- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- OSPF neighbor count
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
OSPF neighbor count
Dear all:
Is there anyone who ever managed over 200 OSPF neighbors and 6 ares before? It's not difficult with Juniper/Cisco or other vendors but what about Check Point?
The customer is using Juniper SSG5200(HA) and doing OSPF over ipsec(Route based VPN) with 200 Juniper SSG350M(2 wan links) for 10 years(Built by me.), if I want to replace with Check Point, can central vpn termination point can handle so many vpn tunnels and OSPF neighbors? I'm afraid of routeD crashes sometimes, that's a nightmare for this kind of network scope.
I know customer can have better choice but I'm wondering can I do the same thing with CP5600(HA) and SMB models like CP1490(For branches)?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I assume your question could be divided on two points:
- OSPF ability; I assume yes; you can check on sk95968 OSPF on Gaia general document and on its related documentations and solutions
- VPN in large environment: will you try Multiple Entry Point (MEP)? If so, look at the dedicated section of the VPN admin guide of your version.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi:
Actually I'ved tried large number of ospf neighbors and neighbors status start random dropping after over 60 neighbor counts(About 2 years ago with R77.30), that's why I doubt Check Point's routeD stability, and MEP is not what customer need since customer's dual wan should be Active/Active mode.
But still thanks for your replay, hope R80.10 or later version can be better.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So we need to wait concrete feebadck from Check Point: Dameon Welch Abernathy could you help us on this?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We've made a number of stability improvements in routed over the last two years, including situations where there are a large number of OSPF neighbors.
I believe most of these fixes were rolled into R80.10 as some of these fixes were available in R77.30 as well.
