<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuring dynamic routing in clustered VSX in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/135690#M24271</link>
    <description>&lt;P&gt;Virtual routers are supported in VSLS deployments as of R81, but I still wouldn't suggest that one should be deployed between every VS and the rest of the network where dynamic routing is required, standard VSs are perfectly capable of performing reasonable dynamic routing duties while firewalling. If you were in a situation with a lot of changes happening in the routing table or peers appearing and disappearing then that might be a different story.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Dec 2021 04:56:53 GMT</pubDate>
    <dc:creator>emmap</dc:creator>
    <dc:date>2021-12-07T04:56:53Z</dc:date>
    <item>
      <title>Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36787#M7731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have run in to the situation where dynamic routing should be implemented on virtual systems in a clustered VSX environment. Can someone tell me if it should be done only on VS' on active cluster member and it will be automatically replicated, or should it be setup on each instance of VS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 13:36:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36787#M7731</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-03-21T13:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36788#M7732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh dear... Last time I heard about VSX +DR was total disaster. I think customer ditched CP in favour of Juniper at the end. But that was a while ago, think it was R67 VSX &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 14:23:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36788#M7732</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-03-21T14:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36789#M7733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, they have it running now and it's been stable for years. Nothing too complicated: OSPF stub zones and passive interfaces facing hosts.&lt;/P&gt;&lt;P&gt;I am looking at making alterations to their environment and am looking at moving some of their stuff to a bridge-mode VS', but there are still some systems that need to receive the routes from the rest of the infrastructure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately, unless I am not looking in the right places, there is nothing in documentation specifically applicable to clustered systems and dynamic routing. Just references to the Advanced Routing documentation that describing the methods from a single system perspective only.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 14:34:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36789#M7733</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-03-21T14:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36790#M7734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We were running OSPF on one of our production 61K in VSX with no high availability. However we need to configure DR separately on each cluster member. Have a look at here&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_VSX_AdminGuide/html_frameset.htm?topic=documents/R80.10/WebAdminGuides/EN/CP_R80.10_VSX_AdminGuide/150222" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_VSX_AdminGuide/html_frameset.htm?topic=documents/R80.10/WebAdminGuides/EN/CP_R80.10_VSX_AdminGuide/150222"&gt;Check Point VSX R80.10 (for future PDF publishing) Administration Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 18:51:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36790#M7734</guid>
      <dc:creator>Ni_c</dc:creator>
      <dc:date>2018-03-21T18:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36791#M7735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;May be it's just improper wording, but it says:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;"You can also configure dynamic routing separately on each cluster member."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;This can be interpreted as not being mandatory.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;It can also refer to the dynamic routing on VS0 only.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;I am trying to determine if I must configure dynamic routing on all instances of Virtual Systems located on all cluster members, or doing it on a single one running on Active cluster member is sufficient.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 19:05:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36791#M7735</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-03-21T19:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36792#M7736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vladimir,&lt;/P&gt;&lt;P&gt;I have implemented with success OSPFv2 on 23600 VSX Cluster ; no issue.&lt;/P&gt;&lt;P&gt;Each instance has been configured (duplicate configuration on each VSX Gateway for the same VS id) ; start with the Secondary node and then the Primary in order to avoid cluster issues. Cloning group should help about synchronization of needed configuration but I do not use it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just : take care regarding OSPF Point-to-Point network (sk116500‌).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 21:29:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36792#M7736</guid>
      <dc:creator>XavierBens</dc:creator>
      <dc:date>2018-03-22T21:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36793#M7737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vladimir Yakovlev &lt;/P&gt;&lt;P&gt;973.558.2738&lt;/P&gt;&lt;P&gt;vlad@eversecgroup.com&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 22:21:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36793#M7737</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-03-22T22:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36794#M7738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Xavier,&lt;/P&gt;&lt;P&gt;can you elaborate: did you have OSPF on VSX(s) or VSs running on VSX?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 04:22:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36794#M7738</guid>
      <dc:creator>Alex_Rozhko</dc:creator>
      <dc:date>2018-03-29T04:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36795#M7739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We do not use context 0 as a 'firewall' but only all others context (VSid = 1, 2, ...) so we use OSPF on all our VS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be more descriptive:&lt;/P&gt;&lt;P&gt;In the following case:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;there is one dedicated bond for each VS (bond.1 for VS id 1, bond.2 for VS id 2, ...)&lt;/LI&gt;&lt;LI&gt;there is one vlan (example : id 1001) to communicate with core switch ; such interface will be the External&lt;/LI&gt;&lt;LI&gt;the area backbone range is 192.168.0.0/16&lt;/LI&gt;&lt;LI&gt;off course if you have a cluster : same configuration should be applied on both nodes members&lt;/LI&gt;&lt;LI&gt;the cost and priority is set on this example to 100 and 200&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have the following configuration applied at the creation process of any VS:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;VSXHost:1&amp;gt; show configuration ospf&lt;/P&gt;&lt;P&gt;show instance 1 configuration ospf&lt;/P&gt;&lt;P&gt;set ospf area backbone on&lt;/P&gt;&lt;P&gt;set ospf interface bond1.1001 area backbone on&lt;/P&gt;&lt;P&gt;set ospf interface bond1.1001 hello-interval 1&lt;/P&gt;&lt;P&gt;set ospf interface bond1.1001 dead-interval 3&lt;/P&gt;&lt;P&gt;set ospf interface bond1.1001 cost 100&lt;/P&gt;&lt;P&gt;set ospf interface bond1.1001 priority 200&lt;/P&gt;&lt;P&gt;set ospf interface bond1.1001 authtype md5 key 2 secret ****&lt;/P&gt;&lt;P&gt;set ospf area backbone range 192.168.0.0/16 on&lt;/P&gt;&lt;P&gt;set virtual-system 2&lt;BR /&gt;Context is set to vsid 2&lt;/P&gt;&lt;P&gt;VSXHost:2&amp;gt; show configuration ospf&lt;/P&gt;&lt;P&gt;show instance 2 configuration ospf&lt;/P&gt;&lt;P&gt;set ospf area backbone on&lt;/P&gt;&lt;P&gt;set ospf interface bond1.1002 area backbone on&lt;/P&gt;&lt;P&gt;set ospf interface bond1.1002 hello-interval 1&lt;/P&gt;&lt;P&gt;set ospf interface bond1.1002 dead-interval 3&lt;/P&gt;&lt;P&gt;set ospf interface bond1.1002 cost 100&lt;/P&gt;&lt;P&gt;set ospf interface bond1.1002 priority 200&lt;/P&gt;&lt;P&gt;set ospf interface bond1.1002 authtype md5 key 2 secret ****&lt;/P&gt;&lt;P&gt;set ospf area backbone range 192.168.0.0/16 on&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;And then, any time you create an interface, you add on the VSXHost the following line (here : for a vlan 12 on the VS id 2):&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;set ospf interface bond2.12 area backbone on&lt;BR /&gt;set ospf interface bond2.12 priority 1&lt;BR /&gt;set ospf interface bond2.12 passive on&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 15:23:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/36795#M7739</guid>
      <dc:creator>XavierBens</dc:creator>
      <dc:date>2018-03-29T15:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/135533#M24244</link>
      <description>&lt;P&gt;What is the recommended approach to configure OSPF and BGP on checkpoint vsx (redistribute into BGP)?&amp;nbsp; Why would you not want to use a virtual router in favour of configuring the DR directly on the VS?&lt;/P&gt;
&lt;P&gt;I assume a firewall rule would also be required to ensure the VS is allowed to establish adjacency with neighbours as well.&lt;/P&gt;
&lt;P&gt;Additionally I assume that none of the DR configurations are actually stored in the management database, so if we had to rebuild the VSX gateway, its important that these configuration as captured per VS and put back on after (Assuming no virtual router is used).&lt;/P&gt;</description>
      <pubDate>Sun, 05 Dec 2021 21:41:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/135533#M24244</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-12-05T21:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/135683#M24268</link>
      <description>&lt;P&gt;Unti recently, virtual routers were not supported on a VSLS deployment, so for many it was not an option to use them. It would still be an unnecessary layer 3 hop to add to many networks in order to deploy dynamic routing, so generally would be avoided.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, firewall rules are required for dynamic routing, depending on protocol.&amp;nbsp;&lt;SPAN&gt;sk39960 has details here.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Correct, DR configuration is not stored on the management server so care should be taken to store this configuration separately, in a build sheet or wherever other baseline gateway configuration is stored.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 03:09:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/135683#M24268</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2021-12-07T03:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/135689#M24270</link>
      <description>&lt;P&gt;Thanks, so I assume virtual routers are now supported from R81.x?&amp;nbsp; If so is this the preferred method to use?&amp;nbsp; I assume if you have many VS's and each VS requires a VR, then this actually is an additional over ahead to consider ie. resource usage on the appliances.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 04:52:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/135689#M24270</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-12-07T04:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/135690#M24271</link>
      <description>&lt;P&gt;Virtual routers are supported in VSLS deployments as of R81, but I still wouldn't suggest that one should be deployed between every VS and the rest of the network where dynamic routing is required, standard VSs are perfectly capable of performing reasonable dynamic routing duties while firewalling. If you were in a situation with a lot of changes happening in the routing table or peers appearing and disappearing then that might be a different story.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 04:56:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/135690#M24271</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2021-12-07T04:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/135692#M24272</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;In the VS itself is there the concept of a loopback IP which is used as the router id for adjacency, and if there is would this be preferred to use, not sure how that would affect topology though ie. in Smartconsole.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 05:10:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/135692#M24272</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-12-07T05:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/135693#M24273</link>
      <description>&lt;P&gt;No loopbacks on virtual devices, an interface IP (the IP configured in SmartConsole) must be used.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 05:12:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/135693#M24273</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2021-12-07T05:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/137898#M24583</link>
      <description>&lt;P&gt;OK so went to add a new OSPF area into an existing VS.&amp;nbsp; Simply templated what was there, but neighbour did not come up.&amp;nbsp; We have added the peer IPs to the firewall rules so we know this is not being blocked.&lt;/P&gt;
&lt;P&gt;It almost feels like the routed daemons hung and only processing what's there.&amp;nbsp; Will do some more investigation.&lt;/P&gt;
&lt;P&gt;example:&lt;/P&gt;
&lt;P&gt;set virtual-system &amp;lt;10&amp;gt;&lt;BR /&gt;set ospf instance default area &amp;lt;0.1.2.3&amp;gt; on&lt;BR /&gt;set ospf instance default area &amp;lt;0.1.2.3&amp;gt; nssa on&lt;BR /&gt;set ospf instance default interface &amp;lt;eth1.123&amp;gt; area &amp;lt;0.1.2.3&amp;gt; on&lt;BR /&gt;set ospf instance default interface &amp;lt;eth1.123&amp;gt; subtract-authlen on&lt;BR /&gt;set ospf instance default interface &amp;lt;eth1.123&amp;gt; authtype cryptographic key 30 algorithm md5 secret &amp;lt;ABC123&amp;gt;&lt;BR /&gt;save config&lt;/P&gt;
&lt;P&gt;I've confirmed that hello packets are entering the VS, however nothing is being sent out for this new area.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 23:36:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/137898#M24583</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2022-01-06T23:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/137902#M24584</link>
      <description>&lt;P&gt;What does the interface level config on the other device look like? Things like point-to-point mode aren't supported.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 01:03:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/137902#M24584</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-01-07T01:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/137903#M24585</link>
      <description>&lt;P&gt;Keep in mind, the router ID is just a 32-bit number, not an IP address. It doesn't have to belong to any interface on the system.&lt;/P&gt;
&lt;P&gt;To get dynamic routing on a cluster to work how most people want it to, you should specify the same router ID on both members and enable graceful restart.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 01:25:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/137903#M24585</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-01-07T01:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/137905#M24586</link>
      <description>&lt;P&gt;Don't forget that you also need the OSPF Multicast to be allowed, 224.0.0.5 and 224.0.0.6&lt;/P&gt;
&lt;P&gt;Other point, make sure the MTU is the same on your interface and on the next hop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are running OSPF on all VSs in our Maestro VSX setup that runs in the core of our network.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 06:10:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/137905#M24586</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2022-01-07T06:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring dynamic routing in clustered VSX</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/137909#M24588</link>
      <description>&lt;P&gt;Rule is in place to allow access to 224.0.0.5/6.&amp;nbsp; MTU size I believe is default and also note that other OSPF instances are working across the same trunked interface.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 09:11:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Configuring-dynamic-routing-in-clustered-VSX/m-p/137909#M24588</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2022-01-07T09:11:00Z</dc:date>
    </item>
  </channel>
</rss>

