<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC/FTD BGP Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-ftd-bgp-question/m-p/5373334#M1124589</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;yes, you should be able to peer with two peers in the same ASN and receive the default route from both. There shouldn't be a loop, as&amp;nbsp;Loop prevention in BGP is achieved by verifying the AS number in the AS Path. BGP rejects route updates when the AS Path attribute contain its own AS number.&amp;nbsp; The peer will also probably configure a list of allowed routes they are willing to receive.&lt;/P&gt;</description>
    <pubDate>Fri, 27 Feb 2026 15:45:02 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2026-02-27T15:45:02Z</dc:date>
    <item>
      <title>FMC/FTD BGP Question</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-bgp-question/m-p/5373326#M1124588</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Is it possible to peer twice to same ASN with BGP from FTD and use multipath? if I do this and I ask the remote side to propagate a default route to our FTD from both peering's will I get both defaults due to the AS number loop prevention? Is it advisable or not to enable allow-as etc to get round this&amp;nbsp; any gotchas ?? Or should I be doing this another way.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 27 Feb 2026 15:15:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-bgp-question/m-p/5373326#M1124588</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2026-02-27T15:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD BGP Question</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-bgp-question/m-p/5373334#M1124589</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;yes, you should be able to peer with two peers in the same ASN and receive the default route from both. There shouldn't be a loop, as&amp;nbsp;Loop prevention in BGP is achieved by verifying the AS number in the AS Path. BGP rejects route updates when the AS Path attribute contain its own AS number.&amp;nbsp; The peer will also probably configure a list of allowed routes they are willing to receive.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Feb 2026 15:45:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-bgp-question/m-p/5373334#M1124589</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-02-27T15:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD BGP Question</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-bgp-question/m-p/5373376#M1124590</link>
      <description>&lt;P data-end="165" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1937" data-start="1568"&gt;On FTD → ECMP only works if the two paths qualify as “equal.” If the provider makes one default look different (prepends, different attributes), you may end up with only one active default. Also, depending on FTD/FMC version, support for “multipath-relax” style behavior can be limited — so if AS_PATHs aren’t identical, don’t assume you’ll get ECMP.&lt;/P&gt;
&lt;P data-end="1937" data-start="1568"&gt;That’s basically it: two peers, multipath enabled, keep the defaults equal, and verify you actually have two next-hops in the RIB/FIB.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Feb 2026 17:29:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-bgp-question/m-p/5373376#M1124590</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2026-02-27T17:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD BGP Question</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-bgp-question/m-p/5379092#M1124822</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/294133"&gt;@saxenanitesh8522&lt;/a&gt;&amp;nbsp;So what about ECMP with static routes is this generally ok ? and anything to watch out for at all??&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2026 10:04:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-bgp-question/m-p/5379092#M1124822</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2026-03-24T10:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD BGP Question</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-bgp-question/m-p/5379184#M1124827</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;ECMP is supported with FTD, configure traffic zones if static routes via different interfaces.&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/100/management-center-device-config-10-0/routing-ecmp.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/100/management-center-device-config-10-0/routing-ecmp.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2026 15:37:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-bgp-question/m-p/5379184#M1124827</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-03-24T15:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD BGP Question</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-bgp-question/m-p/5379219#M1124830</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;what would your preference be ECMP/Static default routes, or BGP multipath ??&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2026 16:36:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-bgp-question/m-p/5379219#M1124830</guid>
      <dc:creator>benolyndav</dc:creator>
      <dc:date>2026-03-24T16:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD BGP Question</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-bgp-question/m-p/5379227#M1124831</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/445131"&gt;@benolyndav&lt;/a&gt;&amp;nbsp;it depends, I'd possibly prefer BGP. With statics you'd need to determine whether the route is up/down with &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/100/management-center-device-config-10-0/routing-static.html#ID-2105-00000029" target="_self"&gt;tracking&lt;/A&gt;. With BGP this is dynamic, tune the timers or BFD for quicker dead peer detection.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2026 16:44:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-bgp-question/m-p/5379227#M1124831</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2026-03-24T16:44:44Z</dc:date>
    </item>
  </channel>
</rss>

