Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
useraz
Explorer

Checkpoint FW and BGP

Hi all,

We currently have two FWs in cluster at two locations in active/backup mode.
FWs servers as a gateway with floating vIP LANs, without BGP.

We would like to add another LAN interface with BGP. We want to have two BGP sessions, one at each location.
At least active FW would advertise default route to leaf/spine switches. When FW switch from backup to active
it should start to advertise better default route.

Is it possible to have such a configuration or we have to move to active/active topology?

 

Best regards, Ales

0 Kudos
Reply
2 Replies
John_Fleming
Advisor

I think it will work. Only the active member talks BGP and I'm not aware of any requirement for the BGP configure to be %100 the same on both members. There could be some items that need to be the same such as local AS.

Better safe then sorry with that being said. Test it out.

0 Kudos
Reply
Chris_Atkinson
Employee
Employee

Router-ID should be the VIP, also recommend using Graceful restart...

0 Kudos
Reply