- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
MS250 routing issue when connected to new firewalls
I have a core stack of ms425 switches connected to a Palo Alto firewall via aggregate link. We are replacing the older firewalls with newer models but when the uplink is connected to the new devices the OSPF routing is not established, therefore, no traffic is getting out of the internal network. The configs between the old and new firewall are exactly the same. We have tried changing the uplink to a standard ethernet as well as rebooting the core stack when connected.
Has anyone else run into this issue? Any advice or guidance is greatly appreciated.
- Labels:
-
Layer 3
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What firewall model are you replacing with? Have you checked the log messages?
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Replacing the older hardware with 1420s. The logs do not indicate that there is any neighbor establishment.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Would it be possible to share what the settings are like on both sides?
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Couple of things jump to mind working through the OSI:
- Layer 1 - you’ve got a solid physical connection at both ends? Both sides are UP, UP
- Layer 2 - I did initially think ARP but you’ve rebooted the MS425 stack so that should have flushed the tables.
Is it just OSPF not working here? Can you test with a static route from the core into the firewall?
https://www.linkedin.com/in/darrenoconnor/
I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Right now it seems to be OSPF. I am having my team set up a mock scenario in the lab to see if we can replicate the issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check the log on the Palo Alto.
