[177773] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Dynamic routing on firewalls.

daemon@ATHENA.MIT.EDU (David Jansen)
Thu Feb 5 09:54:56 2015

X-Original-To: nanog@nanog.org
From: David Jansen <david@nines.nl>
To: Eugeniu Patrascu <eugen@imacandi.net>
Date: Thu, 5 Feb 2015 14:52:49 +0000
In-Reply-To: <CALgc3C6DTzJFwOUtLMfdtS---qzA4bPRYYLrQqktWG8F+dbzzw@mail.gmail.com>
Cc: David Jansen <david@nines.nl>, "nanog@nanog.org" <nanog@nanog.org>
Errors-To: nanog-bounces@nanog.org

Hi Eugeniu,

On 05 Feb 2015, at 15:42, Eugeniu Patrascu <eugen@imacandi.net<mailto:eugen=
@imacandi.net>> wrote:

Any specific firewall in mind? As this depends from vendor to vendor.
We are using Cisco (ASA).

I've had some issues with OSPF and CheckPoint firewalls when the firewalls =
would be overloaded and started dropping packets at the interface level cau=
sing adjacencies to go down, but I solved this by using BGP instead and the=
 routing issues went away.
The last time we were working with OSPF and Cisco was on a fwsm (cisco pix =
blade). Interesting to know that more vendors do have problems with OSPF on=
 firewalls. Also good to hear that BGP seemed to have solved your problem.

Kind regards,
David



home help back first fref pref prev next nref lref last post