Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Connecting RED's to XG when using BGP

Hello,

 

I am wondering if anyone has setup an XG using BGP and has RED's connected to it? Since there are no ACL's for the RED service ports, how can the XG accepts RED's from a BGP IP address that is not on a WAN port? There is no gateway address either so the XG does not have an interface in the BGP IP block. It only has point to point connections to each ISP using /30's.

 

This is a multi-hop BGP setup to 2 different ISP's, advertising a /22. Any info would be greatly appreciated.



This thread was automatically locked due to age.
  • I have 2 interfaces that are PTP links to ISP routers, as I have said numerous times. I then have an internal LAN interface.

    You cannot put any of the /22 on the interfaces for the PTP links as there is no redundancy if you do. If that interface goes down, so does that IP.

    Both of those post are exactly what I am trying to do. Neither got answered.

  • And i am not talking about your PTP Interfaces to ISP.

    I am talking to your LAN interface, which links your Network with the /22 to the Internet, isnt it? 

    Or why do you have a /22 in the first place? 

    You are using this /22 for something? 

    There are servers, which have all those IPs of the /22? 

     

    Both posts are using a internal DMZ with public IPs and publish all IPs through XG via BGP to ISP.

    So basically you put a Loop back interface in place and put the wanted IP on the XG via Alias. 

    __________________________________________________________________________________________________________________

  • You are not listening.

    I am not talking about servers behind the firewall.

    I am talking about the XG listening for services on an IP address that is in the block of the /22.

  • Please provide a Network map on your setup.

    Otherwise i cannot follow your setup, because i cannot provide anykind of suggestion. 

    Maybe with some screenshots, if you do not have a topology. 

    __________________________________________________________________________________________________________________