BR /&gt;K - Kernel Remnant, H - Hidden, P - Suppressed,&lt;BR /&gt;NP - NAT Pool, U - Unreachable, i - Inactive&lt;/P&gt;&lt;P&gt;C 2a07:2200:13f8::/48 is directly connected, bondx.xxx&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 05:09:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-advertising-IPv6-subnet-to-BGP-peer/m-p/159414#M27899</guid>
      <dc:creator>Arend</dc:creator>
      <dc:date>2022-10-13T05:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: Not advertising IPv6 subnet to BGP peer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-advertising-IPv6-subnet-to-BGP-peer/m-p/159424#M27903</link>
      <description>&lt;P&gt;hey,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;According to your export route-map you want to advertise the connected &lt;EM&gt;&lt;STRONG&gt;2a07:2240:17f8::/48&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;but you might need to set a route-redistribution for connected (still I've checked and there is no option for connected routes)....&lt;/P&gt;
&lt;P&gt;Did you tried to change the exact with refines or you need to specify the "&lt;CODE&gt;restrict off&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;- Allows the matched subnets to be exported or imported.&lt;/SPAN&gt;&lt;SPAN&gt;" also ????&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="50%"&gt;&lt;SPAN&gt;CheckPoint fw&amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;show configuration routemap EXP-IPV6-routemap&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;set routemap EXP-IPV6-routemap id 10 on&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;set routemap EXP-IPV6-routemap id 10 allow&lt;/SPAN&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;set routemap EXP-IPV6-routemap id 10 match network 2a07:2240:17f8::/48 exact&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;SPAN&gt;set routemap EXP-IPV6-routemap id 10 match protocol direct&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="50%"&gt;
&lt;P&gt;CheckPoint fw&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;show ipv6 route destination 2a07:2200:13f8::&lt;/STRONG&gt;&lt;BR /&gt;Codes: C - Connected, S - Static, B - BGP, Rg - RIPng, A - Aggregate,&lt;BR /&gt;O - OSPFv3 IntraArea (IA - InterArea, E - External),&lt;BR /&gt;K - Kernel Remnant, H - Hidden, P - Suppressed,&lt;BR /&gt;NP - NAT Pool, U - Unreachable, i - Inactive&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;C 2a07:2200:13f8::/48 is directly connected, bondx.xxx&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ex:&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;Axxx-FW02&amp;gt; set route-redistribution to bgp-as 65004 from&lt;BR /&gt;aggregate - Redistribute aggregate routes into BGP&lt;BR /&gt;bgp-as-number - Redistribute BGP routes from a given AS into BGP&lt;BR /&gt;bgp-as-path - Redistribute BGP routes matched by AS path into BGP&lt;BR /&gt;default-origin - Default rule for redistributing IPv4 routes into BGP&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;interface - Redistribute interface routes into BGP&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;kernel - Redistribute kernel routes into BGP&lt;BR /&gt;nat-pool - Redistribute NAT pools into BGP&lt;BR /&gt;ospf2 - Redistribute OSPF routes into BGP&lt;BR /&gt;ospf2ase - Redistribute external OSPF routes into BGP&lt;BR /&gt;rip - Redistribute RIP routes into BGP&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;static-route - Redistribute static routes into BGP&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;Axxx-FW02&amp;gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Like in my case, with IPv4 BGP we don't use routemaps but we used route-redistribution from static routes defined on the GW to be advertised on BGP :&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="50%"&gt;
&lt;P&gt;Axxx-FW02&amp;gt; show bgp peer 10.X.Y.10 advertise&lt;/P&gt;
&lt;P&gt;IPv4 Route MED LocalPref Nexthop Communities&lt;BR /&gt;10.230.211.0/24 None 100 10.X.Y.1&lt;BR /&gt;10.237.1.0/24 None 100 10.X.Y.1&lt;BR /&gt;192.168.130.0/23 None 100 10.X.Y.1&lt;/P&gt;
&lt;P&gt;Axxx-FW02&amp;gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="50%"&gt;Axxx-FW02&amp;gt; show configuration&lt;BR /&gt;.............&lt;BR /&gt;set route-redistribution to bgp-as 65004 from static-route 10.230.211.0/24 on&lt;BR /&gt;set route-redistribution to bgp-as 65004 from static-route 10.237.1.0/24 on&lt;BR /&gt;set route-redistribution to bgp-as 65004 from static-route 192.168.130.0/23 on&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;(those are static routes we have defined)&lt;/STRONG&gt;&lt;/EM&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ty,&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 08:46:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-advertising-IPv6-subnet-to-BGP-peer/m-p/159424#M27903</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-10-13T08:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Not advertising IPv6 subnet to BGP peer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-advertising-IPv6-subnet-to-BGP-peer/m-p/159435#M27906</link>
      <description>&lt;P&gt;Hi Sorin, Thank you for your response.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;solution:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;We just found out that "..... &lt;SPAN&gt;preference 10 &lt;STRONG&gt;family inet6 on&lt;/STRONG&gt;&lt;/SPAN&gt;" is necessary in the BGP config.&lt;/P&gt;&lt;P&gt;Gaia Advanced Routing R81.10 Administration Guide&lt;BR /&gt;Section: Routing Policy Configuration&amp;nbsp; -&amp;gt; sub section "Route Maps - Export and Import"&lt;/P&gt;&lt;P&gt;Syntax to set BGP routemaps for export and import policies&lt;/P&gt;&lt;P&gt;set bgp external remote-as &amp;lt;1-65535&amp;gt; export-routemap &amp;lt;Name of Route Map&amp;gt; preference &amp;lt;1-65535&amp;gt; &lt;STRONG&gt;family inet6 on&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Note: the actual subnets were altered and maybe dont match in the config above.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 10:34:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-advertising-IPv6-subnet-to-BGP-peer/m-p/159435#M27906</guid>
      <dc:creator>Arend</dc:creator>
      <dc:date>2022-10-13T10:34:13Z</dc:date>
    </item>
  </channel>
</rss>

