- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Checkpoint FW and BGP
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Checkpoint FW and BGP
Hi all,
We currently have two FWs in cluster at two locations in active/backup mode.
FWs servers as a gateway with floating vIP LANs, without BGP.
We would like to add another LAN interface with BGP. We want to have two BGP sessions, one at each location.
At least active FW would advertise default route to leaf/spine switches. When FW switch from backup to active
it should start to advertise better default route.
Is it possible to have such a configuration or we have to move to active/active topology?
Best regards, Ales
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think it will work. Only the active member talks BGP and I'm not aware of any requirement for the BGP configure to be %100 the same on both members. There could be some items that need to be the same such as local AS.
Better safe then sorry with that being said. Test it out.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Router-ID should be the VIP, also recommend using Graceful restart...
