<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Running OSPF on the Security Gateways with SecureXL disabled in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Running-OSPF-on-the-Security-Gateways-with-SecureXL-disabled/m-p/31794#M6662</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SecureXL does not impact the performance for OSPF in any way. OSPF is part of the OS and is not part of the traffic passing through the gateway. Impact of OSPF on the box depends on the number of path choices and the number of routes there are. I do not think you will notice more than a 1% increase of CPU usage in a very busy network with hundreds of routes and at least 4 different possible paths to a destination. The latter is something you will rarely see on a perimeter FW, so most likely there will only be updates from the network about networks being added or dropped to/from the routing table.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 30 Sep 2018 21:44:02 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2018-09-30T21:44:02Z</dc:date>
    <item>
      <title>Running OSPF on the Security Gateways with SecureXL disabled</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Running-OSPF-on-the-Security-Gateways-with-SecureXL-disabled/m-p/31793#M6661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Mates,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you are doing just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have taken over as the check point admin of a large telcom company. The company infrastructure is comprised of Internal and External Check Point Clusters running in &lt;STRONG&gt;Load-sharing unicast mode&lt;/STRONG&gt;. Recently it was also enabled the &lt;STRONG&gt;Mobile Access Blade&lt;/STRONG&gt; on the external clusters.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now there is a new process of segmenting our network, and as part of the segmentation, the IP team wishes to have the Check Gateways running OSPF.&lt;/P&gt;&lt;P&gt;I am personally concerned about the performance of the gateways because one of the main feature that improves performance (SecureXL) is already disabled due to the ClusterXL mode, and other enabled software blades such as Mobile Access. We are using a 21800 appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know the performance implications that I can encounter if OSPF is enabled taking into account that secureXL is already not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any relevant contribution is welcome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Sep 2018 18:51:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Running-OSPF-on-the-Security-Gateways-with-SecureXL-disabled/m-p/31793#M6661</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-30T18:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Running OSPF on the Security Gateways with SecureXL disabled</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Running-OSPF-on-the-Security-Gateways-with-SecureXL-disabled/m-p/31794#M6662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SecureXL does not impact the performance for OSPF in any way. OSPF is part of the OS and is not part of the traffic passing through the gateway. Impact of OSPF on the box depends on the number of path choices and the number of routes there are. I do not think you will notice more than a 1% increase of CPU usage in a very busy network with hundreds of routes and at least 4 different possible paths to a destination. The latter is something you will rarely see on a perimeter FW, so most likely there will only be updates from the network about networks being added or dropped to/from the routing table.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Sep 2018 21:44:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Running-OSPF-on-the-Security-Gateways-with-SecureXL-disabled/m-p/31794#M6662</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-09-30T21:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: Running OSPF on the Security Gateways with SecureXL disabled</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Running-OSPF-on-the-Security-Gateways-with-SecureXL-disabled/m-p/31795#M6663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with &lt;A href="https://community.checkpoint.com/migrated-users/50921"&gt;Maarten Sjouw&lt;/A&gt;‌, there should not be a major impact on the cluster due to OSPF.&lt;/P&gt;&lt;P&gt;Actually, since R80.20 introducing dynamic routing anti-spoofing, it should be simpler to implement and, hopefully, we'll see the routing changes in the logs now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Oct 2018 00:24:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Running-OSPF-on-the-Security-Gateways-with-SecureXL-disabled/m-p/31795#M6663</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-10-01T00:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Running OSPF on the Security Gateways with SecureXL disabled</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Running-OSPF-on-the-Security-Gateways-with-SecureXL-disabled/m-p/31796#M6664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks @&lt;A _jive_internal="true" data-avatarid="1946" data-externalid="" data-online="false" data-presence="null" data-userid="50921" data-username="maart190aef73-58b6-43b8-aee6-8bbb11391e10" href="https://community.checkpoint.com/people/maart190aef73-58b6-43b8-aee6-8bbb11391e10" style="color: inherit; background-color: #ffffff; border: 0px; font-weight: bold; text-decoration: underline; font-size: 14px;"&gt;Maarten Sjouw&lt;/A&gt;&amp;nbsp;and &lt;A href="https://community.checkpoint.com/migrated-users/48025"&gt;Vladimir Yakovlev&lt;/A&gt;‌.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the performance impact is not a major problem, I have one additional question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does Check Point Gateways support &lt;STRONG&gt;Mutual Redistribution? How?&amp;nbsp;&lt;/STRONG&gt;I am asking this question because according to the new network design, ouur&amp;nbsp;external Gateways will have to do mutual redistribution between &lt;STRONG&gt;OSPF&lt;/STRONG&gt; and &lt;STRONG&gt;eBGP&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Oct 2018 08:24:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Running-OSPF-on-the-Security-Gateways-with-SecureXL-disabled/m-p/31796#M6664</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-10-01T08:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Running OSPF on the Security Gateways with SecureXL disabled</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Running-OSPF-on-the-Security-Gateways-with-SecureXL-disabled/m-p/31797#M6665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;An additional question is to know whether is it possible to create different OSPF processes on the Firewall. In such a way that networks in a specific OSPF process (for example process 1), are not advertised in another OSPF process (for example OSPF process 2)&lt;/P&gt;&lt;P&gt;&amp;nbsp;Thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Oct 2018 11:21:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Running-OSPF-on-the-Security-Gateways-with-SecureXL-disabled/m-p/31797#M6665</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-10-01T11:21:06Z</dc:date>
    </item>
  </channel>
</rss>

