<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OSPF Adjacencies Flapping over IPSec Tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacencies-flapping-over-ipsec-tunnel/m-p/217986#M63029</link>
    <description>&lt;P&gt;Maurice, Did you find a resolution to your ospf issues? we are experiencing ospf adjaceny drop in 8.0.8 and so checking&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jun 2018 22:08:43 GMT</pubDate>
    <dc:creator>geetha</dc:creator>
    <dc:date>2018-06-14T22:08:43Z</dc:date>
    <item>
      <title>OSPF Adjacencies Flapping over IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacencies-flapping-over-ipsec-tunnel/m-p/204087#M60063</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to open this issue up for discussion, and possible resolution.&amp;nbsp; We have an IPSec Tunnel between two Palo Alto Firewalls (PAN 3050 &amp;amp; PAN 820), and we advertise OSPF routes to interconnect both sites, over the tunnel.&amp;nbsp; This was working fine for months with no issues.&amp;nbsp; Four days ago, we upgraded the 3050 from PANOS7.1 to PANOS8.0.8, and since then our OSPF adjacencies have continuously dropped.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the adjancency is up, the routes work fine, and traffic goes through the tunnel properly.&amp;nbsp; However, they are not up for very long, and only a few successful pings get through.&amp;nbsp; As a workaround we added static routes on both sides, which improved connectivity, however this too was inconsistent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the catch; once we completely broke the OSPF Adjacency, the static routes worked perfectly -- remaining consistent with 100% ping success.&amp;nbsp; I'm not sure what's going on.&amp;nbsp; With both OSPF and static the static will still take precedence (we have not changed Administrative Distance values).&amp;nbsp; Why is it that static routes pointing traffic through the tunnel works only when OSPF is removed.&amp;nbsp; But with OSPF and static, neither provide consistent connectivity over the tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PAN engineers thought it was related to PAN-DB download causing cpu spikes.&amp;nbsp; We deactivated the URL Filtering Licence and inserted a security rule to block pancloud application, and this did not resolve the issue.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anybody else seen behavior like this, or have any inclining to what may be causing this issue?&amp;nbsp; Any help or guidance is appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 15:12:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacencies-flapping-over-ipsec-tunnel/m-p/204087#M60063</guid>
      <dc:creator>Maurice_Green</dc:creator>
      <dc:date>2018-03-07T15:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Adjacencies Flapping over IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacencies-flapping-over-ipsec-tunnel/m-p/204130#M60074</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Are the PAN's both running 8.0.8 or just the 3050? I have both models and OSPF between them using multiple links, i.e. p2p wan links with VPN's. One issue I ran into was they were in different areas and the LSA updates became a problem. Are they in the same area?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just some thoughts.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 16:19:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacencies-flapping-over-ipsec-tunnel/m-p/204130#M60074</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-07T16:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Adjacencies Flapping over IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacencies-flapping-over-ipsec-tunnel/m-p/204166#M60085</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply!&amp;nbsp; They were at one point both running 8.0.8, however, we reverted the 3050 (that was recently upgraded) to 8.0.0 as a troubleshooting step; the PAN820 is still running 8.0.8.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes the links are in the same area, I belive that is a requirement to become neighbors.&amp;nbsp; I did go back and check to make sure all metric values (and area) were the same, and they are.&amp;nbsp; I will point out, the physical WAN links on both ends are OSPF Passive interfaces only, to advertise their respective Networks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The tunnel is formed between those two WAN links, and the tunnel&amp;nbsp;interfaces on both ends are in Area 2, p2p.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 19:39:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacencies-flapping-over-ipsec-tunnel/m-p/204166#M60085</guid>
      <dc:creator>Maurice_Green</dc:creator>
      <dc:date>2018-03-07T19:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Adjacencies Flapping over IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacencies-flapping-over-ipsec-tunnel/m-p/217986#M63029</link>
      <description>&lt;P&gt;Maurice, Did you find a resolution to your ospf issues? we are experiencing ospf adjaceny drop in 8.0.8 and so checking&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 22:08:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacencies-flapping-over-ipsec-tunnel/m-p/217986#M63029</guid>
      <dc:creator>geetha</dc:creator>
      <dc:date>2018-06-14T22:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF Adjacencies Flapping over IPSec Tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacencies-flapping-over-ipsec-tunnel/m-p/218049#M63041</link>
      <description>&lt;P&gt;I encountered this previously&amp;nbsp;due to a change in default BFD behavior between 7.1 and 8.0 - check your BFD settings on the VR and your global settings - we had hard coded the global setting on one firewall to match the default, and&amp;nbsp;left the other "default" so it's setting changed when it was upgraded - this caused the OSPF adjacency to go down every time the BFD timer expired.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jun 2018 14:14:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-adjacencies-flapping-over-ipsec-tunnel/m-p/218049#M63041</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-06-15T14:14:38Z</dc:date>
    </item>
  </channel>
</rss>

