<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OSPFv3 changes state during failover (ClusterXL) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPFv3-changes-state-during-failover-ClusterXL/m-p/103476#M8163</link>
    <description>&lt;P&gt;Hi Jack&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"I know GR aren't applicable when using ClusterXL, but that's the default setting and same behavior when turning it off."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;As mentioned above, I tried both with same result (GR = Graceful Restart).&lt;BR /&gt;But since the OSPFv3 process actually should be clustered GR doesn't make much sense (if this has feature parity compared to how OSPFv2 behaves in ClusterXL). I actually only think GR is supported when using VRRP. In ClusterXL the routing table/state is synced (I assume).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Nov 2020 17:18:39 GMT</pubDate>
    <dc:creator>mgades</dc:creator>
    <dc:date>2020-11-26T17:18:39Z</dc:date>
    <item>
      <title>OSPFv3 changes state during failover (ClusterXL)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPFv3-changes-state-during-failover-ClusterXL/m-p/102981#M8111</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I'm about to roll out IPv6 in our enterprise network, and are testing various scenarios in lab before rolling out in production. Something is puzzling me and telling me this is not right...&lt;/P&gt;&lt;P&gt;We're running 2 x 5800 in HA (active/passive). For IPv4 we are running OSPFv2 to announce a default route, and a few connected routes, and this works like a charm - not a single hickup/ping loss when failing over between the two nodes. Also on other OSPF neighbors there are no state change, as the process is clustered.&lt;/P&gt;&lt;P&gt;But when I try to mimic the same setup for IPv6 (using the OSPFv3 protocol), the OSPF session changes to INIT (as seen on a neighboring device), which leads to downtime until it converges and changes to FULL.&lt;/P&gt;&lt;P&gt;I have both a IPv4 and IPv6 ping running towards two distant hosts. When flipping over the nodes (using clusterXL_admin down on the active node), there are no ping timeouts on the IPv4 ping, but IPv6 fails immediately, and comes back when OSPFv3 reconverges (after about 16 ping timeouts - at least 15 pings too much &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;).&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;lt;CR_LAB&amp;gt;%Nov 23 10:53:53:483 2020 CR_LAB OSPFV3/5/OSPFv3_NBR_CHG: OSPFv3 1 Neighbor 172.20.10.10(Vlan-interface10) received 1-Way and its state from &lt;STRONG&gt;FULL to INIT&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;lt;CR_LAB&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;lt;CR_LAB&amp;gt;%Nov 23 10:54:06:456 2020 CR_LAB OSPFV3/5/OSPFv3_NBR_CHG: OSPFv3 1 Neighbor 172.20.10.10(Vlan-interface10) received LoadingDone and its state from &lt;STRONG&gt;LOADING to FULL&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;CR_LAB is a core router (HPE Comware) - router-id 172.20.127.11&lt;BR /&gt;FW-A and FW-B are Checkpoint R80.40 JHF Take_87 nodes.&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;lt;CR_LAB&amp;gt;disp ospfv3 peer 172.20.10.10&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT face="courier new,courier"&gt;OSPFv3 Process 1 with Router ID 172.20.127.11&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Area 0.0.0.0 interface Vlan-interface10's neighbors&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Router ID: 172.20.10.10 Address: &lt;STRONG&gt;FE80::131:10&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;State: Full Mode: Nbr is slave Priority: 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;DR: 172.20.127.11 BDR: 172.20.127.81 MTU: 1500&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Options is 0x000013 (-|R|-|x|E|V6)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Dead timer due in 00:00:37&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Neighbor is up for 03:38:55&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Neighbor state change count: 16&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Database Summary List 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Link State Request List 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Link State Retransmission List 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Neighbor interface ID: 168461066&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;GR state: Normal&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Grace period: 0 Grace period timer: Off&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;DD Rxmt Timer: Off LS Rxmt Timer: Off&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;The Checkpoint cluster is using the same router-id. And I can confirm the link-local IP is identical on the CluterXL interface.&lt;/P&gt;&lt;P&gt;These are the relevant OSPFv3 configuration lines:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;set ipv6 ospf3 instance default rfc1583-compatibility off&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;set ipv6 ospf3 instance default graceful-restart-helper on&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;set ipv6 ospf3 instance default area backbone on&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;set ipv6 ospf3 instance default interface eth1 area backbone on&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;set ipv6 ospf3 instance default interface eth1 cost 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;set ipv6 ospf3 instance default interface eth1 priority 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;set ipv6 ospf3 instance default export-routemap export_ipv6 preference 1 on&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;set routemap export_ipv6 id 100 on&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;set routemap export_ipv6 id 100 allow&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;set routemap export_ipv6 id 100 match network ::/0 exact&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;set routemap export_ipv6 id 100 match protocol static&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I know GR aren't applicable when using ClusterXL, but that's the default setting and same behavior when turning it off.&lt;/P&gt;&lt;P&gt;Does anyone have a clue what I've done wrong? Is the clustered OSPFv3 process using ClusterXL really supposed to change the neighbor state during failover?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Morten Gade Sørensen&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 06:52:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPFv3-changes-state-during-failover-ClusterXL/m-p/102981#M8111</guid>
      <dc:creator>mgades</dc:creator>
      <dc:date>2020-11-24T06:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: OSPFv3 changes state during failover (ClusterXL)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPFv3-changes-state-during-failover-ClusterXL/m-p/103446#M8158</link>
      <description>&lt;P&gt;Anyone running OSPFv3 in a HA cluster??&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 14:18:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPFv3-changes-state-during-failover-ClusterXL/m-p/103446#M8158</guid>
      <dc:creator>mgades</dc:creator>
      <dc:date>2020-11-26T14:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: OSPFv3 changes state during failover (ClusterXL)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPFv3-changes-state-during-failover-ClusterXL/m-p/103470#M8161</link>
      <description>&lt;P&gt;Do you have graceful restart enabled?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 16:09:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPFv3-changes-state-during-failover-ClusterXL/m-p/103470#M8161</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2020-11-26T16:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: OSPFv3 changes state during failover (ClusterXL)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPFv3-changes-state-during-failover-ClusterXL/m-p/103476#M8163</link>
      <description>&lt;P&gt;Hi Jack&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"I know GR aren't applicable when using ClusterXL, but that's the default setting and same behavior when turning it off."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;As mentioned above, I tried both with same result (GR = Graceful Restart).&lt;BR /&gt;But since the OSPFv3 process actually should be clustered GR doesn't make much sense (if this has feature parity compared to how OSPFv2 behaves in ClusterXL). I actually only think GR is supported when using VRRP. In ClusterXL the routing table/state is synced (I assume).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 17:18:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPFv3-changes-state-during-failover-ClusterXL/m-p/103476#M8163</guid>
      <dc:creator>mgades</dc:creator>
      <dc:date>2020-11-26T17:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: OSPFv3 changes state during failover (ClusterXL)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPFv3-changes-state-during-failover-ClusterXL/m-p/103490#M8164</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/51303"&gt;@mgades&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is applicable and required for v3.&amp;nbsp;&lt;/P&gt;&lt;P&gt;See below extract from the OSPF &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk95968" target="_self"&gt;SK.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In cluster environment, in OSPFv2 all cluster members must have the same OSPF Router ID value. During a failover, one of the Standby members (Backup) becomes the new Active member (Master) and then continues where the former Active member (Master) failed. As a result, there should be no traffic outage and no need for OSPFv2 graceful restart. &lt;STRONG&gt;&lt;EM&gt;The above-mentioned sync of OSPF database does not happen in OSPFv3 therefore Graceful Restart is needed and supported for OSPFv3 with ClusterXL.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 19:39:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPFv3-changes-state-during-failover-ClusterXL/m-p/103490#M8164</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2020-11-26T19:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: OSPFv3 changes state during failover (ClusterXL)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPFv3-changes-state-during-failover-ClusterXL/m-p/103814#M8187</link>
      <description>&lt;P&gt;EUREKA!! You're right!&lt;/P&gt;&lt;P&gt;I was blinded by the comment in this post was under the impression that GR isn't supported in OSPFv3, but that was actually only in OSPFv2 with ClusterXL:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/Dynamic-Routing-Real-World-Experience/m-p/75483/highlight/true#M5850" target="_blank"&gt;https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/Dynamic-Routing-Real-World-Experience/m-p/75483/highlight/true#M5850&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;When enabling Graceful Restart for OSPFv3 on both the Checkpoint devices and other OSPFv3 neighbors (in this case our core routers), the failover is instant and no(ish) lost IPv6 packets. From the logs on the HPE Comware device the OSPFv3 neighbor is going to EXSTART back to FULL within the same second:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;%Nov 30 14:45:&lt;STRONG&gt;41:166&lt;/STRONG&gt; 2020 xxx-CR OSPFV3/5/OSPFv3_NBR_CHG: OSPFv3 1 Neighbor 172.20.10.10(Vlan-interface10) received SeqNumberMismatch and its state from &lt;STRONG&gt;FULL to EXSTART&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;%Nov 30 14:45:&lt;STRONG&gt;41:211&lt;/STRONG&gt; 2020 xxx-CR OSPFV3/5/OSPFv3_NBR_CHG: OSPFv3 1 Neighbor 172.20.10.10(Vlan-interface10) received LoadingDone and its state from &lt;STRONG&gt;LOADING to FULL&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Thanks again &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Morten&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 07:54:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPFv3-changes-state-during-failover-ClusterXL/m-p/103814#M8187</guid>
      <dc:creator>mgades</dc:creator>
      <dc:date>2020-12-01T07:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: OSPFv3 changes state during failover (ClusterXL)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPFv3-changes-state-during-failover-ClusterXL/m-p/103833#M8188</link>
      <description>&lt;P&gt;Anytime! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a good week!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 09:22:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/OSPFv3-changes-state-during-failover-ClusterXL/m-p/103833#M8188</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2020-12-01T09:22:27Z</dc:date>
    </item>
  </channel>
</rss>

