<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ClusterXL standby member does not install OSPF routes in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-standby-member-does-not-install-OSPF-routes/m-p/102540#M8059</link>
    <description>&lt;P&gt;FYI&amp;nbsp; - I don't remember if this is the case, but I think it will not let you change the router-id without first removing the OSPF config. PITA I know.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Nov 2020 17:39:40 GMT</pubDate>
    <dc:creator>John_Fleming</dc:creator>
    <dc:date>2020-11-18T17:39:40Z</dc:date>
    <item>
      <title>ClusterXL standby member does not install OSPF routes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-standby-member-does-not-install-OSPF-routes/m-p/102511#M8053</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We're running four R80.30 Security Gateways (hotfix take 219) with two of them being in HA ClusterXL mode. Topology is fairly simple:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="topo.JPG" style="width: 681px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9096i83D7AE08FAFF962B/image-size/large?v=v2&amp;amp;px=999" role="button" title="topo.JPG" alt="topo.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;FW1 and FW2 have OSPF adjacencies formed between each other and cluster VIP (10.20.100.63), everything works correctly there. Cluster members, both show OSPF adjacencies formed with FW1/FW2 and both have OSPF databases populated, but only the active member installs routes in the routing table. The problem occurs when failover happens. After standby member becomes active, the routes are still not being installed and effectively all the traffic stops. This persists until I manually restart &lt;STRONG&gt;routed&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;When first member comes back online and stays as standby (we do not have preempting configured), it exhibits the same behavior. Adjacencies are formed, OSPF database is populated but routes are not installed.&lt;/P&gt;&lt;P&gt;Is there anything I'm missing in configuration?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 15:06:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-standby-member-does-not-install-OSPF-routes/m-p/102511#M8053</guid>
      <dc:creator>Flanger</dc:creator>
      <dc:date>2020-11-18T15:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL standby member does not install OSPF routes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-standby-member-does-not-install-OSPF-routes/m-p/102533#M8054</link>
      <description>&lt;P&gt;Do both members have the same router-id? Is the cluster health before the failover? Do the routes show up as hidden by chance? (show route all)&lt;/P&gt;&lt;P&gt;from clish enable ospf tracing and look in /var/log/routed.log&lt;/P&gt;&lt;P&gt;set trace ospf all all on&lt;/P&gt;&lt;P&gt;set trace global all all on&lt;/P&gt;&lt;P&gt;set trace kernel all all on&lt;/P&gt;&lt;P&gt;Something like that.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 17:05:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-standby-member-does-not-install-OSPF-routes/m-p/102533#M8054</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-11-18T17:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL standby member does not install OSPF routes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-standby-member-does-not-install-OSPF-routes/m-p/102537#M8056</link>
      <description>&lt;P&gt;Members have unique OSPF router IDs and routes do not show as hidden either. They are just absent, only present in OSPF database. There is no other problem with the cluster, I did manual failover to test it using &lt;STRONG&gt;clusterxl admin down/up&lt;/STRONG&gt; on active member first and then tried again by reloading active member, I thought it's expected behavior and routes will install once standby becomes active. That didn't happen. Interestingly after I reloaded &lt;STRONG&gt;routed&lt;/STRONG&gt;, traffic started flowing but routes would still not show up for another minute or so.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 17:34:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-standby-member-does-not-install-OSPF-routes/m-p/102537#M8056</guid>
      <dc:creator>Flanger</dc:creator>
      <dc:date>2020-11-18T17:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL standby member does not install OSPF routes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-standby-member-does-not-install-OSPF-routes/m-p/102538#M8057</link>
      <description>&lt;P&gt;The members should have the same router-id. That might be the problem.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 17:35:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-standby-member-does-not-install-OSPF-routes/m-p/102538#M8057</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-11-18T17:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL standby member does not install OSPF routes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-standby-member-does-not-install-OSPF-routes/m-p/102539#M8058</link>
      <description>&lt;P&gt;Thanks for the tip. I will make changes within next downtime window and reply with the results.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 17:37:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-standby-member-does-not-install-OSPF-routes/m-p/102539#M8058</guid>
      <dc:creator>Flanger</dc:creator>
      <dc:date>2020-11-18T17:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL standby member does not install OSPF routes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-standby-member-does-not-install-OSPF-routes/m-p/102540#M8059</link>
      <description>&lt;P&gt;FYI&amp;nbsp; - I don't remember if this is the case, but I think it will not let you change the router-id without first removing the OSPF config. PITA I know.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 17:39:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-standby-member-does-not-install-OSPF-routes/m-p/102540#M8059</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-11-18T17:39:40Z</dc:date>
    </item>
  </channel>
</rss>

