Dynamic routing on firewalls.

David Jansen david at nines.nl
Thu Feb 5 14:52:49 UTC 2015


Hi Eugeniu,

On 05 Feb 2015, at 15:42, Eugeniu Patrascu <eugen at imacandi.net<mailto:eugen at imacandi.net>> wrote:

Any specific firewall in mind? As this depends from vendor to vendor.
We are using Cisco (ASA).

I've had some issues with OSPF and CheckPoint firewalls when the firewalls would be overloaded and started dropping packets at the interface level causing adjacencies to go down, but I solved this by using BGP instead and the routing issues went away.
The last time we were working with OSPF and Cisco was on a fwsm (cisco pix blade). Interesting to know that more vendors do have problems with OSPF on firewalls. Also good to hear that BGP seemed to have solved your problem.

Kind regards,
David





More information about the NANOG mailing list