<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Micro BFD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094206#M1112229</link>
    <description>&lt;P&gt;So it depends on the hashing of the port-channel, not all bgp neighbors go down just the ones that travel over the link that is being pulled&lt;BR /&gt;&lt;BR /&gt;lets's say:&lt;BR /&gt;&lt;BR /&gt;bgp neigbor A travels over link 1 of the port-channel (because of src-dst ip hashing)&lt;BR /&gt;bgp neigbor B travels over link 2 of the port-channel (because of src-dst ip hashing)&lt;BR /&gt;&lt;BR /&gt;link 2 gets disconnected&lt;BR /&gt;&lt;BR /&gt;neihgbor A stays up&lt;BR /&gt;neighbor B gets torn down because bfd noticed the link down, after which neighbor B re-establishes over link 1&lt;BR /&gt;&lt;BR /&gt;To prevent neighbor B from even being torn down and re-establishing you can use micro-bfd (if it's supported on your hardware)&lt;BR /&gt;&lt;BR /&gt;also see the blog post from Ivan i posted before&lt;/P&gt;</description>
    <pubDate>Wed, 08 May 2024 13:27:55 GMT</pubDate>
    <dc:creator>Pim Scheffers</dc:creator>
    <dc:date>2024-05-08T13:27:55Z</dc:date>
    <item>
      <title>ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5093913#M1112204</link>
      <description>&lt;P&gt;Does anyone know if any cisco ASA version supports Micro-BFD (RFC 7130) ?&lt;/P&gt;&lt;P&gt;I'm having a hard time finding it in the documentation so probably not.&lt;/P&gt;&lt;P&gt;maybe in an upcoming release?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 09:00:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5093913#M1112204</guid>
      <dc:creator>Pim Scheffers</dc:creator>
      <dc:date>2024-05-08T09:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5093915#M1112205</link>
      <description>&lt;P&gt;Why you are looking for BFD?&lt;/P&gt;
&lt;P&gt;Do you have IGP you need to fast recovery by bfd?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 09:03:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5093915#M1112205</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-08T09:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5093949#M1112209</link>
      <description>&lt;P&gt;Do you have IGP you need to fast recovery by bfd? YES&lt;/P&gt;&lt;P&gt;BFD is already running on the ASA, i'm looking to convert it it to Micro-BFD because it's connected the a Nexus VPC&lt;BR /&gt;When 1 of the links of the port-channel now goes down bfd is killiing the igp that's why i need micro-bfd RFC 7130&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 09:31:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5093949#M1112209</guid>
      <dc:creator>Pim Scheffers</dc:creator>
      <dc:date>2024-05-08T09:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5093952#M1112210</link>
      <description>&lt;P&gt;One ASA BFD is used 1) to support fast BGP fall-over and 2) for health monitoring and failure detection inside failover subsystem. For LAG monitoring and failure detection ASA/FXOS uses LACP. Micro BFD is not supported. Why do you need BFD on LAG interfaces?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 09:32:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5093952#M1112210</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2024-05-08T09:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5093954#M1112211</link>
      <description>&lt;P&gt;you run PO between ASA and vPC or redundancy interface ?&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 09:36:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5093954#M1112211</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-08T09:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5093991#M1112213</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/188522"&gt;@Pim Scheffers&lt;/a&gt;, sorry if I'm asking something stupid, but are you talking about IGP through the ASA or to the ASA? So far as I know, ASA OSPF has not been integrated with BFD running on the ASA: the "CSCvh56774 &lt;SPAN class=""&gt;ENH: Request to add BFD support for OSPF on ASA&lt;/SPAN&gt;" enhancement has not been implemented. Also,&lt;/P&gt;&lt;PRE&gt;router ospf ...&lt;BR /&gt;&amp;nbsp;bfd all-interfaces&lt;/PRE&gt;&lt;P&gt;is not available on the ASA (although I don't have latest version of the code in hands). Why does OSPF fail in this case when one of port-channel links goes down?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 10:07:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5093991#M1112213</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2024-05-08T10:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094037#M1112214</link>
      <description>&lt;P&gt;So the setup is ASA with port-channel to nexus VPC pair - which connects to cisco asr1001-X also with a port-channel&lt;BR /&gt;between the ASA &amp;amp; ASR1001-x I have multiple bgp neigbourships with BFD fall-over configured&amp;nbsp;&lt;BR /&gt;If i pull a link or reboot a switch from the vpc pair i see&amp;nbsp; bgp neigbourships being torn down because of bfd which i can prevent if micro-bfd was supported, hope it's clear like this&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 10:58:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094037#M1112214</guid>
      <dc:creator>Pim Scheffers</dc:creator>
      <dc:date>2024-05-08T10:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094060#M1112215</link>
      <description>&lt;P&gt;Did you use bfd multihop also?&lt;/P&gt;
&lt;P&gt;Since ebgp is multi hop then bfd need to be multi also&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 11:08:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094060#M1112215</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-08T11:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094080#M1112216</link>
      <description>&lt;P&gt;ebgp CAN be multi hop but it's not in this case the bgp neighbours are on the same segement.&lt;/P&gt;&lt;P&gt;I also don't read in the documentation that when you use bgp it MUST be multihop bfd i see loads of examples where it is single hop.&lt;BR /&gt;&lt;BR /&gt;or maybe i'm misunderstanding&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 11:38:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094080#M1112216</guid>
      <dc:creator>Pim Scheffers</dc:creator>
      <dc:date>2024-05-08T11:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094084#M1112218</link>
      <description>&lt;P&gt;ASA-NSK-ASR&amp;nbsp;&lt;BR /&gt;BGP run between ASA and ASR&amp;nbsp;&lt;BR /&gt;the traffic pass through NSK L3 and it count as Hop&amp;nbsp;&lt;BR /&gt;so BFD need to be multi in ASA to detect ASR&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 11:40:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094084#M1112218</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-08T11:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094087#M1112219</link>
      <description>&lt;P&gt;The nexus doesn't do L3 it's L2 Switch&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 11:45:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094087#M1112219</guid>
      <dc:creator>Pim Scheffers</dc:creator>
      <dc:date>2024-05-08T11:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094090#M1112220</link>
      <description>&lt;P&gt;can I see the ASA BFD and BGP config&amp;nbsp;&lt;BR /&gt;also&amp;nbsp;&lt;BR /&gt;show etherchannel summary &amp;lt;&amp;lt;- in NSK&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 11:49:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094090#M1112220</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-08T11:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094095#M1112221</link>
      <description>&lt;P&gt;Thanks for all the replies, but i think it's clear ASA doesn't support micro bfd&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 11:53:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094095#M1112221</guid>
      <dc:creator>Pim Scheffers</dc:creator>
      <dc:date>2024-05-08T11:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094101#M1112222</link>
      <description>&lt;P&gt;ASA not support micro BFD we agree&lt;BR /&gt;but ASA one link down loss BGP is not OK&lt;BR /&gt;the NSK see one link of PO not two, that Why when this link down the ASA loss BGP&lt;/P&gt;
&lt;P&gt;anyway consider this NSK with vPC and PO sometime have issue&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 11:57:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094101#M1112222</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-05-08T11:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094133#M1112224</link>
      <description>&lt;P&gt;Ivan Pepelnjak already wrote a blogpost on it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://blog.ipspace.net/2014/10/micro-bfd-bfd-over-lag-port-channel.html" target="_blank"&gt;https://blog.ipspace.net/2014/10/micro-bfd-bfd-over-lag-port-channel.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 12:06:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094133#M1112224</guid>
      <dc:creator>Pim Scheffers</dc:creator>
      <dc:date>2024-05-08T12:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094151#M1112226</link>
      <description>&lt;P&gt;Noticed above that peers are on the same subnet, so removing misleading info.&lt;/P&gt;&lt;P&gt;Still, I don't understand why BFD between ASA and ASR1k fails if one link of the vPC fails and why micro-BFD is needed in this topology.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 12:57:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094151#M1112226</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2024-05-08T12:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094206#M1112229</link>
      <description>&lt;P&gt;So it depends on the hashing of the port-channel, not all bgp neighbors go down just the ones that travel over the link that is being pulled&lt;BR /&gt;&lt;BR /&gt;lets's say:&lt;BR /&gt;&lt;BR /&gt;bgp neigbor A travels over link 1 of the port-channel (because of src-dst ip hashing)&lt;BR /&gt;bgp neigbor B travels over link 2 of the port-channel (because of src-dst ip hashing)&lt;BR /&gt;&lt;BR /&gt;link 2 gets disconnected&lt;BR /&gt;&lt;BR /&gt;neihgbor A stays up&lt;BR /&gt;neighbor B gets torn down because bfd noticed the link down, after which neighbor B re-establishes over link 1&lt;BR /&gt;&lt;BR /&gt;To prevent neighbor B from even being torn down and re-establishing you can use micro-bfd (if it's supported on your hardware)&lt;BR /&gt;&lt;BR /&gt;also see the blog post from Ivan i posted before&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 13:27:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094206#M1112229</guid>
      <dc:creator>Pim Scheffers</dc:creator>
      <dc:date>2024-05-08T13:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Micro BFD</title>
      <link>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094281#M1112233</link>
      <description>&lt;P&gt;In my opinion, this can only happen if BFD timers on ASA and/or ASR1k are so small that a failure of a single link leads to the loss of few &lt;SPAN class=""&gt;consecutive BFD packets, before the hash is re-programmed, in which case session is torn down. I might be mistaken. Increase timers and test?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;On ASA BFD/UDP connection should be created with a port-channel as egress interface ("show conn all protocol udp port 3784"), so ASA should be able to switch to another physical link as soon as the other link is removed from the hash by the underlying code.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Micro-BFD would be run between the Nexus switch and the ASA on one side and the Nexus switch and the ASR1k on the other side, whilst your BGP is between the ASA and the ASR1k. How would this help?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 14:54:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-micro-bfd/m-p/5094281#M1112233</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2024-05-08T14:54:07Z</dc:date>
    </item>
  </channel>
</rss>

