Loss of North-South Communication After Palo Alto Firewall Crash
search cancel

Loss of North-South Communication After Palo Alto Firewall Crash

book

Article ID: 406737

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • Post PA firewall is restored, BGP connection is re established with edge 
  • Upon checking T0 SR routing table, there are no valid routes learned from BGP 
  • The default route to the ToR is missing when verifying the routing table from the Edge node (edge01(tier0_sr[6])> get route)

Environment

VMware NSX-T Data Center
VMware NSX

Cause

This is an issue on PA Firewall , where the 3rd party firewall does not push any routes to the NSX edge 

Resolution

There is no issue found on  NSX config. Involve vendor for resolution 

Workaround:

Create a static default route on NSX-T T0 pointing to TOR