<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OSPF adjacency flapping - normal? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207043#M60735</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I think I might have gotten confused along the way somewhere. Would this a simplified representation of the nework between the distric and the schools?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 660px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14390i654CC9A9280A357D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If yes, then I think the setup is OK.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Mar 2018 22:48:59 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-03-22T22:48:59Z</dc:date>
    <item>
      <title>OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205468#M60324</link>
      <description>&lt;P&gt;While trying to track down the cause for 3 recent Internet outages we've experienced at one of our schools (which we still haven't determined the cause to yet), we've noticed that our OSPF adjacencies are flapping up and down across the district.&amp;nbsp; Multiple times per day, across multiple sites, going back to the beginning of last month (that's as far back as the logs go on the district core firewall).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this normal or something we should be concerned with?&amp;nbsp; Could this be the reason we get hiccups in our connections to the schools (where you can be typing in an SSH session and suddenly all the characters stop appearing for 10 seconds then appear slowly then appear normally again) when network usage for the school is fairly low?&amp;nbsp; Could this be the reason for 5-10 minute outages like we've experienced the past two days (nothing showing in the logs on the fibre switches, no links up/down, no STP outages, etc)?&amp;nbsp; Could this get to the point where our entire WAN goes down?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm very new to OSPF and routing protocols in general, coming from a static routing background dealing only with the connections on the "inside" of the telco router at a remote site (each site with their own connection to the Internet).&amp;nbsp; We've since migrated to a proper WAN setup using OSPF internally, with a single connection to the public Internet for the whole district.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our WAN consists of 3 separate networks that all terminate at the district office:&amp;nbsp; an MPLS link with the local telco for the out-of-town schools, a point-to-point fibre network in town, and a point-to-point wireless network for schools we can't reach with fibre yet.&amp;nbsp; For the MPLS links, the OSPF is established between&amp;nbsp;an L3 switch in the district office (upstream from the district firewall) and the PA firewall in the school.&amp;nbsp; For the fibre and wireless networks, the OSPF is established between the PA firewall in the district office and the PA firewall in the school (we use a layer 2 vlans across the fibre/wireless network terminating on the PA firewall).&amp;nbsp; Other than the Router ID, and neighbour config, the OSPF setup on all the firewalls is virtually identical (everything is in Area 0).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We haven't had any issues (that we know of) with the above setup, although we do understand that it's sub-optimal (we're looking at what it would take to have all of the OSPF links terminate on the L3 switch instead, such that the district firewall stops being a router too).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, should I be worried about the OSPF adjacencies flapping?&amp;nbsp; Should I spend time on figuring those out?&amp;nbsp; Or are they a red herring to some other issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most of the OSPF "outages" are under 10 seconds.&amp;nbsp; The only ones that are longer (3-5 minutes) are for the school that lost connectivity completely 3 times in the last two days (but, not sure if that's the cause or just a symptom).&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 21:07:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205468#M60324</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-14T21:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205480#M60325</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Are you referring to the following messages as flaps?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OSPF adjacency with neighbor has gone down. interface tunnel.XX, neighbor router ID 1.2.3.4, neighbor IP address 1.2.3.5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OSPF doesnt flap on its own. In my experience on single links such as yours, the reason is an actual link issue and not OSPF if your settings are default. To mititgate this we have two ways to get back to our data centers, P2P wan links, primary, and VPN tunnels over the internet to the datacenters. So each or our sites has 2 conections to its 'closest' data center and 1 to the remote one for additional redundancy. I have a 100M fiber link that is just for internet access at one of my sites, but it also does this, for a few seconds randomly it blips and used to down the site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 21:34:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205480#M60325</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-14T21:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205482#M60326</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;wrote:&lt;BR /&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Are you referring to the following messages as flaps?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OSPF adjacency with neighbor has gone down. interface tunnel.XX, neighbor router ID 1.2.3.4, neighbor IP address 1.2.3.5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes, these are the messages I'm seeing, multiple times per day, going back at least two months.&amp;nbsp; 3-10 seconds later will be a message that OSPF adjacency has been established again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wondering if these are normal, or something to be concerned with?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 21:39:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205482#M60326</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-14T21:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205485#M60328</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;In short yes, be concerened, but it might not be your config. What is the latency across the circuits? Are they ever full, i.e. 100% capacity? One thing you might try if the links are full or near capacity is to setup QoS and give priority to routing protocols, in this case OSPF, over all other traffic, even voice. If the circuits have low latency and are not near capacity, then I would call the provider and have them test circuits to verify.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you dont have monitoring software, you could download a free version and monitor the links with pings and watch drops/latency/jitter etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 21:46:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205485#M60328</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-14T21:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205493#M60333</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;We're the provider of the links.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use Ubiquiti point-to-point and point-to-multi-point wireless connections between schools, connecting back to a site with a fibre link, that connects back to the central office.&amp;nbsp; These are very low-latency links (generally under 5 ms, the longest link is 15 ms) and nowhere near saturated.&amp;nbsp; Most schools have dedicated 100 Mbps links with 30-50 Mbps usage; a handful of schools share a 700 Mbps link that shows under 200 Mbps usage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It could be that we're dropping packets on these wireless links, including the OSPF hello packets, which is causing the OSPF link to drop and re-establish.&amp;nbsp; If I'm reading the OSPF docs right, though, that would require a 40 second network outage (or really bad luck to drop the 4 hello packets without affecting other traffic).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would playing with the Hello Interval, Dead Counts, or similar timings make a difference in such an environment?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything is monitored via Nagios and LibreNMS, so we have graphs and alerts out the wazoo, but they aren't real-time (polling runs every 5 minutes and takes just about the full 5 minutes to query everything).&amp;nbsp; Nothing has been flagged as "bad", although we do get the odd jump to 200 ms latency to some sites, and the occasional jump to 10 % packet loss.&amp;nbsp; But that's every few days, not multiple times per day.&amp;nbsp; And rarely for more than 1 polling cycle.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or, is this barking up the wrong tree?&amp;nbsp; We need to look deeper into the Ubiquiti links, which will "fix" the OSPF issues running on top?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 22:18:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205493#M60333</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-14T22:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205500#M60337</link>
      <description>&lt;P&gt;As we are using layer 2 vlans between the district office and the remote school (vlan across the wireless links, too), would changing the OSPF Link Type from "broadcast" to "p2p" make a difference here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All of the schools use the same vlan and connect back to the same switch (that the district firewall is plugged into, with the vlans terminating on the firewall).&amp;nbsp; In essense, these are point-to-point links (the district firewall is the neighbour for each of the school firewalls).&amp;nbsp; Would using the default "broadcast" type with all the multicast packets going out to all the sites be an issue?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 22:26:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205500#M60337</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-14T22:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205503#M60338</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Sorry misread the provider part of it but yes, wireless can be 'exciting' :). If you are to change from the default values, just be careful and make the changes on the far side of the link first rather than the near/hub side as this can cause OSPF issues and potentially dropping routes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="List_1_outer"&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="List_1_inner"&gt;•&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="List_1_inner"&gt;&lt;SPAN class="uicontrol"&gt;Hello Interval (sec)&lt;/SPAN&gt;—Interval, in seconds, at which the OSPF process sends hello packets to its directly connected neighbors (range is 0-3600; default is 10).&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV class="List_1_outer"&gt;&lt;TABLE border="0" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="List_1_inner"&gt;•&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="List_1_inner"&gt;&lt;SPAN class="uicontrol"&gt;Dead Counts&lt;/SPAN&gt;—Number of times the hello interval can occur for a neighbor without OSPF receiving a hello packet from the neighbor, before OSPF considers that neighbor down. The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="uicontrol"&gt;Hello Interval&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;multiplied by the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="uicontrol"&gt;Dead Counts&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;equals the value of the dead timer (range is 3-20; default is 4).&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try increasing the Hello Interval to 20 from the default 10 and see if the issues still apear. This will take the Dead Count from 40 seconds to 80 seconds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This article uses Cisco but the concept is the same for any OSPF configuration:&lt;/P&gt;&lt;P&gt;&lt;A href="https://networklessons.com/ospf/ospf-hello-and-dead-interval/" target="_blank"&gt;https://networklessons.com/ospf/ospf-hello-and-dead-interval/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also check and see if you can setup QoS on both the PAN's and Ubiquity to see if you can prioritize the OSPF packets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 14 Mar 2018 22:34:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205503#M60338</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-14T22:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205505#M60339</link>
      <description>&lt;P&gt;So PAN would say that setting the Link type to P2P would be best since they are the only devices talking, however I have seen it work in broadcast without issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you can all the schools use the same vlan are you saying its one big flat vlan or each school has its own vlan ID and subnet ( I hope the latter for security)? Unless the Ubiquity is blocking some of the multicast packets, it shouldnt be an issue. But if you do make the change, makes ure its the far side first :).&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 22:40:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205505#M60339</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-14T22:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205508#M60340</link>
      <description>&lt;P&gt;We originally had each school on their own vlan and just did static routing from the district office through the fibre/wireless network.&amp;nbsp; Each school had their own public subnet and FreeBSD firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then we got migrated over to an MPLS network for all the schools terminating at the district office, with two /24 subnets for the entire district (each school gets 5-8 IPs distributed via OSPF).&amp;nbsp; The contrators that implemented that, including the initial installation and configuration of the Palo Alto firewalls, just mirrored the MPLS setup onto our vlan setup (1 MPLS tag for Internet traffic, 1 MPLS tag for in-district tech traffic, 1 MPLS tag for in-district management traffic became 1 vlan for Internet, 1 vlan for tech traffic, 1 vlan for management traffic).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So now we have 1 interface on the district firewall with 3 vlans terminated there.&amp;nbsp; That connects to a switch that distributes fibre links to the secondary schools, that connect to the Ubiquiti wireless dishes to connect the elementary schools.&amp;nbsp; And the 3 vlans are pushed through each of those links.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, yes, 1 "flat" vlan setup to all the schools on our private network.&amp;nbsp; With the firewalls in the schools handling all the traffic, security policies, NAT, etc.&amp;nbsp; With OSPF between the district firewall and the school firewalls.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 22:49:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/205508#M60340</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-14T22:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/206959#M60716</link>
      <description>&lt;P&gt;Okay, after some further digging and testing, it appears the OSPF setup we have may be sub-optimal, and cannot be (easily) switched to p2p/p2mp.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the MPLS side of things, the school firewall has a&amp;nbsp;separate /30 subnet for each of the vlans, and the telco router next to it is the neighbour (other end of the /30 subnet).&amp;nbsp; Then the telco does their magic in the MPLS "cloud".&amp;nbsp; The telco router in our data centre then has a /30 subnet on it for each vlan, with the district firewall being the OSPF neighbour, using the same /30 subnets for each vlan.&amp;nbsp; IOW, there's a 1 single IP/subnet on each firewall and router.&amp;nbsp; And they're basically directly connected via Ethernet patch cables.&amp;nbsp; So the school firewall sends a multicast/broadcast out one physical interface, to a directly-attached telco router.&amp;nbsp; And the district firewall sends a multicast/broadcast out one physical interface, to a directly-attached telco router.&amp;nbsp; And the telco routers do their magic behind the scenes to connect everything across the MPLS network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the fibre/wireless side of things, the contractor just emulated the same setup, making the district firewall take the place of the telco router, putting each of the /30 subnets from each school onto a single interface on the district firewall for the OSPF.&amp;nbsp; So the school firewalls are configured the same&amp;nbsp;as on the MPLS network&amp;nbsp;(1 /30 subnet for each vlan).&amp;nbsp; But the district firewall has&amp;nbsp;all of the /30 subnets for&amp;nbsp;all the schools on the same physical interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, the OSPF setup on the fibre/wireless network (which is basically a single flat layer 2 network with the same 3 vlans connecting the district firewall and&amp;nbsp;each of the school firewalls) is using multicast/broadcast across 84 separate subnets (28 schools x 3 vlans), to reach a neighbour that is logically 1 hop away.&amp;nbsp; This seems ... very sub-optimal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, moving to a (hopefully) better setup&amp;nbsp;would require modifying the OSPF setup on all the school firewalls, switching to using a single /24 private subnet to connect the firewalls on the fibre/wireless network, and using only a single IP on the district firewall for the OSPF interfaces.&amp;nbsp; Which means downtime for 28 schools simultaneously.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this a correct assumption?&amp;nbsp; Is this something that would be worthwhile pursuing, or is the current setup "okay"?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 17:45:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/206959#M60716</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-22T17:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207036#M60732</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Do all your PAN's see each other as OSPF neighbors or one from each school location to the&amp;nbsp;distric fw? If they are all enighbors, then I would really worry, if they are not and the distric fw is a neighbor to the rest of them, there could be minor tweaks but I dont think its the cause of your original issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW did increasing the hello timer help out?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 22:24:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207036#M60732</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-22T22:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207039#M60733</link>
      <description>&lt;P&gt;Each firewall sees only a single neighbour.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the telco network, the school firewalls only see the telco router as a neighbour, and the district firewall sees only the the telco router (via the Internet interface).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the fibre/wireless network, the school firewalls only see the district firewall as a neighbour, using their own /30 subnet.&amp;nbsp; The district firewall sees all of the school firewalls as neighbours.&amp;nbsp; So it's a star configuration, using a separate fibre interface on the district firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The school firewalls do not see the other school firewalls as neighbours.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We haven't made any changes to the OSPF setup as yet.&amp;nbsp; We're still investigating the setup, figuring out how it all works.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 22:38:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207039#M60733</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-22T22:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207043#M60735</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I think I might have gotten confused along the way somewhere. Would this a simplified representation of the nework between the distric and the schools?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 660px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14390i654CC9A9280A357D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If yes, then I think the setup is OK.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 22:48:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207043#M60735</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-22T22:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207045#M60736</link>
      <description>&lt;P&gt;Not really.&amp;nbsp; There's only a single link into any school.&amp;nbsp; Below is a crude ASCII drawing for it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internet &amp;lt;--------&amp;gt; Telco router &amp;lt;--------&amp;gt; District firewall &amp;lt;--------&amp;gt; fibre/wireless &amp;lt;---------&amp;gt; School firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;\&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;\--------&amp;gt; School firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;\---------&amp;gt; School firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; V&lt;/P&gt;&lt;P&gt;&amp;nbsp; Telco router &amp;lt;-----&amp;gt; MPLS &amp;lt;------&amp;gt; Telco router &amp;lt;----&amp;gt; School firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;|&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;^&lt;/P&gt;&lt;P&gt;&amp;nbsp; School firewall&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;V&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Telco router &amp;lt;-------&amp;gt; School firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;School firewall neighbours with telco router. \&lt;/P&gt;&lt;P&gt;Telco router neighbours with telco router.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|---&amp;gt; all of these are done with 1:1 connections&lt;/P&gt;&lt;P&gt;Telco router neighbours with district firewall. /&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;School firewall A neighbours with district firewall \&lt;/P&gt;&lt;P&gt;School firewall B neighbours with district firewall&amp;nbsp; |---&amp;gt; schools use 1 IP, district firewall has separate IPs for each school&lt;/P&gt;&lt;P&gt;School firewall C neighbours with district firewall /&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(but the district firewall uses only a single physical interface for this)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes things a little clearer.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 23:00:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207045#M60736</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-22T23:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207049#M60737</link>
      <description>&lt;P&gt;So each school firewall has OSPF adjacency with both a telco router and the district firewall (via wireless)? or is the MPLS network layer2 and transparent to your firewalls?&amp;nbsp; If two adjacencies, which ones are flapping?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I apologize if I missed it, but what version of PanOS and how is BFD configured?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 23:32:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207049#M60737</guid>
      <dc:creator>jandreini</dc:creator>
      <dc:date>2018-03-22T23:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207050#M60738</link>
      <description>Each school has exactly one of adjacency to one neighbor.&lt;BR /&gt;&lt;BR /&gt;28 school firewalls neighbour with the district firewall via our private fibre/wireless network. There are no routers in these schools. The adjacencies for these ospf connections are flapping.&lt;BR /&gt;&lt;BR /&gt;20-odd school firewalls neighbour with the Telco router in the school. Which then neighbours with the Telco router in our datacentre via the Telco MPLS network. These ospf adjacencies are not flapping.&lt;BR /&gt;&lt;BR /&gt;Oh, PanOS 6.1.19 on the school firewalls, and 7.1.14 on the district firewall. School firewalls are PA200s (elementary) , PA500s (secondary), and a single PA3020 in the multi-building high school. The district firewall is a pair of PA3020s in active/passive HA.&lt;BR /&gt;&lt;BR /&gt;Sorry for typos and multiple edits, posting from a phone. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Fri, 23 Mar 2018 00:16:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207050#M60738</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-23T00:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207051#M60739</link>
      <description>&lt;P&gt;Can you tell from the logs which side is tearing down the adjacency?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am still interested in the BFD configuration.&amp;nbsp; Of the models mentioned, the 3020 is the only firewall that supports it and your adjacency flapping mirrors a situation I had where BFD was disabled on one end of a link.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Mar 2018 00:24:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207051#M60739</guid>
      <dc:creator>jandreini</dc:creator>
      <dc:date>2018-03-23T00:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207052#M60740</link>
      <description>That's something I haven't looked into yet. Won't be back at work until Monday. I can check the logs then to see which side losses adjacency first (district firewall or school firewall).&lt;BR /&gt;&lt;BR /&gt;BFD is not configured anywhere (at least, I don't think it is).</description>
      <pubDate>Fri, 23 Mar 2018 00:51:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207052#M60740</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-23T00:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207063#M60744</link>
      <description>&lt;P&gt;Agreed - I perused the documentation, and while your central firewall is the only one that supports it (only 3000 and larger or VM models, introduced in 7.1), it appears the default behavior in 7.1 was for it to be disabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still easy to check under network -&amp;gt; virtual routers -&amp;gt; your VR -&amp;gt; OSPF and network -&amp;gt; BFD Profiles just to be sure&lt;/P&gt;</description>
      <pubDate>Fri, 23 Mar 2018 01:45:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207063#M60744</guid>
      <dc:creator>jandreini</dc:creator>
      <dc:date>2018-03-23T01:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF adjacency flapping - normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207459#M60815</link>
      <description>&lt;P&gt;BFD Profile is listed as "Inherit-vr-global-setting" on all the Virtual Routers&amp;nbsp;configured on the district firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The lone PA3020 in a school is running PanOS 6.1.10, so it doesn't have the BFD settings.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 15:58:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacency-flapping-normal/m-p/207459#M60815</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-26T15:58:04Z</dc:date>
    </item>
  </channel>
</rss>

