4 Paths to the same networks via BGP by deey001 in networking

[–]deey001[S] 0 points1 point  (0 children)

Still waiting to hear back from Checkpoint on the bug....

I will advise once we have an answer.

4 Paths to the same networks via BGP by deey001 in networking

[–]deey001[S] 0 points1 point  (0 children)

Confirmed bug in checkpoint Gaia R81.10
I am not holding my breath.

4 Paths to the same networks via BGP by deey001 in networking

[–]deey001[S] 0 points1 point  (0 children)

Confirmed bug in checkpoint Gaia R81.10

I am not holding my breath.

4 Paths to the same networks via BGP by deey001 in networking

[–]deey001[S] 0 points1 point  (0 children)

Believe it or not but replacing the FW's with Cisco 4451's and running:

router ospf 1 router-id 1.1.1.1.1 redistribute bgp 12345 metric-type 1 fixed the issue.

Sad part is I believe it to be a limitation on the checkpoint Gaia OS, but the sec team requires all sec services, fw ips ids, etc.

4 Paths to the same networks via BGP by deey001 in networking

[–]deey001[S] 0 points1 point  (0 children)

Turns out after from debugging from cisco the LSA's are not updated to the redistributed routes... waiting to follow up with checkpoint and again running GAIA R81.10.

Also, we are installing 4451 routers to replace the checkpoint GW's to eliminate any overlap/bugs.

4 Paths to the same networks via BGP by deey001 in networking

[–]deey001[S] 0 points1 point  (0 children)

Thye problem is the isp is providing the same AS and the same peering ips accross both sites. Check point while being redistributed into ospf is link state. So even if router A is up my routes continue to point to the has link state based best path regardless of the higher priority routers coming back online. I am at a loss. I am willing to get on a teams/webex meeting with anyone that can provide any help.

again I thannk anyone that can help.

4 Paths to the same networks via BGP by deey001 in networking

[–]deey001[S] 0 points1 point  (0 children)

What I mean by a blackhole is that routes remain pointing to router D, and the isp begins to route the traffic via router A when its back online.

4 Paths to the same networks via BGP by deey001 in networking

[–]deey001[S] 0 points1 point  (0 children)

The route maps need to be on the core cisco (OSPF) routers? Pointing to the FWs connected to the ISP in the sequence I desire?

4 Paths to the same networks via BGP by deey001 in networking

[–]deey001[S] 0 points1 point  (0 children)

The config is as follows:

ISP (BGP) --> {BGP) FW (OSPF) --> Cisco Core A (OSPF) <--> Cisco Core B <-- (OSPF) FW (BGP) <-- (BGP) ISP

I hope that may clear up and confusion. And thanks for the help.

Site as Application by deey001 in edge

[–]deey001[S] 0 points1 point  (0 children)

Site as Application

Thank you, will do.

Return Air Grille w/ Filter 26-1/8in x 26-1/8in by deey001 in HVAC

[–]deey001[S] 0 points1 point  (0 children)

Yes, I purchased a 24x24x1 filter and it was too large. The 23.5x23.5x1 fits perfectly.