<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BGP peering with ClusterXL across 2 sites - use a VIP in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/BGP-peering-with-ClusterXL-across-2-sites-use-a-VIP/m-p/77979#M15883</link>
    <description>&lt;P&gt;Rccou,&lt;/P&gt;
&lt;P&gt;what you describe is normal behaviour with ClusterXL HA.&lt;/P&gt;
&lt;P&gt;One node is active with the VIP and the other node is in standby.&lt;/P&gt;
&lt;P&gt;If active is failing, then standby becomes active and the VIP will be active there.&lt;/P&gt;
&lt;P&gt;Maybee you have a design problem for your needs and you are running better not using ClusterXL.&lt;/P&gt;
&lt;P&gt;As an example&amp;nbsp;one gateway as single instance in every location,&amp;nbsp;both are active. And with dynamic routing internal and external (BGP, OSPF, BFD) you can build your redundancy.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
    <pubDate>Wed, 11 Mar 2020 14:26:25 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2020-03-11T14:26:25Z</dc:date>
    <item>
      <title>BGP peering with ClusterXL across 2 sites - use a VIP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-peering-with-ClusterXL-across-2-sites-use-a-VIP/m-p/77954#M15878</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have 2 sites connected by a 10Gb circuit.&amp;nbsp; We have a pair of Firewalls running R80.30 set as Active/Standby using ClusterXL.&lt;/P&gt;&lt;P&gt;We have an&amp;nbsp; eBGP peering to a remote entity which uses the Cluster VIP on our side.&lt;/P&gt;&lt;P&gt;The problem, as noted yesterday during a downtime window for one of the sites, is that if we take a site down for maintenance the FWs stop talking to each other so they switch the Standby FW to Active and it takes over the VIP.&amp;nbsp; However this site was the one we had taken down therefore the whole company lost connection to the remote entity.&lt;/P&gt;&lt;P&gt;I read that it is best practice to use the VIP for ClusterXL and BGP but is that only really the case when both FWs are in the same rack?&lt;/P&gt;&lt;P&gt;If they are in different sites would it make more sense to have 2&amp;nbsp; eBGP peerings and an iBGP peering between them?&lt;/P&gt;&lt;P&gt;Is there going to be any problem with setting this up, due to them being essentially the same cluster?&lt;/P&gt;&lt;P&gt;Will this work?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 10:22:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-peering-with-ClusterXL-across-2-sites-use-a-VIP/m-p/77954#M15878</guid>
      <dc:creator>Rccou</dc:creator>
      <dc:date>2020-03-11T10:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: BGP peering with ClusterXL across 2 sites - use a VIP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-peering-with-ClusterXL-across-2-sites-use-a-VIP/m-p/77966#M15879</link>
      <description>&lt;P&gt;Could you please tell us more about your BGP configuration and process used to take a site offline?&lt;/P&gt;
&lt;P&gt;Are you using graceful restart and is there only a single non-redundant path between the sites...&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 13:22:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-peering-with-ClusterXL-across-2-sites-use-a-VIP/m-p/77966#M15879</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-03-11T13:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: BGP peering with ClusterXL across 2 sites - use a VIP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-peering-with-ClusterXL-across-2-sites-use-a-VIP/m-p/77975#M15882</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;Taking the site offline was done by powering down the switches that connects the FW to the peer router.&amp;nbsp; It's a fibre across a DC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This would have also taken down the site to site cluster communications so it would trigger the cluster switchover. Here's another question: Would the VIP move from the old Active (would this go to Standby?) to the new Active or would they both keep the VIP independently?&lt;/P&gt;&lt;P&gt;The BGP peering is with a Juniper MX. It's completely basic eBGP.&amp;nbsp; Each FW has a peering to a different MX router, both coming from the same VIP. No iBGP between them.&lt;/P&gt;&lt;P&gt;(if it's done wrong or suboptimally then feel free to say - I inherited it)&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 14:17:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-peering-with-ClusterXL-across-2-sites-use-a-VIP/m-p/77975#M15882</guid>
      <dc:creator>Rccou</dc:creator>
      <dc:date>2020-03-11T14:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: BGP peering with ClusterXL across 2 sites - use a VIP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-peering-with-ClusterXL-across-2-sites-use-a-VIP/m-p/77979#M15883</link>
      <description>&lt;P&gt;Rccou,&lt;/P&gt;
&lt;P&gt;what you describe is normal behaviour with ClusterXL HA.&lt;/P&gt;
&lt;P&gt;One node is active with the VIP and the other node is in standby.&lt;/P&gt;
&lt;P&gt;If active is failing, then standby becomes active and the VIP will be active there.&lt;/P&gt;
&lt;P&gt;Maybee you have a design problem for your needs and you are running better not using ClusterXL.&lt;/P&gt;
&lt;P&gt;As an example&amp;nbsp;one gateway as single instance in every location,&amp;nbsp;both are active. And with dynamic routing internal and external (BGP, OSPF, BFD) you can build your redundancy.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 14:26:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-peering-with-ClusterXL-across-2-sites-use-a-VIP/m-p/77979#M15883</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-03-11T14:26:25Z</dc:date>
    </item>
  </channel>
</rss>

