Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

announcement of ext DIP prefix in BGP

$
0
0

Hi,

I have an ISG2000 (6.3.0) with two L3 external interfaces, running BGP over both for redundancy. Outbound NAT is achieved by having both of these interfaces in a loopback-group, and then utilising a DIP range on the associated loopback interface. This works fine: BGP announces the loopback prefix over both links, and traffic is correctly NATed irrespective of path.

However when I add a second DIP range on the loopback interface, I need to add it as an ext DIP since it's in a different subnet. My problem is that this new ext DIP prefix is not seen in the routing table, and thus not announced over BGP, and so return traffic does not flow.

I tried adding a static route in the vr (so that could be redistributed into BGP), however loopback is not a selectable next-hop interface. The only option is null, and although this triggers the neccessary BGP announcement; it obviously just blackholes all the (return) traffic.

I also tried using a second loopback interface, but it appears the L3 interfaces can only be a member of a single loopback-group.


It there any way to force the ext DIP to appear the routing table, so BGP can pick it up ?

 

thanks

/Pete


Viewing all articles
Browse latest Browse all 2577

Trending Articles