<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic OSPF on NSX in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192098#M35470</link>
    <description>&lt;P&gt;We have OSPF running successfully on a number of hardware clusters connected to hardware switches. We are trying to run OSPF now on a cluster of virtual gateways in a VMware environment running NSX-T. As soon as we add an OSPF interface on the cluster Routed on the standby gateway fails and ClusterXL marks the member as down.&lt;/P&gt;&lt;P&gt;Anybody else seen or fixed this?&lt;/P&gt;</description>
    <pubDate>Sat, 09 Sep 2023 07:41:16 GMT</pubDate>
    <dc:creator>Scott_Paisley</dc:creator>
    <dc:date>2023-09-09T07:41:16Z</dc:date>
    <item>
      <title>OSPF on NSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192098#M35470</link>
      <description>&lt;P&gt;We have OSPF running successfully on a number of hardware clusters connected to hardware switches. We are trying to run OSPF now on a cluster of virtual gateways in a VMware environment running NSX-T. As soon as we add an OSPF interface on the cluster Routed on the standby gateway fails and ClusterXL marks the member as down.&lt;/P&gt;&lt;P&gt;Anybody else seen or fixed this?&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2023 07:41:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192098#M35470</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2023-09-09T07:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF on NSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192101#M35471</link>
      <description>&lt;P&gt;Are you saying the issue doesn't resolve when the configuration is set consistently on both cluster members and with w&lt;SPAN&gt;hich Version/Jumbo?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2023 09:35:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192101#M35471</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-09-09T09:35:01Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF on NSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192104#M35472</link>
      <description>&lt;P&gt;R81.10 Jumbo 109&lt;/P&gt;&lt;P&gt;The gateways are in a cloning group so the configuration is consistemt across the gateways. Enabling OSPF on both gateways instantly disables ROUTED on the standby.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2023 11:52:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192104#M35472</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2023-09-09T11:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF on NSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192107#M35473</link>
      <description>&lt;P&gt;What does /var/log/messages and /var/log/routed* have to say when this occurs?&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2023 13:59:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192107#M35473</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-09T13:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF on NSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192108#M35474</link>
      <description>&lt;P&gt;messages&lt;/P&gt;&lt;P&gt;Sep 9 15:01:44 2023 EU-AZ-EDC-WAN-CKP-02 xpand[10207]: instance name is [default]&lt;BR /&gt;Sep 9 15:01:44 2023 EU-AZ-EDC-WAN-CKP-02 xpand[10207]: Configuration changed from localhost by user admin by the service rmbserver&lt;BR /&gt;Sep 9 15:01:44 2023 EU-AZ-EDC-WAN-CKP-02 xpand[10207]: finalize: routed conf file is [/etc/routed0.conf]&lt;BR /&gt;Sep 9 15:01:44 2023 EU-AZ-EDC-WAN-CKP-02 xpand[10207]: finalize: routed instance is [default]&lt;BR /&gt;Sep 9 15:01:44 2023 EU-AZ-EDC-WAN-CKP-02 xpand[10207]: moving /etc/cprd_syntax_test_default to /etc/routed0.conf&lt;BR /&gt;Sep 9 15:01:44 2023 EU-AZ-EDC-WAN-CKP-02 xpand[10207]: Using routed pid 15436 for 'default'&lt;BR /&gt;Sep 9 15:01:44 2023 EU-AZ-EDC-WAN-CKP-02 routed[13470]: [routed] NOTICE: task_reconfigure re-initializing from /etc/routed.conf&lt;BR /&gt;Sep 9 15:01:44 2023 EU-AZ-EDC-WAN-CKP-02 routed[13470]: [routed] NOTICE: parse_instance_only: my_instance_id -1 parsing instance default&lt;BR /&gt;Sep 9 15:01:44 2023 EU-AZ-EDC-WAN-CKP-02 routed[13470]: [routed] NOTICE: task_reconfigure reinitializing done&lt;BR /&gt;Sep 9 15:01:44 2023 EU-AZ-EDC-WAN-CKP-02 xpand[10207]: admin localhost t +routed:instance:default:ospf2:instance:default:area:0.0.0.0:interface:eth5 t&lt;BR /&gt;Sep 9 15:01:44 2023 EU-AZ-EDC-WAN-CKP-02 xpand[10207]: admin localhost t +routed:instance:default:ospf2:instance:default:interface:eth5:area 0.0.0.0&lt;BR /&gt;Sep 9 15:01:44 2023 EU-AZ-EDC-WAN-CKP-02 xpand[10207]: admin localhost t +routed:instance:default:ospf2:instance:default:area:0.0.0.0:interface:eth5:priority 1&lt;BR /&gt;Sep 9 15:01:44 2023 EU-AZ-EDC-WAN-CKP-02 xpand[10207]: admin localhost t +routed:instance:default:ospf2:instance:default:area:0.0.0.0:interface:eth5:auth:null t&lt;BR /&gt;Sep 9 15:01:44 2023 EU-AZ-EDC-WAN-CKP-02 xpand[10207]: admin localhost t +routed:instance:default:ospf2:instance:default:area:0.0.0.0:interface:eth5:authtype null&lt;BR /&gt;Sep 9 15:01:44 2023 EU-AZ-EDC-WAN-CKP-02 fwk: CLUS-211700-1: Remote member 2 (state STANDBY -&amp;gt; DOWN) | Reason: ROUTED PNOTE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;routed_messages&lt;/P&gt;&lt;P&gt;Sep 9 15:01:45.956161 [routed] ERROR: OSPF2 instance default OspfInterfaceUp(4656): not starting protocol on interface 172.25.48.35(eth5)&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2023 14:05:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192108#M35474</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2023-09-09T14:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF on NSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192109#M35475</link>
      <description>&lt;P&gt;Is IPV6/RD enabled on this cluster (sk102369)?&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2023 15:09:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192109#M35475</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-09-09T15:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF on NSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192111#M35476</link>
      <description>&lt;P&gt;IPv6 is not enabled&lt;/P&gt;&lt;P&gt;Router Discovery is not enabled&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2023 15:53:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192111#M35476</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2023-09-09T15:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF on NSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192113#M35477</link>
      <description>&lt;P&gt;If I were you, I would call TAC and see if you can do remote session, or at least provide further files/debugs for investigation. I had never seen issue like this myself before, either with OSPF or BGP.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2023 18:08:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192113#M35477</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-09T18:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF on NSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192235#M35515</link>
      <description>&lt;P&gt;We got it working. Details here for reference.&lt;/P&gt;&lt;P&gt;To recap, 3 clusters running in an ESX environment using NSX-T for the networking.&lt;/P&gt;&lt;P&gt;Each cluster configured as a separate cloning group so the configurations match.&lt;/P&gt;&lt;P&gt;On 2 of the 3 clusters, when we enable OSPF on a single interface, the standby cluster member fails with a ROUTED PNOTE.&lt;/P&gt;&lt;P&gt;The 'fix' was to break the cloning groups, reboot each member, reconfigure OSPF on each individual box, then enable the cloning group again. Now all 3 clusters are happy, although somehow the OSPF interface moved on one of the clusters&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 14:31:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPF-on-NSX/m-p/192235#M35515</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2023-09-11T14:31:22Z</dc:date>
    </item>
  </channel>
</rss>

