<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to inject OSPF information from PA to other OSPF-Routers in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48901#M36009</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We cannot disable these messages, as they are notifications about OSPF state changes. If you are seeing these messages frequently, then it appears that the adjacency on eth1/xx is flapping, and can introduce instability in the OSPF domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; Verify if the Link itself is not flapping&lt;/P&gt;&lt;P&gt;2) Verify if there is no MTU mismatch on the interfaces ( If there is a mismatch in the interface MTU, the OSPF states wouldnt go beyond Exstart )&lt;/P&gt;&lt;P&gt;3) Ensure that you have a policy to permit OSPF for the zone on which eth1/xx is configured on &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Aug 2013 13:30:41 GMT</pubDate>
    <dc:creator>kprakash</dc:creator>
    <dc:date>2013-08-12T13:30:41Z</dc:date>
    <item>
      <title>How to inject OSPF information from PA to other OSPF-Routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48891#M35999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we created a IPSec tunnel between Cisco and PA:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="overview.jpg" class="jive-image-thumbnail jive-image" height="339" src="https://live.paloaltonetworks.com/legacyfs/online/7111_overview.jpg" width="682" /&gt;&lt;/P&gt;&lt;P&gt;Now we have a problem to make the network behind the Cisco Router reachable from the Corporate LAN and the other way (from Corporate LAN to the "Cisco LAN"). Both routers running OSPF. With OSPF we want to make this networks reachable through the PA. The PA already gets the OSPF informations from both Routers and &lt;SPAN style="text-decoration: underline;"&gt;is able to inject the "connected" network&lt;/SPAN&gt; (setting image ospf9.jpg) to the OSPF network. &lt;SPAN style="text-decoration: underline;"&gt;But the OSPF routing information itself not.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need your help. Did we missed a configuration? How does it work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please take a look at the attached files... Thanks a lot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 08:24:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48891#M35999</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2013-06-26T08:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to inject OSPF information from PA to other OSPF-Routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48892#M36000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try using the actual subnets (eg : 192.168.1.0/24)&amp;nbsp; in the Destination field instead of the interfaces (ospf-9)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 10:55:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48892#M36000</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-06-26T10:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to inject OSPF information from PA to other OSPF-Routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48893#M36001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did the change like you said:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ospf-new1.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7112_ospf-new1.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it doesn't work. Still able to reach the tunnel subnet but not the network behind the router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 11:13:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48893#M36001</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2013-06-26T11:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to inject OSPF information from PA to other OSPF-Routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48894#M36002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hithead,&lt;/P&gt;&lt;P&gt;I have some recommendations for you:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) First of all, if you want to learn the routes via OSPF, then we&amp;nbsp; enable OSPF on the interfaces of the devices. We have OSPF configured on tunnel.2 and on eth1/2.1.&amp;nbsp; From the screenshots on OSPF-1 and OSPF-2, we can see that the PANFW is learning the routes 10.xx.0.0/26 through the tunnel.2 interface and the 192, the 172 and the 10 networks on the eth1/2.1 interface. You can increase the metric of the static routes to prefer the link state routes over the static routes. &lt;/P&gt;&lt;P&gt;2) I see that the OSPF routes are being learnt, but just to be sure, have an "any any" permitting policy for OSPF application.&lt;/P&gt;&lt;P&gt;3) on ospf-4, I see that the tunnel.2 is seen as a BDR. Tunnel interfaces are always point to point. Change the interface link type to "point-to-point" and also change it on the tunnel interface of the cisco router.&lt;/P&gt;&lt;P&gt;4) You dont redistribute an OSPF route into OSPF, like we have on the screenshots of OSPF-7 and OSPF-8. All you need is to configure the interfaces with OSPF, which we have done. I see that the tunnel.2 is on area0 and eth1/2.1 is on area x. Likewise, we dont need redistribution of inter area routes. It is automatically done by OSPF&lt;/P&gt;&lt;P&gt;5) We dont have to resdistribute the connected routes into OSPF. The participating interfaces would advertise their network addresses,and also the networks reachable on them into OSPF by default.&lt;/P&gt;&lt;P&gt;6) When you mean you can reach the tunnel subnet, I see that you are attempting to reach networks on the remote lan. Can you verify if the routing is configured correctly on the remote end routers.&lt;/P&gt;&lt;P&gt;7) After having verified all these steps, if we still cannot get it to work, please open a case with us.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and best regards,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 13:34:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48894#M36002</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-06-26T13:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to inject OSPF information from PA to other OSPF-Routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48895#M36003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the check list. Now we got OSPF. But not completely:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ospf-works.jpg" class="jive-image-thumbnail jive-image" height="256" src="https://live.paloaltonetworks.com/legacyfs/online/7129_ospf-works.jpg" width="524" /&gt;&lt;/P&gt;&lt;P&gt;You see, the cisco router and the "OSPF Router" at the same network as the PA gets the OSPF information. But the PA (or OSPF Router - vendor Cisco) do not forward the OSPF information to e.g. LAN B (we have several subnets).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 11:15:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48895#M36003</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2013-06-27T11:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to inject OSPF information from PA to other OSPF-Routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48896#M36004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...The OSPF router that connect to LANB is responsible for route advertisement to other OSPF neighbors in LANB.&amp;nbsp; Please check the configuration of the OSPF router and review its neighbor's stats.&amp;nbsp; Thanks.,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 13:39:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48896#M36004</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2013-06-27T13:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to inject OSPF information from PA to other OSPF-Routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48897#M36005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you verify if the interface on the router on LAN-B is not configured as a passive interface for OSPF, oe doenst have any wierd access list that is blocking the advertisement of the network? We can see that the PANFW is learning the routes via OSPF from its neighbours OSPF router and Cisco router. If its just one network, ie the LAN B, that the firewall isnt getting routing information for, we have to check the settings on the firewall on LAN B&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 14:51:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48897#M36005</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-06-27T14:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to inject OSPF information from PA to other OSPF-Routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48898#M36006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i guess its a Cisco Router problem. Have to test it. Will update this thread, when we found the issue. Thanks for your help...!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jul 2013 14:06:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48898#M36006</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2013-07-18T14:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to inject OSPF information from PA to other OSPF-Routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48899#M36007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;finally we got the right configuration to inject OPSF information in our LAN from the remote station. I'd like to share you the configuration we did:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="works3ospf.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7639_works3ospf.JPG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="works2ospf.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7640_works2ospf.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="works1ospf.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7637_works1ospf.jpg" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Aug 2013 06:35:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48899#M36007</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2013-08-12T06:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to inject OSPF information from PA to other OSPF-Routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48900#M36008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With this configuration we get this system message from the PA: &lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;domain: 1&lt;/P&gt;&lt;P&gt;actionflags: 0x0&lt;/P&gt;&lt;P&gt;type: SYSTEM&lt;/P&gt;&lt;P&gt;subtype: routing&lt;/P&gt;&lt;P&gt;config_ver: 0&lt;/P&gt;&lt;P&gt;vsys: &lt;/P&gt;&lt;P&gt;eventid: routed-OSPF-neighbor-down&lt;/P&gt;&lt;P&gt;object: ROSEN_LAN&lt;/P&gt;&lt;P&gt;fmt: 0&lt;/P&gt;&lt;P&gt;id: 0&lt;/P&gt;&lt;P&gt;module: general&lt;/P&gt;&lt;P&gt;severity: high&lt;/P&gt;&lt;P&gt;opaque: &lt;STRONG&gt;OSPF adjacency with neighbor has gone down. interface ethernet1/XX&lt;/STRONG&gt;,&lt;BR /&gt;neighbor router ID 10.XXXXXX, neighbor IP address 10.XXXXXX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can we fix or disable this message?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Aug 2013 06:39:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48900#M36008</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2013-08-12T06:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to inject OSPF information from PA to other OSPF-Routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48901#M36009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We cannot disable these messages, as they are notifications about OSPF state changes. If you are seeing these messages frequently, then it appears that the adjacency on eth1/xx is flapping, and can introduce instability in the OSPF domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; Verify if the Link itself is not flapping&lt;/P&gt;&lt;P&gt;2) Verify if there is no MTU mismatch on the interfaces ( If there is a mismatch in the interface MTU, the OSPF states wouldnt go beyond Exstart )&lt;/P&gt;&lt;P&gt;3) Ensure that you have a policy to permit OSPF for the zone on which eth1/xx is configured on &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Aug 2013 13:30:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-inject-ospf-information-from-pa-to-other-ospf-routers/m-p/48901#M36009</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-12T13:30:41Z</dc:date>
    </item>
  </channel>
</rss>

