<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BFP with OSPF graceful restart causing outages during failover in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/bfp-with-ospf-graceful-restart-causing-outages-during-failover/m-p/1235206#M6151</link>
    <description>&lt;P&gt;Dear community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In a active/passive configuration with OSPF graceful restart and BFD enabled, when we do failover we experience a&lt;SPAN&gt;&amp;nbsp;downtime 1 minute after the failover and it takes about 10 seconds to be fixed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Checking the logs it looks like the firewall builds the new BFD sessions with the core switch, but after 1 minute after the failover the FW rejects the BFD sessions and rebuild them.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-&amp;gt; Is this a normal behavior??&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Fortinet recommends not to use graceful restart with BFD for both OSPF and BGP.&lt;BR /&gt;&lt;A href="https://community.fortinet.com/t5/FortiGate/Technical-Tip-BFD-with-Graceful-Restart-on-FortiGate/ta-p/247154" target="_blank"&gt;https://community.fortinet.com/t5/FortiGate/Technical-Tip-BFD-with-Graceful-Restart-on-FortiGate/ta-p/247154&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Palo Alto only recommends not to use it with BGP but I couldn´t find any reference to OSPF:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/bfd/bfd-overview/bfd-for-dynamic-routing-protocols#id9d612915-3bfe-42ef-927f-b0ec260b9a5f" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/bfd/bfd-overview/bfd-for-dynamic-routing-protocols#id9d612915-3bfe-42ef-927f-b0ec260b9a5f&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 01 Aug 2025 11:58:25 GMT</pubDate>
    <dc:creator>Carracido</dc:creator>
    <dc:date>2025-08-01T11:58:25Z</dc:date>
    <item>
      <title>BFP with OSPF graceful restart causing outages during failover</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/bfp-with-ospf-graceful-restart-causing-outages-during-failover/m-p/1235206#M6151</link>
      <description>&lt;P&gt;Dear community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In a active/passive configuration with OSPF graceful restart and BFD enabled, when we do failover we experience a&lt;SPAN&gt;&amp;nbsp;downtime 1 minute after the failover and it takes about 10 seconds to be fixed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Checking the logs it looks like the firewall builds the new BFD sessions with the core switch, but after 1 minute after the failover the FW rejects the BFD sessions and rebuild them.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-&amp;gt; Is this a normal behavior??&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Fortinet recommends not to use graceful restart with BFD for both OSPF and BGP.&lt;BR /&gt;&lt;A href="https://community.fortinet.com/t5/FortiGate/Technical-Tip-BFD-with-Graceful-Restart-on-FortiGate/ta-p/247154" target="_blank"&gt;https://community.fortinet.com/t5/FortiGate/Technical-Tip-BFD-with-Graceful-Restart-on-FortiGate/ta-p/247154&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Palo Alto only recommends not to use it with BGP but I couldn´t find any reference to OSPF:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/bfd/bfd-overview/bfd-for-dynamic-routing-protocols#id9d612915-3bfe-42ef-927f-b0ec260b9a5f" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/bfd/bfd-overview/bfd-for-dynamic-routing-protocols#id9d612915-3bfe-42ef-927f-b0ec260b9a5f&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2025 11:58:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/bfp-with-ospf-graceful-restart-causing-outages-during-failover/m-p/1235206#M6151</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2025-08-01T11:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: BFP with OSPF graceful restart causing outages during failover</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/bfp-with-ospf-graceful-restart-causing-outages-during-failover/m-p/1235345#M6155</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The conflict between Graceful Restart (GR) and Bidirectional Forwarding Detection (BFD) is an architectural issue that applies to any dynamic routing protocol. It is not specific to OSPF or BGP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem arises during an HA failover or any event that causes a brief disruption. BFD, being extremely fast, will detect the disruption and tear down the session with the peer device.&amp;nbsp;&lt;SPAN class="citation-30 citation-end-30"&gt;This rapid action from BFD overrides the slower process of Graceful Restart.&lt;/SPAN&gt;&amp;nbsp;This can lead to the routing tables being flushed and an extended outage, exactly as you described&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In summary, the problem is not tied to the specific routing protocol (OSPF, BGP, etc.) but rather to the conflicting nature of BFD and GR. They are designed for different types of failures, and when both are active, BFD's speed typically overrides GR's grace period, leading to the kind of extended downtime you are seeing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2025 11:49:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/bfp-with-ospf-graceful-restart-causing-outages-during-failover/m-p/1235345#M6155</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-08-04T11:49:01Z</dc:date>
    </item>
  </channel>
</rss>

