nanog mailing list archives

Re: Dynamic routing on firewalls.


From: ML <ml () kenweb org>
Date: Thu, 05 Feb 2015 09:53:24 -0500


On 2/5/2015 9:42 AM, Eugeniu Patrascu wrote:
On Juniper things tend work OK. Other than this, make sure you don't run into asymmetric routing as connections might get dropped because the firewall does not know about them or packets arrive out of order and the firewall cannot reassemble all of them.

Agreed. Assymmetric routing is not your friend unless you plan accordingly.

I use OSPF and BGP quite a bit on Juniper SRX.  Works great.


Current thread: