<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic OSPF:  more detailed logs? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-more-detailed-logs/m-p/236551#M67807</link>
    <description>&lt;P&gt;We're still experiencing the occasional OSPF adjacency drop, although it's much improved since our changes over the summer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the log entries in the System log is anything but useful:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;OSPF adjacency with neighbor has gone down. interface ae2.211, neighbor router ID 10.200.11.96, neighbor IP address 10.200.11.96.&lt;/PRE&gt;&lt;P&gt;Is there any way to get more detailed logs as to why the adjacency has gone down?&lt;/P&gt;</description>
    <pubDate>Mon, 22 Oct 2018 18:39:03 GMT</pubDate>
    <dc:creator>fjwcash</dc:creator>
    <dc:date>2018-10-22T18:39:03Z</dc:date>
    <item>
      <title>OSPF:  more detailed logs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-more-detailed-logs/m-p/236551#M67807</link>
      <description>&lt;P&gt;We're still experiencing the occasional OSPF adjacency drop, although it's much improved since our changes over the summer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the log entries in the System log is anything but useful:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;OSPF adjacency with neighbor has gone down. interface ae2.211, neighbor router ID 10.200.11.96, neighbor IP address 10.200.11.96.&lt;/PRE&gt;&lt;P&gt;Is there any way to get more detailed logs as to why the adjacency has gone down?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 18:39:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-more-detailed-logs/m-p/236551#M67807</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-10-22T18:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF:  more detailed logs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-more-detailed-logs/m-p/236562#M67808</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42838"&gt;@fjwcash&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The best place to start would be the routed.log; combining this with the logs of the peer device terminating the OSPF connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; less mp-log routed.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've seen bugs in the past which cause OSPF hello packets to be caused, causing flapping. What PAN-OS version are you on?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 19:23:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-more-detailed-logs/m-p/236562#M67808</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-10-22T19:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF:  more detailed logs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-more-detailed-logs/m-p/236564#M67809</link>
      <description>&lt;P&gt;The core firewall that's set as the Designated Router (via priority settings) is an HA pair of PA3020s running 7.1.14.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The school firewalls are a mix of PA200s, PA500s, and PA3020s, running 7.1.19.&amp;nbsp; The school in question has a PA200.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The routed.log gives a bit more information, although the error codes are a little cryptic.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; And don't show up in Google searches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;**** AUDIT       0x3e01 - 91   (0000) **** I:1a6ba9ec F:00000002
qodmnmi.c 215 :at 08:51:18, 22 October 2018 (1499305380 ms)
OSPF 5 An adjacency with a neighbor has gone down.
Resources associated with database exchange for this neighbor will be
freed.
Neighbor router ID                 10.200.2.70
Neighbor IP address                10.200.2.70
Interface category                 network interface
Interface neighbor                 IP addr 10.200.2.70 i/f idx 0X00000000

**** AUDIT       0x3e01 - 210  (0000) **** I:1a6ba9ec F:00000002
qoamnfsa.c 754 :at 08:51:18, 22 October 2018 (1499305380 ms)
OSPF 5  i/f idx 0X0000010A  rtr ID 10.200.2.70 IP addr 10.200.2.70 neighbor FSM state has deteriorated.
Interface address                      = IP addr 10.200.2.1
OSPF link category                     = 1
Is neighbor virtual?                   = 0
FSM input                              = QOAM_NBR_INACTIVITY_TMR (13)
Old FSM state                          = AMB_OSPF_NBR_FULL (8)
New FSM state                          = AMB_OSPF_NBR_DOWN (1)
FSM action                             = I (9)
Neighbor friend status                 = 1
Number of neighbor events              = 6
Number of database exchange timeouts   = 0&lt;/PRE&gt;&lt;P&gt;I'm guessing the QOAM_NBR_INACTIVITY_TMR means the dead count timer has expired (meaning it hasn't received any of the 4 HELLO packets that were sent 10 seconds apart)?&amp;nbsp; If this is the case, then we'll need to consider changing the dead count timer/intervals to compensate (tried that this morning by just updated the PA3020s, which knocked the entire district offline due to timer mismatch.&amp;nbsp; Ooops!).&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The link between the school board office where the core PA3020s sit are connected to most schools via a private fibre network (secondary schools) and via Ubiquiti wireless links (elementary school) back to the secondary schools.&amp;nbsp; It's the wireless sites that are having the occasional OSPF drop-off.&amp;nbsp; It's a flat layer-2 bridged network currently.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 19:47:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-more-detailed-logs/m-p/236564#M67809</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-10-22T19:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF:  more detailed logs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-more-detailed-logs/m-p/236569#M67812</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42838"&gt;@fjwcash&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's great - and you're definitely right "QOAM_NBR_INACTIVITY_TMR" seems to be indicating that the firewall didn't receive the OSPF hello packets. So either yes, the timer values need to be adjusted, or there is an issue with the OSPF packets reaching the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No OSPF related bugs in the version you're on up until 7.1.20 - so I don't think it's any buggy behaviour causing this. I would start off with adjusting the timeout values as a starter for one and see how you get on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 20:31:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-more-detailed-logs/m-p/236569#M67812</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-10-22T20:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF:  more detailed logs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-more-detailed-logs/m-p/236570#M67813</link>
      <description>&lt;P&gt;Yeah, we're thinking we're going to adjust the dead timer intervals on all the firewalls on our fibre/wireless network over the Christmas break (as it will require taking all sites offline for the time it takes to configure each VR on each firewall).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We'll have to do some more reading on it, but we'll probably go with something along the lines of:&lt;/P&gt;&lt;P&gt;Hello Interval:&amp;nbsp; 5&lt;/P&gt;&lt;P&gt;Dead Counts: 12&lt;/P&gt;&lt;P&gt;Retransmit Interval:&amp;nbsp; (not sure)&lt;/P&gt;&lt;P&gt;Transit Delay: (not sure)&lt;/P&gt;&lt;P&gt;Graceful Restart: 15&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That way, the link would have to be really bad for a minute before OSPF drops it from the routing table.&amp;nbsp; Send more frequently, and wait longer before declaring it dead.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We'll live with the occasional OSPF flap until then.&amp;nbsp; It's much improved compared to last school year, with the OSPF changes we made over the summer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the pointers.&amp;nbsp; We'll get these firewalls configured perfectly, just in time for the Ministry of Education to change everything next year.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 20:48:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-more-detailed-logs/m-p/236570#M67813</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-10-22T20:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: OSPF:  more detailed logs?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ospf-more-detailed-logs/m-p/346992#M86568</link>
      <description>&lt;P&gt;dont meant to hijack the thread, but is there a was to configure this log? For example there's a lot of information on here that we dont necessarily need but would be nice if we can include for example the "name of the tunnel" or the Comment for the tunnel so its easier to identify version tunnel.214.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;are these log editable and if so where? Thanks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;domain: 1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;receive_time: 2020/09/04 12:04:18&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;actionflags: 0x0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;type: SYSTEM&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;subtype: routing&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;config_ver: 0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;time_generated: 2020/09/04 12:04:18&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dg_hier_level_1: 0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dg_hier_level_2: 0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dg_hier_level_3: 0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;dg_hier_level_4: 0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;vsys_name: &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;device_name: WH-CME-PA3220&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;vsys_id: 0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;vsys: &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;eventid: routed-OSPF-neighbor-down&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;object: default&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;fmt: 0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;id: 0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;module: general&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;severity: high&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;opaque: OSPF adjacency with neighbor has gone down. interface tunnel.226, neighbor router ID 10.254.109.26, neighbor IP address 172.16.19.81.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 18:49:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ospf-more-detailed-logs/m-p/346992#M86568</guid>
      <dc:creator>Iliya-wh</dc:creator>
      <dc:date>2020-09-04T18:49:03Z</dc:date>
    </item>
  </channel>
</rss>

