<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic OSPF through Vwire in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-through-vwire/m-p/67886#M39709</link>
    <description>&lt;P&gt;I attempted to install a PA5060 between a Cisco ASA and Cisco Nexus switch in vwire mode. the ASA has an OSPF neighbor with the nexus 7k to distribute the defualt route learned via BGP from the ISP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once the 5060 was installed, the OSPF neigbor came up but the routes were not exchanged. in the logs I see the traffic as allowed and the application as OSPF.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any other configuration needed? I see in the following article that multicast traffic is allowed by defualt in vwire.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Block-Multicast-Traffic-in-a-VWire-Virtual-Wire-Setup/ta-p/55877" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Block-Multicast-Traffic-in-a-VWire-Virtual-Wire-Setup/ta-p/55877&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The PA-5060 is running 7.0.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All other traffic was working. I could ping across the vwire but the routes were not there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks,&lt;/P&gt;
&lt;P&gt;Nathan&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Nov 2015 01:01:48 GMT</pubDate>
    <dc:creator>Nathan.McCart</dc:creator>
    <dc:date>2015-11-10T01:01:48Z</dc:date>
    <item>
      <title>OSPF through Vwire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-through-vwire/m-p/67886#M39709</link>
      <description>&lt;P&gt;I attempted to install a PA5060 between a Cisco ASA and Cisco Nexus switch in vwire mode. the ASA has an OSPF neighbor with the nexus 7k to distribute the defualt route learned via BGP from the ISP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once the 5060 was installed, the OSPF neigbor came up but the routes were not exchanged. in the logs I see the traffic as allowed and the application as OSPF.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any other configuration needed? I see in the following article that multicast traffic is allowed by defualt in vwire.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Block-Multicast-Traffic-in-a-VWire-Virtual-Wire-Setup/ta-p/55877" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Block-Multicast-Traffic-in-a-VWire-Virtual-Wire-Setup/ta-p/55877&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The PA-5060 is running 7.0.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All other traffic was working. I could ping across the vwire but the routes were not there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks,&lt;/P&gt;
&lt;P&gt;Nathan&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 01:01:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-through-vwire/m-p/67886#M39709</guid>
      <dc:creator>Nathan.McCart</dc:creator>
      <dc:date>2015-11-10T01:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF through Vwire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-through-vwire/m-p/67912#M39722</link>
      <description>&lt;P&gt;Hi there...Did you include security rule(s) to allow OSPF traffic in both directions across the vwire? &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 19:43:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-through-vwire/m-p/67912#M39722</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2015-11-10T19:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF through Vwire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-through-vwire/m-p/67917#M39725</link>
      <description>&lt;P&gt;yes I have security policies allowing all traffic both ways.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 20:39:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-through-vwire/m-p/67917#M39725</guid>
      <dc:creator>Nathan.McCart</dc:creator>
      <dc:date>2015-11-10T20:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF through Vwire</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-through-vwire/m-p/67918#M39726</link>
      <description>&lt;P&gt;You can turn on packet capture on the PA device and filter on the OSPF multicast to see what's happening to the packets. &amp;nbsp;Set the pcap to capture at all 4 stages: TX, RX, DROP and FIREWALL. &amp;nbsp;That should provide information to help pinpoint the issue. &amp;nbsp;Thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 20:44:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-through-vwire/m-p/67918#M39726</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2015-11-10T20:44:03Z</dc:date>
    </item>
  </channel>
</rss>

