<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OSPF Link State Database Overload Protection for Palo Alto Firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-link-state-database-overload-protection-for-palo-alto/m-p/99623#M44197</link>
    <description>&lt;P&gt;Unfortunately, this parameter is not availabe in the current PanOS releases. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can discuss with your sales engineer either adding a feature request for a future release or if one alreadly exists adding your company vote for the feature.&lt;/P&gt;</description>
    <pubDate>Sat, 23 Jul 2016 12:57:57 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2016-07-23T12:57:57Z</dc:date>
    <item>
      <title>OSPF Link State Database Overload Protection for Palo Alto Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-link-state-database-overload-protection-for-palo-alto/m-p/99381#M44177</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're migrating from a Cisco ASA to a Palo Alto firewall device. I had a query about the OSPF Link State Database Overload Protection for the Palo Alto Firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Cisco ASA firewall provides OSPF Link State Database Overload Protection using the &lt;STRONG&gt;max-lsa&lt;/STRONG&gt; command&lt;/P&gt;&lt;P&gt;Here is the Cisco reference: &lt;A href="http://www.cisco.com/c/en/us/td/docs/ios/12_0s/feature/guide/ospfopro.html" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/ios/12_0s/feature/guide/ospfopro.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;“To limit the number of nonself-generated link-state advertisements (LSAs) that an Open Shortest Path First (OSPF) routing process can keep in the OSPF link-state database (LSDB), use the max-lsa command in router configuration mode. To remove the limit of non self-generated LSAs that an OSPF routing process can keep in the OSPF LSDB, use the no form of this command.”&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could not find the equivalent protection in a Palo Alto firewall&lt;/P&gt;&lt;P&gt;Please could you let me know&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;How I can configure OSPF Link State database overload protection from the web interface?&lt;/LI&gt;&lt;LI&gt;What is the equivalent command/CLI entry for this?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is my existing Palo Alto Configuration&lt;/P&gt;&lt;P&gt;=====================&lt;/P&gt;&lt;P&gt;&amp;lt;ospf&amp;gt;&lt;BR /&gt;&amp;lt;enable&amp;gt;yes&amp;lt;/enable&amp;gt;&lt;BR /&gt;&amp;lt;area&amp;gt;&lt;BR /&gt;&amp;lt;entry name="0.0.0.0"&amp;gt;&lt;BR /&gt;&amp;lt;interface&amp;gt;&lt;BR /&gt;&amp;lt;entry name="ethernet1/11"&amp;gt;&lt;BR /&gt;&amp;lt;enable&amp;gt;yes&amp;lt;/enable&amp;gt;&lt;BR /&gt;&amp;lt;passive&amp;gt;no&amp;lt;/passive&amp;gt;&lt;BR /&gt;&amp;lt;gr-delay&amp;gt;10&amp;lt;/gr-delay&amp;gt;&lt;BR /&gt;&amp;lt;metric&amp;gt;1000&amp;lt;/metric&amp;gt;&lt;BR /&gt;&amp;lt;priority&amp;gt;1&amp;lt;/priority&amp;gt;&lt;BR /&gt;&amp;lt;hello-interval&amp;gt;10&amp;lt;/hello-interval&amp;gt;&lt;BR /&gt;&amp;lt;dead-counts&amp;gt;4&amp;lt;/dead-counts&amp;gt;&lt;BR /&gt;&amp;lt;retransmit-interval&amp;gt;5&amp;lt;/retransmit-interval&amp;gt;&lt;BR /&gt;&amp;lt;transit-delay&amp;gt;1&amp;lt;/transit-delay&amp;gt;&lt;BR /&gt;&amp;lt;link-type&amp;gt;&lt;BR /&gt;&amp;lt;broadcast/&amp;gt;&lt;BR /&gt;&amp;lt;/link-type&amp;gt;&lt;BR /&gt;&amp;lt;/entry&amp;gt;&lt;BR /&gt;&amp;lt;entry name="ethernet1/12"&amp;gt;&lt;BR /&gt;&amp;lt;enable&amp;gt;yes&amp;lt;/enable&amp;gt;&lt;BR /&gt;&amp;lt;passive&amp;gt;no&amp;lt;/passive&amp;gt;&lt;BR /&gt;&amp;lt;gr-delay&amp;gt;10&amp;lt;/gr-delay&amp;gt;&lt;BR /&gt;&amp;lt;metric&amp;gt;1000&amp;lt;/metric&amp;gt;&lt;BR /&gt;&amp;lt;priority&amp;gt;1&amp;lt;/priority&amp;gt;&lt;BR /&gt;&amp;lt;hello-interval&amp;gt;10&amp;lt;/hello-interval&amp;gt;&lt;BR /&gt;&amp;lt;dead-counts&amp;gt;4&amp;lt;/dead-counts&amp;gt;&lt;BR /&gt;&amp;lt;retransmit-interval&amp;gt;5&amp;lt;/retransmit-interval&amp;gt;&lt;BR /&gt;&amp;lt;transit-delay&amp;gt;1&amp;lt;/transit-delay&amp;gt;&lt;BR /&gt;&amp;lt;link-type&amp;gt;&lt;BR /&gt;&amp;lt;broadcast/&amp;gt;&lt;BR /&gt;&amp;lt;/link-type&amp;gt;&lt;BR /&gt;&amp;lt;/entry&amp;gt;&lt;BR /&gt;&amp;lt;entry name="loopback"&amp;gt;&lt;BR /&gt;&amp;lt;enable&amp;gt;yes&amp;lt;/enable&amp;gt;&lt;BR /&gt;&amp;lt;passive&amp;gt;yes&amp;lt;/passive&amp;gt;&lt;BR /&gt;&amp;lt;gr-delay&amp;gt;10&amp;lt;/gr-delay&amp;gt;&lt;BR /&gt;&amp;lt;metric&amp;gt;1000&amp;lt;/metric&amp;gt;&lt;BR /&gt;&amp;lt;priority&amp;gt;1&amp;lt;/priority&amp;gt;&lt;BR /&gt;&amp;lt;hello-interval&amp;gt;10&amp;lt;/hello-interval&amp;gt;&lt;BR /&gt;&amp;lt;dead-counts&amp;gt;4&amp;lt;/dead-counts&amp;gt;&lt;BR /&gt;&amp;lt;retransmit-interval&amp;gt;5&amp;lt;/retransmit-interval&amp;gt;&lt;BR /&gt;&amp;lt;transit-delay&amp;gt;1&amp;lt;/transit-delay&amp;gt;&lt;BR /&gt;&amp;lt;link-type&amp;gt;&lt;BR /&gt;&amp;lt;broadcast/&amp;gt;&lt;BR /&gt;&amp;lt;/link-type&amp;gt;&lt;BR /&gt;&amp;lt;/entry&amp;gt;&lt;BR /&gt;&amp;lt;entry name="ae2"&amp;gt;&lt;BR /&gt;&amp;lt;enable&amp;gt;yes&amp;lt;/enable&amp;gt;&lt;BR /&gt;&amp;lt;passive&amp;gt;yes&amp;lt;/passive&amp;gt;&lt;BR /&gt;&amp;lt;gr-delay&amp;gt;10&amp;lt;/gr-delay&amp;gt;&lt;BR /&gt;&amp;lt;metric&amp;gt;10&amp;lt;/metric&amp;gt;&lt;BR /&gt;&amp;lt;priority&amp;gt;1&amp;lt;/priority&amp;gt;&lt;BR /&gt;&amp;lt;hello-interval&amp;gt;10&amp;lt;/hello-interval&amp;gt;&lt;BR /&gt;&amp;lt;dead-counts&amp;gt;4&amp;lt;/dead-counts&amp;gt;&lt;BR /&gt;&amp;lt;retransmit-interval&amp;gt;5&amp;lt;/retransmit-interval&amp;gt;&lt;BR /&gt;&amp;lt;transit-delay&amp;gt;1&amp;lt;/transit-delay&amp;gt;&lt;BR /&gt;&amp;lt;link-type&amp;gt;&lt;BR /&gt;&amp;lt;broadcast/&amp;gt;&lt;BR /&gt;&amp;lt;/link-type&amp;gt;&lt;BR /&gt;&amp;lt;/entry&amp;gt;&lt;BR /&gt;&amp;lt;/interface&amp;gt;&lt;BR /&gt;&amp;lt;type&amp;gt;&lt;BR /&gt;&amp;lt;normal/&amp;gt;&lt;BR /&gt;&amp;lt;/type&amp;gt;&lt;BR /&gt;&amp;lt;/entry&amp;gt;&lt;BR /&gt;&amp;lt;/area&amp;gt;&lt;BR /&gt;&amp;lt;router-id&amp;gt;10.1.1.1&amp;lt;/router-id&amp;gt;&lt;BR /&gt;&amp;lt;/ospf&amp;gt;&lt;BR /&gt;&amp;lt;ospfv3&amp;gt;&lt;BR /&gt;&amp;lt;enable&amp;gt;no&amp;lt;/enable&amp;gt;&lt;BR /&gt;&amp;lt;/ospfv3&amp;gt;&lt;/P&gt;&lt;P&gt;=====================&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2016 07:50:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-link-state-database-overload-protection-for-palo-alto/m-p/99381#M44177</guid>
      <dc:creator>mskpalo</dc:creator>
      <dc:date>2016-07-22T07:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Link State Database Overload Protection for Palo Alto Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-link-state-database-overload-protection-for-palo-alto/m-p/99623#M44197</link>
      <description>&lt;P&gt;Unfortunately, this parameter is not availabe in the current PanOS releases. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can discuss with your sales engineer either adding a feature request for a future release or if one alreadly exists adding your company vote for the feature.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2016 12:57:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-link-state-database-overload-protection-for-palo-alto/m-p/99623#M44197</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-07-23T12:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Link State Database Overload Protection for Palo Alto Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-link-state-database-overload-protection-for-palo-alto/m-p/99643#M44201</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9524"&gt;@pulukas﻿&lt;/a&gt; for the reply. Are there any other features we could implement to secure the OSPF Link State Database in Palo Alto Firewalls?&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2016 20:14:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-link-state-database-overload-protection-for-palo-alto/m-p/99643#M44201</guid>
      <dc:creator>mskpalo</dc:creator>
      <dc:date>2016-07-23T20:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Link State Database Overload Protection for Palo Alto Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-link-state-database-overload-protection-for-palo-alto/m-p/99669#M44204</link>
      <description>&lt;P&gt;If the primary concern is security, you can use md5 authentication for the neighbor relationships.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-OSPF-Authentication/ta-p/52330" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-OSPF-Authentication/ta-p/52330&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jul 2016 17:05:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-link-state-database-overload-protection-for-palo-alto/m-p/99669#M44204</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-07-24T17:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Link State Database Overload Protection for Palo Alto Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-link-state-database-overload-protection-for-palo-alto/m-p/99683#M44210</link>
      <description>&lt;P&gt;Thanks a lot for the support&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jul 2016 22:43:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-link-state-database-overload-protection-for-palo-alto/m-p/99683#M44210</guid>
      <dc:creator>mskpalo</dc:creator>
      <dc:date>2016-07-24T22:43:32Z</dc:date>
    </item>
  </channel>
</rss>

