openBGPD and FFR - Migrating 2.3.x to Latest 2.5.x
-
Hey Everyone,
Our pfSense installation has gotten severely out of date. I've recently been tasked with leading a migration to new hardware as well as the latest version of pfSense.
Last weekend my boss and I attempted to restore the current firewall config to the new hardware. We were able to restore the config successfully, communicating to local devices. However, we were unable to get a connection to the internet. We can still ping our ISPs router so this makes me believe it's a BGP issue. What reinforces that thought is that openBGPD is no longer available after 2.4.x.
On both routers, everything except for the BGP is the same. Same switchport config, same public IP, VLANs, settings, etc...
I guess what I'm really looking for here is validation in my thinking that no BGP router is our problem.
-
You are probably hitting the changed FRR requirement to have a route-map in place:
https://docs.netgate.com/pfsense/en/latest/packages/frr/bgp/example.html#route-map-for-peer-filteringWithout that you will see not routes exchanges in the current version.
Need more info to speculate further.
Steve
-
@stephenw10 Thanks for the response! I think I may have figured it out. Our uplink is configured so we need to use a BGP router. Otherwise, we'll need to phone the isp to enable static BGP routing for us. I think my boss now understands we need to use bgp
-
@work_purposes_only said in openBGPD and FFR - Migrating 2.3.x to Latest 2.5.x:
Our pfSense installation has gotten severely out of date.
At least, you admitted...but man, if your setup is for a business, it makes one shaking, scratching one's head for not taking the business network seriously.
-
Yeah if the upstream router requires you announce your subnet you won't get much without BGP!
-
@nollipfsense I've just inherited this network. So, I'll be taking this next year to tidy it up before going back to uni for my degree
-
@work_purposes_only said in openBGPD and FFR - Migrating 2.3.x to Latest 2.5.x:
@nollipfsense I've just inherited this network. So, I'll be taking this next year to tidy it up before going back to uni for my degree
Okay...fine inheritance...hope it came loaded (your forum name implied business).