Link to home
Start Free TrialLog in
Avatar of FREDARCE
FREDARCE

asked on

ebgp multihop thru cisco asa

I am trying to peer two routers vie ebgp multihop.  each peer router is being a cisco asa firewall. The peer routers can ping each other and I have allowed tcp 179 on both ASA's but I still don't have a successful neighborship?  Am I missing something?

Avatar of John Meggers
John Meggers
Flag of United States of America image

TCP /179 is correct.  Only thing I can think of is be careful of NATing and what address is being used to establish the peer relationship.  You might do some debugs on the routers to identify what BGP is trying to do, and you might also look at the ASA logs to identify what traffic is being blocked.
Avatar of FREDARCE
FREDARCE

ASKER

I am using any nat on either ASA.  changed logging to debug but don't see anything in the logs.  I would at least expect to see deny attempts made on tcp/179.  how can I ensure that the peer routers are at least trying to establish a neighborship?

ASKER CERTIFIED SOLUTION
Avatar of FREDARCE
FREDARCE

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
turns out my problem was I was relying on a default route for return traffic on each of the neighbor routers and what I needed to do was add a specific static route instead.  Once I added the static route bgp neighborship came up.
Forgot about the default route. BGP won't establish without an explicit route.