- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
03-02-2022 08:58 PM
Got two Cisco ISR 4431 as border routers peering with 2 ISP. Got PA-850 that I need to configure as:
Any configuration example out there that can assist will be really appreciated
03-11-2022 03:34 PM
Hi @usaiatawakevou ,
PA does not support routing without an IP address. I would put 2 switches in the middle for redundancy, but if you don't want to do that you could configure IRB on the 4431s so that Gi0/0/0 and Gi0/0/1 are in the same subnet.
With regard to BGP, the PA is RFC compliant and can form the iBGP neighbor.
Thanks,
Tom
03-03-2022 04:32 PM
This is my planned setup
03-04-2022 09:41 AM
What exactly are you trying to accomplish?
03-06-2022 03:57 PM
I've listed it above on my initial post
03-07-2022 08:24 AM
You listed what you want to configure, not what you're trying to accomplish.
When you say IP unnumbered, does that mean you want to use vwire? What are you trying to do with OSPF and BGP? Egress and Ingress paths? Full tables/provider table/default? Are there public resources behind the PA? A/A vs A/P? Is there a reason you don't have L2 switch between the FW and routers?
Without knowing what you're trying to do, it's hard to provide any feedback.
03-11-2022 11:23 AM
Thanks for the response.
Current setup:
We will replace pfsense firewall, VPN device and Vyos with a pair of PA-850. Need to accomplish the following:
I've replicate the desired setup on my GNS3 lab however I couldn't figure out how iBGP works and ip unnumbered on PA so my lab is using IP address on point to point interface for now. OSPF between Cisco and PA with HA works but not BGP. When I tried to add peers, showing error as in peer invalid.
Probably there is a way to do this on PA but I'm only familiar with Cisco and Vyos for iBGP hence my request for any pointers or configuration example for similar scenario
Hope Im clear
Thanks
03-11-2022 03:34 PM
Hi @usaiatawakevou ,
PA does not support routing without an IP address. I would put 2 switches in the middle for redundancy, but if you don't want to do that you could configure IRB on the 4431s so that Gi0/0/0 and Gi0/0/1 are in the same subnet.
With regard to BGP, the PA is RFC compliant and can form the iBGP neighbor.
Thanks,
Tom
03-14-2022 04:41 AM
Thanks @TomYoung BVI solve it for me and my iBGP works now. Much apprecaited
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!