OSPF through Vwire

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

OSPF through Vwire

L2 Linker

I attempted to install a PA5060 between a Cisco ASA and Cisco Nexus switch in vwire mode. the ASA has an OSPF neighbor with the nexus 7k to distribute the defualt route learned via BGP from the ISP.

 

Once the 5060 was installed, the OSPF neigbor came up but the routes were not exchanged. in the logs I see the traffic as allowed and the application as OSPF. 

 

Is there any other configuration needed? I see in the following article that multicast traffic is allowed by defualt in vwire.

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Block-Multicast-Traffic-in-a-VWir...

 

The PA-5060 is running 7.0.3

 

All other traffic was working. I could ping across the vwire but the routes were not there.

 

thanks,

Nathan 

3 REPLIES 3

L6 Presenter

Hi there...Did you include security rule(s) to allow OSPF traffic in both directions across the vwire?  

yes I have security policies allowing all traffic both ways. 

You can turn on packet capture on the PA device and filter on the OSPF multicast to see what's happening to the packets.  Set the pcap to capture at all 4 stages: TX, RX, DROP and FIREWALL.  That should provide information to help pinpoint the issue.  Thanks. 

  • 3471 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!