<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable OSPF Graceful-Restart on Maestro Security Group (R81.10) in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Enable-OSPF-Graceful-Restart-on-Maestro-Security-Group-R81-10/m-p/174030#M1449</link>
    <description>&lt;P&gt;Which Jumbo take is deployed in the environment?&lt;/P&gt;
&lt;P&gt;Graceful restart is typically relevant to failover scenarios as different to the symptoms you've described.&lt;/P&gt;
&lt;P&gt;Do you see the SMO / DR role change to a different SGM during this process?&lt;/P&gt;</description>
    <pubDate>Wed, 08 Mar 2023 14:15:05 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-03-08T14:15:05Z</dc:date>
    <item>
      <title>Enable OSPF Graceful-Restart on Maestro Security Group (R81.10)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Enable-OSPF-Graceful-Restart-on-Maestro-Security-Group-R81-10/m-p/174027#M1448</link>
      <description>&lt;P&gt;Dear Checkmates,&lt;/P&gt;&lt;P&gt;We have realized, that we obviously lose all sessions, when we add a new interface to our security group and add it into ospf.&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;set ospf instance default interface bond1.2742 passive on&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;set ospf instance default interface bond1.2762 area 0.0.0.10 on&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Thus I would like to enable OSPF graceful-restart on our securitygroup.&lt;/P&gt;&lt;P&gt;(&lt;FONT size="2"&gt;&lt;EM&gt;Although in some comment of C_Atkinson here on the forum it is mentioned, that graceful-restart should not be required, although it refers to Cluster XL?&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/td-p/152083#" target="_self"&gt;https://community.checkpoint.com/t5/Security-Gateways/OSPF-drops-on-cluster-failover-since-R81-10-upgrade-from-R80-30/td-p/152083#&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;)&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything I need to consider? We peer with Cisco Switches and I stumbled across:&lt;/P&gt;&lt;P&gt;"graceful-restart feature is an industry standard and Maestro supports it for both OSPF and BGP. That way you don't lose routes.&amp;nbsp;graceful-restart must be supported by the peer and timers need to be in sync. The routes will stay while peering is built up after failover."&lt;/P&gt;&lt;P&gt;Can I assume this matches, since OSPF and graceful-restart helper already work?&lt;/P&gt;&lt;P&gt;Also I saw the following in the GUI:&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;"OSPF Graceful Restart is incompatible with VRRP preempt" mode. Please disable preempt mode before configuring graceful restart"&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Since this is no VRRP Cluster and we already have graceful-restart-helper enabled, I think I can ignore this warning?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you think it is safe to issue:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;set ospf instance default graceful-restart on&lt;/EM&gt;&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance and BR,&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 13:08:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Enable-OSPF-Graceful-Restart-on-Maestro-Security-Group-R81-10/m-p/174027#M1448</guid>
      <dc:creator>T_Sonnberger</dc:creator>
      <dc:date>2023-03-08T13:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Enable OSPF Graceful-Restart on Maestro Security Group (R81.10)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Enable-OSPF-Graceful-Restart-on-Maestro-Security-Group-R81-10/m-p/174030#M1449</link>
      <description>&lt;P&gt;Which Jumbo take is deployed in the environment?&lt;/P&gt;
&lt;P&gt;Graceful restart is typically relevant to failover scenarios as different to the symptoms you've described.&lt;/P&gt;
&lt;P&gt;Do you see the SMO / DR role change to a different SGM during this process?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 14:15:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Enable-OSPF-Graceful-Restart-on-Maestro-Security-Group-R81-10/m-p/174030#M1449</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-08T14:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: Enable OSPF Graceful-Restart on Maestro Security Group (R81.10)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Enable-OSPF-Graceful-Restart-on-Maestro-Security-Group-R81-10/m-p/174033#M1450</link>
      <description>&lt;P&gt;Hi Chris, thanks for the quick response:&lt;/P&gt;&lt;P&gt;We run:&lt;/P&gt;&lt;P&gt;HOTFIX_R81_10_JUMBO_HF_MAIN Take: 66&lt;/P&gt;&lt;P&gt;How could I see if the SM0 role changes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were made aware of this through a team, which mentioned, that they have lost twice all sessions on their machines, and the timestamps matched exactly with the creation of some interfaces and adding them to OSPF.&lt;/P&gt;&lt;P&gt;I also could see, that our loadbalancer lost all connections to servers, sitting behind the firewall, at the same time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The /var/log/meassges looked like:&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:37 2023 security-group-ch01-01 clish[75447]: cmd by admin: Start executing : set ospf ... (cmd md5: 618860da39c8d871aec65ec33b6ebc30)&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:37 2023 security-group-ch01-01 clish[75447]: cmd by admin: Processing : set ospf instance default interface bond1.2204 area 0.0.0.10 on (cmd md5: 618860da39c8d871aec65ec33b6ebc30)&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 xpand[61248]: NETIS Message:vsxnet_send_rtnetlink_getlink_query failed to resolve if_type_str for magg0&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 xpand[61248]: NETIS Message:vsxnet_bond_status vsxnet_send_rtnetlink_getlink_query failed for magg0&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 xpand[61248]: instance name is [default]&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 xpand[61248]: Configuration changed from localhost by user admin&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 xpand[61248]: finalize: routed conf file is [/etc/routed0.conf]&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 xpand[61248]: finalize: routed instance is [default]&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 xpand[61248]: moving /etc/cprd_syntax_test_default to /etc/routed0.conf&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 xpand[61248]: Using routed pid 68213 for 'default'&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 routed[68188]: [routed] NOTICE: task_reconfigure re-initializing from /etc/routed.conf&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 routed[68188]: [routed] NOTICE: parse_instance_only: my_instance_id -1 parsing instance default&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 routed[68188]: [routed] NOTICE: task_reconfigure reinitializing done&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 clish[75447]: cmd by admin: Start executing : set ospf ... (cmd md5: f890304ce4e765ac409944891568858a)&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 clish[75447]: cmd by admin: Processing : set ospf instance default interface bond1.2204 passive on (cmd md5: f890304ce4e765ac409944891568858a)&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 xpand[61248]: instance name is [default]&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 xpand[61248]: Configuration changed from localhost by user admin&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 xpand[61248]: finalize: routed conf file is [/etc/routed0.conf]&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 xpand[61248]: finalize: routed instance is [default]&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 xpand[61248]: moving /etc/cprd_syntax_test_default to /etc/routed0.conf&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 xpand[61248]: Using routed pid 68213 for 'default'&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 routed[68188]: [routed] NOTICE: task_reconfigure re-initializing from /etc/routed.conf&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 routed[68188]: [routed] NOTICE: parse_instance_only: my_instance_id -1 parsing instance default&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Feb 20 14:46:38 2023 security-group-ch01-01 routed[68188]: [routed] NOTICE: task_reconfigure reinitializing done&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;Thanks in advance and BR,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;Thomas&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 13:41:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Enable-OSPF-Graceful-Restart-on-Maestro-Security-Group-R81-10/m-p/174033#M1450</guid>
      <dc:creator>T_Sonnberger</dc:creator>
      <dc:date>2023-03-08T13:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: Enable OSPF Graceful-Restart on Maestro Security Group (R81.10)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Enable-OSPF-Graceful-Restart-on-Maestro-Security-Group-R81-10/m-p/174037#M1451</link>
      <description>&lt;P&gt;To see the current SMO &amp;amp; DR manager (Dynamic routing manager) review the following command output from expert mode:&lt;/P&gt;
&lt;P&gt;asg stat -i tasks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 13:59:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Enable-OSPF-Graceful-Restart-on-Maestro-Security-Group-R81-10/m-p/174037#M1451</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-08T13:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: Enable OSPF Graceful-Restart on Maestro Security Group (R81.10)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Enable-OSPF-Graceful-Restart-on-Maestro-Security-Group-R81-10/m-p/174038#M1452</link>
      <description>&lt;P&gt;Thank you:&lt;/P&gt;&lt;P&gt;This is the output - it seems it remained on 1 (though I can't prove that it has been 2 before)&lt;/P&gt;&lt;P&gt;Chassis 1:&lt;BR /&gt;[Expert@security-group-ch01-01:0]# asg stat -i tasks&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;| Task (Task ID) | Chassis 1 |&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;| SMO (0) | 1(local) |&lt;BR /&gt;| General (1) | 1(local) |&lt;BR /&gt;| LACP (2) | 1(local) |&lt;BR /&gt;| CH Monitor (3) | 1(local) |&lt;BR /&gt;| DR Manager (4) | 1(local) |&lt;BR /&gt;| UIPC (5) | 1(local) |&lt;BR /&gt;| Alert (6) | 1(local) |&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Chassis 2:&lt;/P&gt;&lt;P&gt;[Expert@vsecurity-group-01-ch01-02:0]# asg stat -i tasks&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;| Task (Task ID) | Chassis 1 |&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;| SMO (0) | 1 |&lt;BR /&gt;| General (1) | 1 |&lt;BR /&gt;| LACP (2) | 1 |&lt;BR /&gt;| CH Monitor (3) | 1 |&lt;BR /&gt;| DR Manager (4) | 1 |&lt;BR /&gt;| UIPC (5) | 1 |&lt;BR /&gt;| Alert (6) | 1 |&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 14:00:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Enable-OSPF-Graceful-Restart-on-Maestro-Security-Group-R81-10/m-p/174038#M1452</guid>
      <dc:creator>T_Sonnberger</dc:creator>
      <dc:date>2023-03-08T14:00:26Z</dc:date>
    </item>
  </channel>
</rss>

