Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Arend
Contributor

BGP connection rejection by Check Point 6000 series cluster

Hello,

We have a Check Point 6000 series cluster at R81.20 connected to Cisco hardware of the ISP. We do BGP peering for exchange of default route and some public routes.

After an ISP hardware switch (no config change on our Check Point side) we see a BGP message on port 179 which is send from our Check Point: Notification Message (3), length: 21, Cease (6), subcode Connection Rejected (5)

What would be the issue that the Check Point rejects the connection request? The message was seen on the primary gateway as that gateway is active.

0 Kudos
3 Replies
the_rock
Legend
Legend

What does zdebug show? fw ctl zdebug + drop | grep "179"

Andy

0 Kudos
Alex-
Leader Leader
Leader

Check if they didn't implement extra options on the new router, like authentication of the BGP peers and so on.

(1)
the_rock
Legend
Legend

Good suggestion @Alex- 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events