- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
We migrate a ClusterXL to Maestro with VSX R81.20. We have a lot of interfaces and most of them are doing OSPF. Now we are getting a limitation, after adding 128. OSPF interface:
"Can only configure a maximum of 127 OSPF interfaces"
Will this be a limitation of VSX or Maestro ?
Any solution for this ?
This limitation is based on best practices that you shouldn't have more than 60 OSPF neighbors per router. Thus the number of OSPF interfaces per SGW/VS is 127 I talked this with R&D and they also confirmed the same.
See the article from Cisco below.
Designing Scalable OSPF Design > Designing Cisco Network Service Architectures (ARCH): Developing an...
If you need more interfaces, you should segment your network.
Best to open a TAC request to get an official answer.
This limitation is based on best practices that you shouldn't have more than 60 OSPF neighbors per router. Thus the number of OSPF interfaces per SGW/VS is 127 I talked this with R&D and they also confirmed the same.
See the article from Cisco below.
Designing Scalable OSPF Design > Designing Cisco Network Service Architectures (ARCH): Developing an...
If you need more interfaces, you should segment your network.
maybe I don‘t understand this. We have only two OSPF neighbours (these are external routers) and we have a gateway with 180 interfaces. We want to distribute via OSPF the routing information for the networks of these interfaces. We are doing this since 10 years with a Check Point Gateway without problems. The production system running R80.30 has no problem with all these interfaces.
Including every interface in the OSPF process is not redistribution. I believe you have added them as passive so far. Probably we haven't enforced this limitation before, not 100% sure.
If you want to redistribute your connected routes there are two options:
1. Use redistribution
2. Use route-maps
Routemaps allow you to be more flexible allowing modification of the routes.
Benefit of including the interfaces in OSPF process itself is that they will appear as internal OSPF routes (Type 1 LSA), show route shows them with O.
If you redistribute them, they are automatically external routes (O E1 or O E2). This can become an issue only if you have the same routes coming from different sources. In this case the internal routes are prioritized over the external ones. However, you can change this designation with a routemap.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
18 | |
3 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY