Firewall tries to close a BGP/TCP connection with switch

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Firewall tries to close a BGP/TCP connection with switch

L1 Bithead


Hi,

 

  The following problem involves a firewall (10.249.0.13) wanting to close a BGP connection with its neighboring switch (10.249.0.14).

 

The switch answers with a BGP NOTIFICATION message that contains 'No supported AFI/SAFI'. (separate issue) The firewall then sends a FIN to the switch to close the TCP connection. Follows a series of FIN retransmissions from the firewall and ACK retransmissions from the switch.

 

Is there a way to determine which side is not understanding here?

I have included an excerpt of the .pcap.

 

Thanks



Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.
1 REPLY 1

Community Team Member

Hi @FrancoisNoel,

 

Thanks for reaching out. It looks like the switch sent a NOTIFICATION message because it detected an error with the BGP configuration between itself and the Palo. As a result, we see the termination of the adjacency. 

 

The capture tells us there is a misconfiguration in either the switch or the palo.  Can you share the configs? Also, it would be helpful to see the full debug to see what AFI and SAFI numbers are being exchanged. For example, the Palo default uses an address class of IPv4 and so if your switch bgp config is set with an address class of IPv6 then that could be an issue. 

 

NGFW 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 2883 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!