<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BGP sessions reset or not - Active-Standby HA in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/bgp-sessions-reset-or-not-active-standby-ha/m-p/997405#M5196</link>
    <description>&lt;P&gt;Hi Jase&lt;/P&gt;
&lt;P&gt;1. after a failover BGP needs to re-establish neighborship&lt;/P&gt;
&lt;P&gt;2. the RIB is not synced, the FIB is synced over HA1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchronization" target="_blank"&gt;Reference: HA Synchronization&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Dec 2024 09:18:57 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2024-12-10T09:18:57Z</dc:date>
    <item>
      <title>BGP sessions reset or not - Active-Standby HA</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/bgp-sessions-reset-or-not-active-standby-ha/m-p/997115#M5186</link>
      <description>&lt;P&gt;Hello All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a few BGP related questions regarding Palo Alto Network firewalls HA active-standby setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scenario:&lt;/P&gt;&lt;P&gt;* eBGP to internal/trust network&lt;/P&gt;&lt;P&gt;* static default route for WAN/untrust side&lt;/P&gt;&lt;P&gt;* floating IPs are used&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Qs:&lt;/P&gt;&lt;P&gt;1. During failover, is the the BGP session state re-established on the passive firewall?&amp;nbsp;That is, the BGP session is not synced over HA1 (control plane) to the standby (new 'active').&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2: I guess BGP routing table (RIB) is synced over HA1 and BGP graceful restart can help maintain the FIB (i.e. best routes are not withdrawn from FIB of standby firewall that is the new 'active') ? Please confirm.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance community.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jase&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2024 23:48:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/bgp-sessions-reset-or-not-active-standby-ha/m-p/997115#M5186</guid>
      <dc:creator>Retr0_Jase</dc:creator>
      <dc:date>2024-12-08T23:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: BGP sessions reset or not - Active-Standby HA</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/bgp-sessions-reset-or-not-active-standby-ha/m-p/997405#M5196</link>
      <description>&lt;P&gt;Hi Jase&lt;/P&gt;
&lt;P&gt;1. after a failover BGP needs to re-establish neighborship&lt;/P&gt;
&lt;P&gt;2. the RIB is not synced, the FIB is synced over HA1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchronization" target="_blank"&gt;Reference: HA Synchronization&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 09:18:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/bgp-sessions-reset-or-not-active-standby-ha/m-p/997405#M5196</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-12-10T09:18:57Z</dc:date>
    </item>
  </channel>
</rss>

