This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG OSPF Graceful Restart or NSF

Hi,

I did a quick research on the OSPF implementation on the XG series and did not find any clues on how to activate or rather configure "graceful restart" or NSF, as stated in RFC 3623.

I have two XG430s in an active-passive configuration connected to a FortiGate cluster. Both clusters exchanges their local connected routes and OSPF works flawlessly. That is, until I restart the primary firewall of one of the two clusters for firmware updates or other reasons.

The FortiGate cluster has graceful restart enabled and HA route wait timings etc. configured so the cluster sends out the appropriate grace-LSAs when doing restart of the master or failure of it.

The XG cluster on the other hand, does not seem to advertise those grace-LSAs, as it seems to directly flush its LSAs, which causes to the FortiGate cluster to drop its learned routes from the XGs as it seems to go through normal OSPF shutdown.

Ultimately, this causes a brief routing outage between the to clusters and causes some prolonged networks interruptions, which could be avoidable if all adjacent routers had OSPF graceful restart enabled.

So my question is, is there a way to enable graceful restart or NSF on the XG side? Or is it enabled by default I am missing something else entirely?

Thanks for your time and your help!

With best regards,

Florian



This thread was automatically locked due to age.
Parents
  • It could not be support in the version, which the firewall uses. The product uses Quagga for OSPF/BGP and quagga got this feature in 2016. The update of the version of quagga to support new features is currently in development. 

    __________________________________________________________________________________________________________________

  • Thank you for the information!

    Just to clarify: a newer version quagga is being implemented in a new vesion of SFOS? I guess there ne ETA yet?

    Greetings,

    Florian

  • As such a update of such a core module is complicated and needs a lot of testing, it will take some time to release. I cannot give a ETA on this release but sophos is planning to update the module in a firmware release of SFOS. 

    __________________________________________________________________________________________________________________

  • Okay, thanks for sharing this.

    I hope this will not take too long (many months, or even years), as OSPF NSF is quite an essential feature these days for many applications and customers.

    Greetings,

    Florian

Reply Children
No Data