BGP sessions reset or not - Active-Standby HA

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

BGP sessions reset or not - Active-Standby HA

L0 Member

Hello All, 

 

I have a few BGP related questions regarding Palo Alto Network firewalls HA active-standby setup.

 

Scenario:

* eBGP to internal/trust network

* static default route for WAN/untrust side

* floating IPs are used

 

Qs:

1. During failover, is the the BGP session state re-established on the passive firewall? That is, the BGP session is not synced over HA1 (control plane) to the standby (new 'active').

 

2: I guess BGP routing table (RIB) is synced over HA1 and BGP graceful restart can help maintain the FIB (i.e. best routes are not withdrawn from FIB of standby firewall that is the new 'active') ? Please confirm.

 

Thanks in advance community. 

 

Jase

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi Jase

1. after a failover BGP needs to re-establish neighborship

2. the RIB is not synced, the FIB is synced over HA1

 

Reference: HA Synchronization

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

1 REPLY 1

Cyber Elite
Cyber Elite

Hi Jase

1. after a failover BGP needs to re-establish neighborship

2. the RIB is not synced, the FIB is synced over HA1

 

Reference: HA Synchronization

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 accepted solution
  • 275 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!