<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BGP default route on standby member expected behaviour? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194889#M32625</link>
    <description>&lt;P&gt;What does the BGP config look like, could you please share the version/JHF of Gateway and if graceful-restart is configured for BGP?&lt;/P&gt;</description>
    <pubDate>Sun, 15 Oct 2023 02:40:20 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-10-15T02:40:20Z</dc:date>
    <item>
      <title>BGP default route on standby member expected behaviour?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194853#M32619</link>
      <description>&lt;P&gt;I have a cluster which is learning its default route via BGP, this works fine on the active member, but the standby never installs the route, so all communications that rely on the default route fail (updates.checkpoint.com for instance)&lt;/P&gt;&lt;P&gt;On failover its fine, as the default route appears immediatly when it becomes active, but whichever member is standby loses its default route, so more an annoyance than anything else.&lt;/P&gt;&lt;P&gt;This isn't occuring for OSPF, the standby member has all of the OSPF learnt routes with the exception of the ones hidden because they are directly connected ones.&lt;/P&gt;&lt;P&gt;If I add a manual static default (or specific route) pointing at the two BGP routers then everything works as intended, the standby has a default route but also folds the outbound traffic over the Sync interface and out through the active, however because (as I undertsand it) a static *always* takes precedence over a dynamic in Checkpoint land, this means that the static default overrides the BGP default.&lt;/P&gt;&lt;P&gt;Output of "show route all bgp" on Active:&lt;/P&gt;&lt;PRE&gt;Codes: C - Connected, S - Static, R - RIP, B - BGP (D - Default),&lt;BR /&gt;O - OSPF IntraArea (IA - InterArea, E - External, N - NSSA),&lt;BR /&gt;IS - IS-IS (L1 - Level 1, L2 - Level 2, IA - InterArea, E - External),&lt;BR /&gt;A - Aggregate, K - Kernel Remnant, H - Hidden, P - Suppressed,&lt;BR /&gt;NP - NAT Pool, U - Unreachable, i - Inactive&lt;BR /&gt;&lt;BR /&gt;B D 0.0.0.0/0 via XXX.YYY.ZZZ.249, eth1-01.500, cost 0, age 3223&lt;BR /&gt;B H i 0.0.0.0/0 via XXX.YYY.ZZZ.250, eth1-01.500, cost None, age 3196&lt;BR /&gt;B H i 0.0.0.0/0 via XXX.YYY.ZZZ.249, eth1-01.500, cost None, age 3195&lt;/PRE&gt;&lt;P&gt;On Standby:&lt;/P&gt;&lt;PRE&gt;Codes: C - Connected, S - Static, R - RIP, B - BGP (D - Default),&lt;BR /&gt;O - OSPF IntraArea (IA - InterArea, E - External, N - NSSA),&lt;BR /&gt;IS - IS-IS (L1 - Level 1, L2 - Level 2, IA - InterArea, E - External),&lt;BR /&gt;A - Aggregate, K - Kernel Remnant, H - Hidden, P - Suppressed,&lt;BR /&gt;NP - NAT Pool, U - Unreachable, i - Inactive&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I missing something obvious?&amp;nbsp; Is it not passing the route to the standby becuase &lt;EM&gt;FIBMGR &lt;/EM&gt;treats default 0.0.0.0/0 routes differently?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 15:52:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194853#M32619</guid>
      <dc:creator>MattElkington</dc:creator>
      <dc:date>2023-10-11T15:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: BGP default route on standby member expected behaviour?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194885#M32623</link>
      <description>&lt;P&gt;I thought myself that was indeed right, but its not. I just checked in customer's environment and shows same on both active and standby.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 20:52:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194885#M32623</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-11T20:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: BGP default route on standby member expected behaviour?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194889#M32625</link>
      <description>&lt;P&gt;What does the BGP config look like, could you please share the version/JHF of Gateway and if graceful-restart is configured for BGP?&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2023 02:40:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194889#M32625</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-10-15T02:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: BGP default route on standby member expected behaviour?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194890#M32626</link>
      <description>&lt;P&gt;Since Chris asked about version/jumbo, our customer is on R81.20 jumbo 24. Only reason why we did not go to recommended jumbo was actually BGP issue another customer posted about in a different post.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 23:41:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194890#M32626</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-11T23:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: BGP default route on standby member expected behaviour?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194917#M32627</link>
      <description>&lt;P&gt;Static routes are not always preferred but depend of Rank. Static routes have a rank of 60 and BGP a rank of 170, so to add a floating route you need to configure one with a rank of a higher numerical value than 170.&lt;/P&gt;&lt;P&gt;Regarding your issue, routes should normally be synced between the two cluster members assuming they have the same configurations but you might be getting your default route from somewhere else when the cluster isn't active for some reason, or they might not be installed because of a configuration issue.&lt;/P&gt;&lt;P&gt;Ensure you have the same router-id and BGP configuration on both members and check the router-options as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Gaia_Advanced_Routing_AdminGuide/Topics-GARG/Routing-Options-Protocol-Rank.htm?tocpath=Routing%20Options%7C_____3" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Gaia_Advanced_Routing_AdminGuide/Topics-GARG/Routing-Options-Protocol-Rank.htm?tocpath=Routing%20Options%7C_____3&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 09:30:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194917#M32627</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-10-12T09:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: BGP default route on standby member expected behaviour?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194924#M32628</link>
      <description>&lt;P&gt;R81.20 JHF Take 26&lt;/P&gt;&lt;P&gt;Config for bgp is:&lt;/P&gt;&lt;PRE&gt;set nat-pool XXX.YYY.ZZ8.16/28 on&lt;BR /&gt;set nat-pool XXX.YYY.ZZ8.16/28 comment "Static NAT Range advertised via BGP"&lt;BR /&gt;&lt;BR /&gt;set bgp default-med 0&lt;BR /&gt;set bgp default-route-gateway XXX.YYY.ZZ7.249&lt;BR /&gt;set bgp external remote-as ABCDE on&lt;BR /&gt;set bgp external remote-as ABCDE export-routemap "bgp_export" preference 1 family inet on&lt;BR /&gt;set bgp external remote-as ABCDE peer XXX.YYY.ZZ7.249 on&lt;BR /&gt;set bgp external remote-as ABCDE peer XXX.YYY.ZZ7.249 ping on&lt;BR /&gt;set bgp external remote-as ABCDE peer XXX.YYY.ZZ7.250 on&lt;BR /&gt;set bgp external remote-as ABCDE peer XXX.YYY.ZZ7.250 ping on&lt;BR /&gt;&lt;BR /&gt;set inbound-route-filter bgp-policy 512 based-on-as as GHIJK.LMNOP on&lt;BR /&gt;set inbound-route-filter bgp-policy 512 accept-all-ipv4&lt;BR /&gt;set inbound-route-filter bgp-policy 512 default-localpref 0&lt;BR /&gt;set inbound-route-filter bgp-policy 512 default-weight 0&lt;BR /&gt;&lt;BR /&gt;set routemap bgp_export id 1 on&lt;BR /&gt;set routemap bgp_export id 1 allow&lt;BR /&gt;set routemap bgp_export id 1 match network 0.0.0.0/0 all&lt;BR /&gt;set routemap bgp_export id 1 match protocol nat-pool&lt;BR /&gt;set bgp external remote-as ABCDE export-routemap bgp_export preference 1 family inet on&lt;/PRE&gt;&lt;P&gt;I do notice that if I remove "set bgp default-route-gateway XXX.YYY.ZZ7.249" that even the active gateway doesn't get a default route.&amp;nbsp; So maybe its that its not &lt;EM&gt;learning&lt;/EM&gt; the BGP Default, or at least not transferring to the kernel.&lt;/P&gt;&lt;P&gt;I feel like I'm missing something here central here,&amp;nbsp; do I need to explicitly export the BGP routes to the kernel?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 11:51:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194924#M32628</guid>
      <dc:creator>MattElkington</dc:creator>
      <dc:date>2023-10-12T11:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: BGP default route on standby member expected behaviour?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194926#M32629</link>
      <description>&lt;P&gt;You need an import route-map to install routes received from BGP.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 11:54:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194926#M32629</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-10-12T11:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: BGP default route on standby member expected behaviour?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194963#M32632</link>
      <description>&lt;P&gt;Yep! That's the badger!&lt;/P&gt;&lt;P&gt;It was essentially me being an idiot.&amp;nbsp; There's an inbound route filter for the internal BGP AS, but not the external one.&amp;nbsp; That explains why the routes were flagging as Inactive and Hidden on the Active gateway.&lt;BR /&gt;&lt;BR /&gt;This explains why OSPF routes work (they also have an inbound filter for all routes being accepted), but BGP doesn't as I wasn't bloody importing the BGP routes.&lt;BR /&gt;&lt;BR /&gt;I have added an inbound route filter and now the two 0.0.0.0/0 routes from each peer are only showing as Inactive and not Hidden, but they are only inactive because i have&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;set bgp default-route-gateway XXX.YYY.ZZ7.249&lt;/PRE&gt;&lt;P&gt;set.&amp;nbsp; I will remove that tomorrow morning and hopefully the actual BGP routes will be used on the active and not this "manufactured" default, and those will be pushed over to the standby.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Knew I was missing something important!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 15:59:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/194963#M32632</guid>
      <dc:creator>MattElkington</dc:creator>
      <dc:date>2023-10-12T15:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: BGP default route on standby member expected behaviour?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/195104#M32669</link>
      <description>&lt;P&gt;I have confirmed today that actually importing the BGP routes to the kernel and disabling the&lt;/P&gt;&lt;PRE&gt;set bgp default-route-gateway XXX.YYY.ZZ7.249&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;setting makes it so the Active firewall actually uses the BGP learned default, and then passes it over tot he standby correctly.&lt;/P&gt;&lt;P&gt;All is now well in the world!&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 16:18:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/195104#M32669</guid>
      <dc:creator>MattElkington</dc:creator>
      <dc:date>2023-10-13T16:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: BGP default route on standby member expected behaviour?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/195107#M32670</link>
      <description>&lt;P&gt;Happy its working! &lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 16:57:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/195107#M32670</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-13T16:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: BGP default route on standby member expected behaviour?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/275612#M46009</link>
      <description>&lt;P&gt;I currently have an Active/Standby cluster and am trying to get BGP working. I have to BGP peers that are Established. When I check received routes, the default route from ISP-B is showing 'i' for Inactive. I am getting the full routes from the other ISP, ISP-A. I tried testing this by removing the physical link for ISP-A and I lose internet, I am assuming because the only route I am receiving from ISP-B is the default route, which is showing Inactive.&lt;/P&gt;&lt;P&gt;It sounds similar to the issue you were facing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2026 13:41:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/275612#M46009</guid>
      <dc:creator>cmale</dc:creator>
      <dc:date>2026-04-16T13:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: BGP default route on standby member expected behaviour?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/275619#M46012</link>
      <description>&lt;P&gt;Do you have inbound route filters or route maps matching the route?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2026 14:10:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/BGP-default-route-on-standby-member-expected-behaviour/m-p/275619#M46012</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-04-16T14:10:46Z</dc:date>
    </item>
  </channel>
</rss>

