- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-16-2011 06:01 PM
Hi,
I've the following setup.
Two PA5020 in Active/Passive setup.
One VR = STX-VR
Running OSPF & BGP instances.
Primary firewall joined in OSPF since i have interface e1/1 joined Area : 0.0.0.0
Primary firewalls joined in BGP since i have interface e1/2 peering with TWO BGP routers ( cisco )
Interface e1/1 is part of OSPF and its learning default route 0.0.0.0/0
I would like to inject the same default route in BGP AS so that routers peering with Firewalls would know the default route.
I tried the following
Created a Redistribution profile and tried to attach it to exprot tab on BGP, didn't not work.
Created a export Rule on BGP -TAB- and created a rule as ( Prefixes = 0.0.0.0/0 Action Allow )
Also, i would like to add custom BGP communities, but PA doesn't seem to accept. I might very well be doing something wrong. I wish there could be a simple document showing with explanation of what are the various options/featuers in OSPF/BGP Tabs.
Any help will be highly appreicaited.
Thanks & Regards
Junaid
10-18-2011 01:26 PM
Hi Junaid,
It looks like you're mostly there! The one issue that stood out at me (in your BGP configuration) is the export rules. For BGP, the export rules dictate what you want to filter out (or specifically include) in your route advertisements to BGP peers. Export rules are applied to the set of routes that BGP will share AFTER redistribution from OSPF/RIP and static/connected routes takes place. Export rules alone will not cause redistribution from OSPF to BGP. In order to redistribute your default route from OSPF to BGP, you must also specify the correct redistribution profile on the redistribution rules tab of the BGP configuration.
In your case, it looks like the "OSPF" redistribution profile matches the routes you want to redistribute from OSPF to BGP. So simply specify that redistribution profile in the name dropdown of the "New BGP Redistribution Rule" window that pops up when you create a new redistribution rule in BGP. Also make sure your export rules don't block out these newly redistributed routes.
What are you trying to do with BGP communities? It might help me to understand the configuration better once I know your ultimate goal.
Thanks,
Nick
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!