{"id":1452,"date":"2023-10-16T17:02:25","date_gmt":"2023-10-16T15:02:25","guid":{"rendered":"https:\/\/virtualguru.cz\/?p=1452"},"modified":"2024-02-05T09:33:32","modified_gmt":"2024-02-05T08:33:32","slug":"bgp-a-nsx-gw-firewall","status":"publish","type":"post","link":"https:\/\/virtualguru.cz\/en\/2023\/10\/16\/bgp-a-nsx-gw-firewall\/","title":{"rendered":"BGP and NSX GW firewall"},"content":{"rendered":"<p>U jednoho z\u00e1kazn\u00edka jsem \u0159e\u0161il mal\u00fd probl\u00e9m na NSX gateway firewallu.<\/p>\n<p>Zam\u00fd\u0161len\u00e1 situace:<\/p>\n<ul>\n<li>Routing s BGP ji\u017e funguje<\/li>\n<li>Nastavit Policy, kter\u00e1 bude povolovat ICMP (prvotn\u00ed test)<\/li>\n<li>Nastavit posledn\u00ed Default policy na DROP.<\/li>\n<\/ul>\n<p><!--more-->Dle p\u0159edpokladu by to m\u011blo v\u0161echno fungovat, ale opak byl pravdou.<\/p>\n<p>Kdy\u017e jsme nastavili posledn\u00ed pravidlo na ALLOW a to ICMP pravidlo pouze na Log, tak bylo vid\u011bt, \u017ee to do toho ICMP pravidla spadlo. Jakmile jsme nastavili na DROP, tak to taky zapsalo do Logu, ale ICMP nepro\u0161el.<\/p>\n<p>Ud\u011blali jsme tedy Traceflow paketu, kter\u00fd m\u011bl j\u00edt z VM, kter\u00e1 byla uvnit\u0159 na IP adresu v extern\u00ed s\u00edti.<\/p>\n<p>Probl\u00e9m byl vid\u011bt jako &#8222;Interface drop&#8220;, nikoli jako Rule DROP<\/p>\n<p>A v tu chv\u00edli m\u011b to napadlo! Pod\u00edvat se do routovac\u00ed tabulky.<\/p>\n<p>Pokud bylo posledn\u00ed pravidlo ALLOW, tak vid\u011bl a spr\u00e1vn\u011b se u\u010dil routy dovnit\u0159 i ven. Pokud ale bylo posledn\u00ed pravidlo DROP, tak se to neu\u010dilo routy z BGP.<\/p>\n<p>NOTE: BGP protokol b\u011b\u017e\u00ed jako IP slu\u017eba na portu 179. Pokud tedy na GW firewallu nastav\u00edme posledn\u00ed pravidlo na DROP, ale nebudeme m\u00edt vytvo\u0159en\u00e9 extra pravidlo pro BGP, tak n\u00e1m p\u0159estane fungovat routing. Nikoli FW.<\/p>\n<p>Proto je pot\u0159eba je\u0161t\u011b nastavit explicitn\u00ed pravidlo pro BGP, kter\u00e9 bude klidn\u011b jako p\u0159edposledn\u00ed, ale mus\u00ed tam b\u00fdt.\u00a0 BGP protokol nem\u00e1 automatick\u00e9 FW pravidlo, nebo jako Syst\u00e9mov\u00e9 pravidlo. Prost\u011b si jej mus\u00edte vytvo\u0159it sami. V NSX neexistuje p\u0159\u00edmo slu\u017eba BGP, tak\u017ee si ji mus\u00edte vytvo\u0159it &#8211; Destination port 179.<\/p>\n<p>Tak snad to n\u011bkomu pom\u016f\u017ee pro p\u0159\u00ed\u0161t\u011b.<\/p>","protected":false},"excerpt":{"rendered":"<p>U jednoho z\u00e1kazn\u00edka jsem \u0159e\u0161il mal\u00fd probl\u00e9m na NSX gateway firewallu. Zam\u00fd\u0161len\u00e1 situace: Routing s BGP ji\u017e funguje Nastavit Policy, kter\u00e1 bude povolovat ICMP (prvotn\u00ed<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/virtualguru.cz\/en\/2023\/10\/16\/bgp-a-nsx-gw-firewall\/\">Continue Reading<span class=\"screen-reader-text\">BGP and NSX GW firewall<\/span> <i class=\"fas fa-angle-right\"><\/i><\/a><\/div>","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"iawp_total_views":17,"footnotes":""},"categories":[50],"tags":[60,62,61,59,11],"class_list":["post-1452","post","type-post","status-publish","format-standard","hentry","category-nsx","tag-bgp","tag-firewall","tag-gateway","tag-nsx","tag-troubleshooting","entry"],"_links":{"self":[{"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/posts\/1452","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/comments?post=1452"}],"version-history":[{"count":7,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/posts\/1452\/revisions"}],"predecessor-version":[{"id":1493,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/posts\/1452\/revisions\/1493"}],"wp:attachment":[{"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/media?parent=1452"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/categories?post=1452"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/tags?post=1452"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}