Hi everyone,
I currently have an Azure-deployed Check Point ClusterXL HA environment (Active/Standby) and I’m considering enabling BGP Graceful Restart.
The current topology looks like this:
Two Check Point gateways in a ClusterXL HA setup.
Each gateway establishes a VPN tunnel (VTI) to an Azure Virtual Network Gateway.
Both firewalls are peering via BGP to a private Azure IP (<BGP Peer IP>), which belongs to the Azure Virtual Network Gateway.
The Virtual Network Gateway in turn peers with on-prem Cisco routers through another connection.
Everything is working fine as-is.
My question is:
➡️ If I enable BGP Graceful Restart on member A (which is currently active), is there any risk that this could trigger a failover in the cluster before applying the same setting to member B?
I’m concerned whether this change could:
Has anyone here performed this adjustment in a similar Azure setup with Cisco routers behind the Virtual Network Gateway?
Would you recommend applying this live, or is it better done during a maintenance window?
Appreciate any advice or shared experience.
Thanks in advance!