<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall tries to close a BGP/TCP connection with switch in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-tries-to-close-a-bgp-tcp-connection-with-switch/m-p/498290#M158</link>
    <description>&lt;P&gt;&lt;BR /&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; The following problem involves a firewall (10.249.0.13) wanting to close a BGP connection with its neighboring switch (10.249.0.14).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The switch answers with a BGP NOTIFICATION message that contains 'No supported AFI/SAFI'. (separate issue) The firewall then sends a FIN to the switch to close the TCP connection. Follows a series of FIN retransmissions from the firewall and ACK retransmissions from the switch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to determine which side is not understanding here?&lt;/P&gt;
&lt;P&gt;I have included an excerpt of the .pcap.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.</description>
    <pubDate>Thu, 02 Jun 2022 14:08:32 GMT</pubDate>
    <dc:creator>FrancoisNoel</dc:creator>
    <dc:date>2022-06-02T14:08:32Z</dc:date>
    <item>
      <title>Firewall tries to close a BGP/TCP connection with switch</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-tries-to-close-a-bgp-tcp-connection-with-switch/m-p/498290#M158</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; The following problem involves a firewall (10.249.0.13) wanting to close a BGP connection with its neighboring switch (10.249.0.14).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The switch answers with a BGP NOTIFICATION message that contains 'No supported AFI/SAFI'. (separate issue) The firewall then sends a FIN to the switch to close the TCP connection. Follows a series of FIN retransmissions from the firewall and ACK retransmissions from the switch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to determine which side is not understanding here?&lt;/P&gt;
&lt;P&gt;I have included an excerpt of the .pcap.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.</description>
      <pubDate>Thu, 02 Jun 2022 14:08:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-tries-to-close-a-bgp-tcp-connection-with-switch/m-p/498290#M158</guid>
      <dc:creator>FrancoisNoel</dc:creator>
      <dc:date>2022-06-02T14:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall tries to close a BGP/TCP connection with switch</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-tries-to-close-a-bgp-tcp-connection-with-switch/m-p/498842#M159</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167567"&gt;@FrancoisNoel&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out. It looks like the switch sent a NOTIFICATION message because it detected an error with the BGP configuration between itself and the Palo. As a result, we see the termination of the adjacency.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The capture tells us there is a misconfiguration in either the switch or the palo.&amp;nbsp; Can you share the configs? Also, it would be helpful to see the full debug to see what AFI and SAFI numbers are being exchanged. For example, the Palo default uses an address class of IPv4 and so if your switch bgp config is set with an address class of IPv6 then that could be an issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="NGFW" id="NGFW"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2022 01:08:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewall-tries-to-close-a-bgp-tcp-connection-with-switch/m-p/498842#M159</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2022-06-03T01:08:05Z</dc:date>
    </item>
  </channel>
</rss>

