- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-08-2024 03:48 PM
Hello All,
I have a few BGP related questions regarding Palo Alto Network firewalls HA active-standby setup.
Scenario:
* eBGP to internal/trust network
* static default route for WAN/untrust side
* floating IPs are used
Qs:
1. During failover, is the the BGP session state re-established on the passive firewall? That is, the BGP session is not synced over HA1 (control plane) to the standby (new 'active').
2: I guess BGP routing table (RIB) is synced over HA1 and BGP graceful restart can help maintain the FIB (i.e. best routes are not withdrawn from FIB of standby firewall that is the new 'active') ? Please confirm.
Thanks in advance community.
Jase
12-10-2024 01:18 AM
Hi Jase
1. after a failover BGP needs to re-establish neighborship
2. the RIB is not synced, the FIB is synced over HA1
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!