Subsecond failover with active/passive firewalls running dynamic routing possible?

Reply
Highlighted
L1 Bithead

Subsecond failover with active/passive firewalls running dynamic routing possible?

Has anyone been able to successfully get subsecond failovers to work with active/passive firewalls running dynamic routing protocols such as BGP or OSPF?  In our lab testing, it appears we can get the firewall to failover instantly, but then it takes BGP a few seconds to drop/re-establish.  Our next testing will be OSPF to see if that helps speed it up any.  But then we'd have to redistribute those routes into BGP (our core) which might introduce a few second gap.  So far testing failovers (manual failovers via the gui), while running BGP and pinging peer behind the FW, we drop several pings.  With static routes in place, the failover seems to happen quick enough that no pings drop.  

 

I've searched about every article on this site and tried about all the suggestions for faster failover, bgp timers, etc.

 

On another note, would going active/active help this scenario?  The only main reason (other than link failures, firewall failures, etc.) I'd expect a failover would be for a firewall upgrade/maintenance.  Granted that will be done during a maintenance window if possible.  But we have some "custom" applications that might go offline and fail to our DR site if they loose connectivity for very long.

 

Thanks


Accepted Solutions
Highlighted
L4 Transporter

Hello,

 

For OSPF, just enabled graceful restart !!

PS: enable this feature also on the neighbor device.

 

Graceful restart is also available for BGP but I have never tested it !!

 

Regards,

 

HA

View solution in original post


All Replies
Highlighted
L4 Transporter

Hello,

 

For OSPF, just enabled graceful restart !!

PS: enable this feature also on the neighbor device.

 

Graceful restart is also available for BGP but I have never tested it !!

 

Regards,

 

HA

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!