nanog mailing list archives

Re: Dynamic routing on firewalls.


From: David Jansen <david () nines nl>
Date: Thu, 5 Feb 2015 14:52:49 +0000

Hi Eugeniu,

On 05 Feb 2015, at 15:42, Eugeniu Patrascu <eugen () imacandi net<mailto:eugen () imacandi net>> wrote:

Any specific firewall in mind? As this depends from vendor to vendor.
We are using Cisco (ASA).

I've had some issues with OSPF and CheckPoint firewalls when the firewalls would be overloaded and started dropping 
packets at the interface level causing adjacencies to go down, but I solved this by using BGP instead and the routing 
issues went away.
The last time we were working with OSPF and Cisco was on a fwsm (cisco pix blade). Interesting to know that more 
vendors do have problems with OSPF on firewalls. Also good to hear that BGP seemed to have solved your problem.

Kind regards,
David



Current thread: