<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Checkpoint BGP redistribution in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-BGP-redistribution/m-p/205580#M34118</link>
    <description>&lt;P&gt;Hello Checkmates,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm coming back to you with another weird problem - as always&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As we're deploying SDWan, we've identified that we want some certain sites, to be filtered from the rest of the network. So in order to achieve that, we separated them in a different VRF (vrf840) . This separated network (several sites) has the default gateway pointed to an Checkpoint cluster.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As we are distributing all those networks through BGP, we have set an BGP neighborship between SDWAN box (AS65002 - Cisco) and Checkpoint firewall (AS65502). All works well, we are receiving the routes that are only part of VRF840 on Checkpoint.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now with those routes, we want to re-distribute them from Checkpoint to the Distribution Core (AS65002 - Cisco). We did the set-up, and peered with the Core, BGP is UP and when we were checking, we were advertising several networks&amp;nbsp; (as they were matching the redistribution rule).&lt;/P&gt;
&lt;P&gt;We can clearly see on Checkpoint, that those routes are advertised but still when we check on Distribution Core, we can not see any routes received - like zero.&lt;/P&gt;
&lt;P&gt;To be sure that we don't have other issues, we decided to redistribute a static route - like 1.2.3.4/32 - and that shows as well as being advertised, and curiously, we can see that on Distribution as received. But any other routes, except the static one, are not showing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did anyone faced similar issues, or do you have a similar set-up, that works or it was failing the same way?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;PS: in the PPT I've tried to capture some details and schemas&lt;/P&gt;
&lt;P&gt;PS2: I've opened a ticket with Checkpoint, and they are correct stating that as long as we can see networks showing as being advertised from Checkpoint, then there is nothing wrong here.&lt;/P&gt;
&lt;P&gt;PS3: The involved HW is 15600 with R81 and JHF87, all the rest is Cisco&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Feb 2024 12:29:44 GMT</pubDate>
    <dc:creator>Sorin_Gogean</dc:creator>
    <dc:date>2024-02-09T12:29:44Z</dc:date>
    <item>
      <title>Checkpoint BGP redistribution</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-BGP-redistribution/m-p/205580#M34118</link>
      <description>&lt;P&gt;Hello Checkmates,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm coming back to you with another weird problem - as always&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As we're deploying SDWan, we've identified that we want some certain sites, to be filtered from the rest of the network. So in order to achieve that, we separated them in a different VRF (vrf840) . This separated network (several sites) has the default gateway pointed to an Checkpoint cluster.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As we are distributing all those networks through BGP, we have set an BGP neighborship between SDWAN box (AS65002 - Cisco) and Checkpoint firewall (AS65502). All works well, we are receiving the routes that are only part of VRF840 on Checkpoint.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now with those routes, we want to re-distribute them from Checkpoint to the Distribution Core (AS65002 - Cisco). We did the set-up, and peered with the Core, BGP is UP and when we were checking, we were advertising several networks&amp;nbsp; (as they were matching the redistribution rule).&lt;/P&gt;
&lt;P&gt;We can clearly see on Checkpoint, that those routes are advertised but still when we check on Distribution Core, we can not see any routes received - like zero.&lt;/P&gt;
&lt;P&gt;To be sure that we don't have other issues, we decided to redistribute a static route - like 1.2.3.4/32 - and that shows as well as being advertised, and curiously, we can see that on Distribution as received. But any other routes, except the static one, are not showing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did anyone faced similar issues, or do you have a similar set-up, that works or it was failing the same way?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;PS: in the PPT I've tried to capture some details and schemas&lt;/P&gt;
&lt;P&gt;PS2: I've opened a ticket with Checkpoint, and they are correct stating that as long as we can see networks showing as being advertised from Checkpoint, then there is nothing wrong here.&lt;/P&gt;
&lt;P&gt;PS3: The involved HW is 15600 with R81 and JHF87, all the rest is Cisco&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 12:29:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-BGP-redistribution/m-p/205580#M34118</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2024-02-09T12:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint BGP redistribution</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-BGP-redistribution/m-p/205589#M34119</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Sorry for the stupid question, did you verify that the routes received wasn't filtered out/blocked by the core(routemap/etc) ? Or that maybe the routes are hidden/inactive?&lt;/P&gt;
&lt;P&gt;Did you run packet capture on the CP &amp;amp; core side to find the actual bgp packet with the missing routes advertisement, and verify if it was sent from CP, and received on the core.&lt;/P&gt;
&lt;P&gt;If all that didn't help, consider enable bgp debug on both devices&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 13:37:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-BGP-redistribution/m-p/205589#M34119</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2024-02-09T13:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint BGP redistribution</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-BGP-redistribution/m-p/205591#M34120</link>
      <description>&lt;P&gt;Good point about routemaps. Also, TAC asked me to enable debug nunch of times for BGP issues, they are helpful, for sure.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 13:43:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-BGP-redistribution/m-p/205591#M34120</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-09T13:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint BGP redistribution</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-BGP-redistribution/m-p/205593#M34121</link>
      <description>&lt;P&gt;Hello AmirArama,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are the details from Distrib Core - as you see it's showing that I receive 1 network - still as you check below, I advertise 3 networks from Checkpoint....&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="50%"&gt;
&lt;P&gt;USDA-FW01&amp;gt; show bgp peer 10.2.3.10 advertise&lt;/P&gt;
&lt;P&gt;IPv4 Route MED LocalPref Nexthop Communities&lt;BR /&gt;1.2.3.4/32 None N/A(EBGP) 10.2.3.1&lt;BR /&gt;10.5.101.24/29 None N/A(EBGP) 10.2.3.1 65432:2444&lt;BR /&gt;10.160.253.253/32 None N/A(EBGP) 10.2.3.1 65432:2444&lt;/P&gt;
&lt;P&gt;USDA-FW01&amp;gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="50%"&gt;
&lt;P&gt;USDA-DIST-VSS(config-router-af)#do sh ip bgp all su&lt;BR /&gt;For address family: IPv4 Unicast&lt;BR /&gt;BGP router identifier 10.2.2.10, local AS number 65002&lt;BR /&gt;BGP table version is 1964305, main routing table version 1964305&lt;BR /&gt;2049 network entries using 508152 bytes of memory&lt;BR /&gt;2713 path entries using 368968 bytes of memory&lt;BR /&gt;419 multipath network entries and 838 multipath paths&lt;BR /&gt;320/298 BGP path/bestpath attribute entries using 92160 bytes of memory&lt;BR /&gt;260 BGP AS-PATH entries using 10736 bytes of memory&lt;BR /&gt;67 BGP community entries using 2704 bytes of memory&lt;BR /&gt;1 BGP extended community entries using 40 bytes of memory&lt;BR /&gt;0 BGP route-map cache entries using 0 bytes of memory&lt;BR /&gt;0 BGP filter-list cache entries using 0 bytes of memory&lt;BR /&gt;BGP using 982760 total bytes of memory&lt;BR /&gt;Dampening enabled. 0 history paths, 0 dampened paths&lt;BR /&gt;67 received paths for inbound soft reconfiguration&lt;BR /&gt;BGP activity 98352/96303 prefixes, 1217580/1214867 paths, scan interval 30 secs&lt;BR /&gt;2211 networks peaked at 03:19:47 Oct 3 2023 EDT (18w3d ago)&lt;/P&gt;
&lt;P&gt;Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd&lt;BR /&gt;10.2.2.11 4 65002 713518 741623 1964305 0 0 16w1d 54&lt;BR /&gt;10.2.2.12 4 65002 713237 741024 1964305 0 0 16w1d 51&lt;BR /&gt;10.2.2.15 4 65002 1178553 1241636 1964305 0 0 27w0d 383&lt;BR /&gt;10.2.2.25 4 65002 1176458 1241603 1964305 0 0 27w0d 383&lt;BR /&gt;10.2.2.35 4 65002 1201156 1241221 1964305 0 0 27w0d 680&lt;BR /&gt;10.2.2.55 4 65002 1168252 1241590 1964305 0 0 27w0d 707&lt;BR /&gt;10.2.2.65 4 65002 1167020 1241229 1964305 0 0 27w0d 0&lt;BR /&gt;10.2.2.250 4 64745 1167057 1167103 1964305 0 0 27w0d 4&lt;BR /&gt;&lt;STRONG&gt;10.2.3.1 4 65502 5446 5250 1964305 0 0 19:02:06 1&lt;/STRONG&gt;&lt;BR /&gt;10.2.252.253 4 65402 2948599 3156486 1964305 0 0 1y21w 0&lt;BR /&gt;10.2.252.254 4 65402 2948599 3156410 1964305 0 0 1y21w 0&lt;BR /&gt;10.2.253.253 4 65402 3658420 4050054 1964305 0 0 1y38w 11&lt;BR /&gt;10.2.253.254 4 65402 3658267 4049650 1964305 0 0 1y38w 11&lt;BR /&gt;USDA-DIST-VSS(config-router-af)#&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did not do any debugs, because I don't think that advertising 3 routes, would mean 3 packets, and only one - the static one - is passed and accepted by Distrib Core.&amp;nbsp;&lt;BR /&gt;An on this particular neighbor, on Distrib Core, I have an in routemap that allows everything. I even dropped it while with Checkpoint TAC and did not do any change.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 13:58:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-BGP-redistribution/m-p/205593#M34121</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2024-02-09T13:58:19Z</dc:date>
    </item>
  </channel>
</rss>

