HP Aruba Certified Professional - Campus Access HPE7-A06 Question # 7 Topic 1 Discussion
HPE7-A06 Exam Topic 1 Question 7 Discussion:
Question #: 7
Topic #: 1
Ever since a recent firewall change at your WAN/lnternet edge, the 8GP state in your VSX pair has not returned to Established. What should you check to restore BGP functionality at the site?
A.
Restart the routing service so thatBGP auto-discovers its neighbors.
B.
Confirm that appropriate TCP ports are still allowed.
The BGP state on a VSX pair is stuck (not 'Established') after a recent firewall change at the WAN/Internet edge, where the BGP peering likely occurs.
BGP and Firewalls:BGP establishes sessions usingTCP port 179. Firewalls located between BGP peers must explicitly permit TCP port 179 traffic bidirectionally for the peering to establish and maintain. Firewall changes are a frequent cause of broken BGP sessions.
Troubleshooting Steps After Firewall Change:The most logical first step is to verify that the firewall change did not inadvertently block TCP port 179 between the configured BGP neighbor IP addresses.
Analysis of Options:
A: Restarting routing service is disruptive and not the first step.
B: Confirming that appropriate TCP ports (specifically 179) are still allowed through the firewall directly addresses the most probable cause related to the firewall change event.
C: Restarting NAT service is likely irrelevant unless NAT is incorrectly configured for BGP peers.
D: Confirming the peer AS is a basic configuration check but less likely related to thefirewall changeevent than port blocking.
Conclusion:Given the problem occurred immediately following a firewall change, verifying that the firewall still permits TCP port 179 between the BGP peers is the most direct and likely troubleshooting step.
[References:BGP protocol specifications (RFC 4271), Firewall management principles, Network troubleshooting methodology. This relates to "Routing" (16%), "Security" (10%), and "Troubleshooting" (10%) objectives., ]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit