- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
05-12-2017 12:12 AM
Hello.
There is a question about OSPF adjacency flapping caused by minor changes in OSPF process.
I planned data-center deployment of PA-5060 HA-cluster. In this plan PA-5060 needs to be attached to OSPF AREA 0, and multiple NSSA areas in different security zones. Number of multiple areas non constant and in will be increasing in the future with deploying new DMZs.
When i configured this, i noticed that some changes in OSPF causes adjacancy reestablishing with peers when configuration is commiting.
For example:
Creating new interface/subinterface and attacing it to existent OSPF area commits without interruption.
Creating new area, even without interfaces belongs to it, commits with reestablishing all existent OSPF adjacancies and service interruption.
Precisely OSPF peers receives one-way hello from PA (hello packet with empty neighbors list) and goes to Init state.
In this scenario deploying of any new DMZ will cause service interruption in whole data-center segment.
Is this a normal behaviour of PA?
Are there any workarounds? GR or something.
I found an article in community.
But it dated 2012. Is this fixed now?
Thanks in advance.
05-13-2017 06:59 AM
If this is still an issue, try testing with using eBGP and private ASN for your DMZ segments instead.
05-13-2017 03:44 PM
I believe that issue is already resolved back in 6.0 or 6.1. I am running on 7.1.9, I don't think I see any OSPF adjacencies flapping when we add or delete interface|subnet..
E
05-15-2017 03:50 AM
nextgenhappines,
As I described, creating int/subint not cause flapping, but creating/deletting area, even without interfaces, leads to flapping.
My design assumes creating a new area for new DMZ.
I tested this case on PA-500 with software from 5.0.0 to 7.1.17, issue still exists.
So sad, it seems we'll have to make new design.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!