<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Subsecond failover with active/passive firewalls running dynamic routing possible? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/subsecond-failover-with-active-passive-firewalls-running-dynamic/m-p/74660#M41747</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For OSPF, just enabled graceful restart !!&lt;/P&gt;
&lt;P&gt;PS: enable this feature also on the neighbor device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Graceful restart is also available for BGP but I have never tested it !!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HA&lt;/P&gt;</description>
    <pubDate>Mon, 14 Mar 2016 14:56:04 GMT</pubDate>
    <dc:creator>licenselu</dc:creator>
    <dc:date>2016-03-14T14:56:04Z</dc:date>
    <item>
      <title>Subsecond failover with active/passive firewalls running dynamic routing possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subsecond-failover-with-active-passive-firewalls-running-dynamic/m-p/74659#M41746</link>
      <description>&lt;P&gt;Has anyone been able to successfully get subsecond failovers to work with active/passive firewalls running dynamic routing protocols such as BGP or OSPF? &amp;nbsp;In our lab testing, it appears we can get the firewall to failover instantly, but then it takes BGP a few seconds to drop/re-establish. &amp;nbsp;Our next testing will be OSPF to see if that helps speed it up any. &amp;nbsp;But then we'd have to redistribute those routes into BGP (our core) which might introduce a few second gap. &amp;nbsp;So far testing failovers (manual failovers via the gui), while running BGP and pinging peer behind the FW, we drop several pings. &amp;nbsp;With static routes in place, the failover seems to happen quick enough that no pings drop. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've searched about every article on this site and tried about all the suggestions for faster failover, bgp timers, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On another note, would going active/active help this scenario? &amp;nbsp;The only main reason (other than link failures, firewall failures, etc.) I'd expect a failover would be for a firewall upgrade/maintenance. &amp;nbsp;Granted that will be done during a maintenance window if possible. &amp;nbsp;But we have some "custom" applications that might go offline and fail to our DR site if they loose connectivity for very long.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2016 13:33:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subsecond-failover-with-active-passive-firewalls-running-dynamic/m-p/74659#M41746</guid>
      <dc:creator>jmurphy</dc:creator>
      <dc:date>2016-03-14T13:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: Subsecond failover with active/passive firewalls running dynamic routing possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/subsecond-failover-with-active-passive-firewalls-running-dynamic/m-p/74660#M41747</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For OSPF, just enabled graceful restart !!&lt;/P&gt;
&lt;P&gt;PS: enable this feature also on the neighbor device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Graceful restart is also available for BGP but I have never tested it !!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HA&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2016 14:56:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/subsecond-failover-with-active-passive-firewalls-running-dynamic/m-p/74660#M41747</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2016-03-14T14:56:04Z</dc:date>
    </item>
  </channel>
</rss>

