<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OSPF between virtual routers in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-between-virtual-routers/m-p/63382#M38150</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've done this a few time with both BGP and OSPF, but always with having the traffic physically leaving the firewall like you say.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's usually been scenarios with multiple vsys, with OSPF/BGP needed between VRs in different vsys's. This has been stable and worked as expected. With a multi-vsys environment, I think it makes sense to have the traffic leave the device, as there are some throughput limitations on inter-vsys routing, and you would have one session pr vsys for each "session" anyway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Never tried exactly the same scenario as you are describing though. Not sure if I would trust the routing functionally in Palo Alto enough to do that anyway. Have seen some strange bugs related to ospf in previous releases. But if you manage to get it working, it would be nice to know how &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Tor&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Aug 2015 10:12:12 GMT</pubDate>
    <dc:creator>torm</dc:creator>
    <dc:date>2015-08-20T10:12:12Z</dc:date>
    <item>
      <title>OSPF between virtual routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-between-virtual-routers/m-p/63380#M38148</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to run OSPF between 2 virtual routers on a single PaloAlto device?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since you need to have an interconnecting interface, I guess you need to have the traffic physically leave the firewall and come back in on another port in the other vr; and then use that interface as routing subnet to talk OSPF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I was wondering of it is also possible to do this internally? Just between the two VRs.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I found a related article for BGP pering using loopback Ips:&amp;nbsp;&lt;A title="BGP-Peering-Between-Virtual-Routers" href="https://live.paloaltonetworks.com/t5/Articles/BGP-Peering-Between-Virtual-Routers/tac-p/63359" target="_blank"&gt;BGP-Peering-Between-Virtual-Routers&lt;/A&gt;&lt;BR /&gt;But this does not seems to work with OSPF (ERROR: In virtual-router IPS1-vr, only OSPFv2 passive mode can be supported on interface loopback.1 in area 0.0.0.0).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Anybody have any experience with this, or any ways around this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2015 09:35:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-between-virtual-routers/m-p/63380#M38148</guid>
      <dc:creator>mr.linus</dc:creator>
      <dc:date>2015-08-20T09:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF between virtual routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-between-virtual-routers/m-p/63382#M38150</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've done this a few time with both BGP and OSPF, but always with having the traffic physically leaving the firewall like you say.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's usually been scenarios with multiple vsys, with OSPF/BGP needed between VRs in different vsys's. This has been stable and worked as expected. With a multi-vsys environment, I think it makes sense to have the traffic leave the device, as there are some throughput limitations on inter-vsys routing, and you would have one session pr vsys for each "session" anyway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Never tried exactly the same scenario as you are describing though. Not sure if I would trust the routing functionally in Palo Alto enough to do that anyway. Have seen some strange bugs related to ospf in previous releases. But if you manage to get it working, it would be nice to know how &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Tor&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2015 10:12:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-between-virtual-routers/m-p/63382#M38150</guid>
      <dc:creator>torm</dc:creator>
      <dc:date>2015-08-20T10:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF between virtual routers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-between-virtual-routers/m-p/63480#M38190</link>
      <description>&lt;P&gt;I've done it with BGP.&amp;nbsp; I use a physical interface IP (or subinterface IP) on each virtual router and peer between the two.&amp;nbsp; This way the traffic does not leave the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;interface e 1/1 has IP 10.10.10.1/30 in VR1&lt;/P&gt;&lt;P&gt;interface e 1/2 has IP 10.10.11.1/30 in VR2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In VR1, set a static route pointing 10.10.11.1/30 to "next vr" VR2.&amp;nbsp; In VR2 do the same with a static route pointing 10.10.10.1/30 to "next vr" VR1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After that you can configure the BGP peering.&amp;nbsp; Make sure to use iBGP and the "export next hop" as "use self".&amp;nbsp; You'll have to set import and export rules up.&amp;nbsp; Export rules in VR1 to set what gets advertised to VR2, and then a matching import rule in VR2 to accept only those exports from VR1.&amp;nbsp; And the other way around to get a two-way route exchange.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Going from zone to zone you're going to need a gateway protocol.&amp;nbsp; I don't think OSPF will work like this.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2015 20:31:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-between-virtual-routers/m-p/63480#M38190</guid>
      <dc:creator>howardtopher</dc:creator>
      <dc:date>2015-08-21T20:31:33Z</dc:date>
    </item>
  </channel>
</rss>

