Loss of North-South Communication After Palo Alto Firewall Crash
book
Article ID: 406737
calendar_today
Updated On:
Products
VMware NSX
Issue/Introduction
- Post PA firewall is restored, BGP connection is re established with edge
- Upon checking T0 SR routing table, there are no valid routes learned from BGP
- The default route to the ToR is missing when verifying the routing table from the Edge node (
edge01(tier0_sr[6])> get route)
Environment
VMware NSX-T Data Center
VMware NSX
Cause
This is an issue on PA Firewall , where the 3rd party firewall does not push any routes to the NSX edge
Resolution
There is no issue found on NSX config. Involve vendor for resolution
Workaround:
Create a static default route on NSX-T T0 pointing to TOR
Feedback
thumb_up
Yes
thumb_down
No