<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BGP Graceful Restart in HA cluster in Azure in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/252710#M49480</link>
    <description>&lt;P&gt;The test you mention, was it also of a cluster?&lt;BR /&gt;&lt;BR /&gt;According to the following sk &lt;A href="https://support.checkpoint.com/results/sk/sk100499" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk100499&lt;/A&gt;&lt;BR /&gt;I would just need to check the Graceful Restart box.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jennyado_0-1751913786110.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30905i1030E3E5E0535206/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jennyado_0-1751913786110.png" alt="jennyado_0-1751913786110.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Jul 2025 18:43:28 GMT</pubDate>
    <dc:creator>jennyado</dc:creator>
    <dc:date>2025-07-07T18:43:28Z</dc:date>
    <item>
      <title>BGP Graceful Restart in HA cluster in Azure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/252704#M49478</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I currently have an &lt;STRONG&gt;Azure-deployed Check Point ClusterXL HA environment (Active/Standby)&lt;/STRONG&gt; and I’m considering enabling &lt;STRONG&gt;BGP Graceful Restart&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;The current topology looks like this:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Two Check Point gateways in a ClusterXL HA setup.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Each gateway establishes a &lt;STRONG&gt;VPN tunnel (VTI)&lt;/STRONG&gt; to an &lt;STRONG&gt;Azure Virtual Network Gateway&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Both firewalls are peering via BGP to a private Azure IP (&lt;STRONG&gt;&amp;lt;BGP Peer IP&amp;gt;&lt;/STRONG&gt;), which belongs to the &lt;STRONG&gt;Azure Virtual Network Gateway&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The &lt;STRONG&gt;Virtual Network Gateway&lt;/STRONG&gt; in turn peers with &lt;STRONG&gt;on-prem Cisco routers&lt;/STRONG&gt; through another connection.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Everything is working fine as-is.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My question is:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":right_arrow:"&gt;➡️&lt;/span&gt; If I enable &lt;STRONG&gt;BGP Graceful Restart&lt;/STRONG&gt; on member A (which is currently active), is there any risk that this could trigger a failover in the cluster before applying the same setting to member B?&lt;/P&gt;&lt;P&gt;I’m concerned whether this change could:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Reset the BGP session on the active member.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Potentially cause ClusterXL to detect a failover condition (due to lost routes or VTI reachability loss).&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Has anyone here performed this adjustment in a similar Azure setup with Cisco routers behind the Virtual Network Gateway?&lt;BR /&gt;Would you recommend applying this live, or is it better done during a maintenance window?&lt;/P&gt;&lt;P&gt;Appreciate any advice or shared experience.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 18:21:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/252704#M49478</guid>
      <dc:creator>jennyado</dc:creator>
      <dc:date>2025-07-07T18:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Graceful Restart in HA cluster in Azure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/252706#M49479</link>
      <description>&lt;P&gt;I tested this in Azure lab last year and was fine, enabling it did not cause any issues, it actually helped. I have a gut feeling that setting is always needed for BGP to fully function without any network outage.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 18:33:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/252706#M49479</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-07T18:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Graceful Restart in HA cluster in Azure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/252710#M49480</link>
      <description>&lt;P&gt;The test you mention, was it also of a cluster?&lt;BR /&gt;&lt;BR /&gt;According to the following sk &lt;A href="https://support.checkpoint.com/results/sk/sk100499" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk100499&lt;/A&gt;&lt;BR /&gt;I would just need to check the Graceful Restart box.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jennyado_0-1751913786110.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30905i1030E3E5E0535206/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jennyado_0-1751913786110.png" alt="jennyado_0-1751913786110.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 18:43:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/252710#M49480</guid>
      <dc:creator>jennyado</dc:creator>
      <dc:date>2025-07-07T18:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Graceful Restart in HA cluster in Azure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/252711#M49481</link>
      <description>&lt;P&gt;Yes and yes &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 18:46:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/252711#M49481</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-07T18:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Graceful Restart in HA cluster in Azure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/261940#M51352</link>
      <description>&lt;P&gt;I have a follow-up question regarding this setting.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Would enabling it only on the Check Point cluster side cause any impact on BGP behavior?&lt;/P&gt;&lt;P&gt;I’m asking because I’m not entirely sure if this option can also be enabled on the Azure VPN Gateway side.&lt;/P&gt;&lt;P&gt;If it cannot be enabled on Azure, would it still be safe to activate it just on the cluster side?&lt;/P&gt;&lt;P&gt;And if it can be enabled on both sides, should it be configured simultaneously to avoid any route synchronization or session issues?&lt;/P&gt;&lt;P&gt;Appreciate any insights you can share on this — I just want to make sure we don’t introduce any BGP instability.&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 02:23:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/261940#M51352</guid>
      <dc:creator>jennyado</dc:creator>
      <dc:date>2025-11-06T02:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Graceful Restart in HA cluster in Azure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/261942#M51353</link>
      <description>&lt;P&gt;I dont have Azure cluster in the lab any more (was costing too much money to keep it on constantly), but to answer your question, when I did have it, I had VPN between on prem cluster and Azure one and my colleague and I also built BGP peering and that setting was enabled on both sides, no issues.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 02:33:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/261942#M51353</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-06T02:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Graceful Restart in HA cluster in Azure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/262085#M51413</link>
      <description>&lt;P&gt;Hey Jenn,&lt;/P&gt;
&lt;P&gt;Just ended up building Azure cluster today to test this (was curious if its same behavior in R82) and was fine, no problems.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 22:49:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/262085#M51413</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-06T22:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Graceful Restart in HA cluster in Azure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/262095#M51416</link>
      <description>&lt;P&gt;Be mindful of the drawbacks of GR for BGP:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://blog.ipspace.net/2024/01/bgp-graceful-restart-harmful/" target="_blank"&gt;https://blog.ipspace.net/2024/01/bgp-graceful-restart-harmful/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You could be doing more harm than good unless you have other ways to detect a potential outage such as ip-reachability-detection with either BFD (single-hop or multi-hop) or ICMP echo; both of which Gaia's BGP supports. &amp;nbsp;If you use BFD, be sure you enable the control plane check as well (the C-bit) so that you aren't fate-sharing BFD and BGP blindly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2025 01:20:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Graceful-Restart-in-HA-cluster-in-Azure/m-p/262095#M51416</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-11-07T01:20:23Z</dc:date>
    </item>
  </channel>
</rss>

