Network > Routing > Routing Profiles > OSPFv3
Table of Contents
11.2
Expand all | Collapse all
-
- Firewall Overview
- Features and Benefits
- Last Login Time and Failed Login Attempts
- Message of the Day
- Task Manager
- Language
- Alarms
- Commit Changes
- Save Candidate Configurations
- Revert Changes
- Lock Configurations
- Global Find
- Threat Details
- AutoFocus Intelligence Summary
- Configuration Table Export
- Change Boot Mode
-
- Objects > Addresses
- Objects > Address Groups
- Objects > Regions
- Objects > Dynamic User Groups
- Objects > Application Groups
- Objects > Application Filters
- Objects > Services
- Objects > Service Groups
- Objects > Devices
- Objects > External Dynamic Lists
- Objects > Custom Objects > Spyware/Vulnerability
- Objects > Custom Objects > URL Category
- Objects > Security Profiles > Antivirus
- Objects > Security Profiles > Anti-Spyware Profile
- Objects > Security Profiles > Vulnerability Protection
- Objects > Security Profiles > File Blocking
- Objects > Security Profiles > WildFire Analysis
- Objects > Security Profiles > Data Filtering
- Objects > Security Profiles > DoS Protection
- Objects > Security Profiles > Mobile Network Protection
- Objects > Security Profiles > SCTP Protection
- Objects > Security Profile Groups
- Objects > Log Forwarding
- Objects > Authentication
- Objects > Packet Broker Profile
- Objects > Schedules
-
-
- Firewall Interfaces Overview
- Common Building Blocks for Firewall Interfaces
- Common Building Blocks for PA-7000 Series Firewall Interfaces
- Tap Interface
- HA Interface
- Virtual Wire Interface
- Virtual Wire Subinterface
- PA-7000 Series Layer 2 Interface
- PA-7000 Series Layer 2 Subinterface
- PA-7000 Series Layer 3 Interface
- Layer 3 Interface
- Layer 3 Subinterface
- Log Card Interface
- Log Card Subinterface
- Decrypt Mirror Interface
- Aggregate Ethernet (AE) Interface Group
- Aggregate Ethernet (AE) Interface
- Network > Interfaces > VLAN
- Network > Interfaces > Loopback
- Network > Interfaces > Tunnel
- Network > Interfaces > SD-WAN
- Network > Interfaces > PoE
- Network > Interfaces > Cellular
- Network > Interfaces > Fail Open
- Network > VLANs
- Network > Virtual Wires
-
- Network > Routing > Logical Routers > General
- Network > Routing > Logical Routers > Static
- Network > Routing > Logical Routers > OSPF
- Network > Routing > Logical Routers > OSPFv3
- Network > Routing > Logical Routers > RIPv2
- Network > Routing > Logical Routers > BGP
- Network > Routing > Logical Routers > Multicast
-
- Network > Routing > Routing Profiles > BGP
- Network > Routing > Routing Profiles > BFD
- Network > Routing > Routing Profiles > OSPF
- Network > Routing > Routing Profiles > OSPFv3
- Network > Routing > Routing Profiles > RIPv2
- Network > Routing > Routing Profiles > Filters
- Network > Routing > Routing Profiles > Multicast
- Network > Proxy
-
- Network > Network Profiles > GlobalProtect IPSec Crypto
- Network > Network Profiles > IPSec Crypto
- Network > Network Profiles > IKE Crypto
- Network > Network Profiles > Monitor
- Network > Network Profiles > Interface Mgmt
- Network > Network Profiles > QoS
- Network > Network Profiles > LLDP Profile
- Network > Network Profiles > SD-WAN Interface Profile
- Network > Network Profiles > MACsec Profile
-
-
- Device > Setup
- Device > Setup > Management
- Device > Setup > Interfaces
- Device > Setup > Telemetry
- Device > Setup > Content-ID
- Device > Setup > WildFire
- Device > Setup > ACE
- Device > Setup > DLP
- Device > Log Forwarding Card
- Device > Config Audit
- Device > Administrators
- Device > Admin Roles
- Device > Access Domain
- Device > Authentication Sequence
- Device > IoT Security > DHCP Server Log Ingestion
- Device > Device Quarantine
-
- Security Policy Match
- QoS Policy Match
- Authentication Policy Match
- Decryption/SSL Policy Match
- NAT Policy Match
- Policy Based Forwarding Policy Match
- DoS Policy Match
- Routing
- Test Wildfire
- Threat Vault
- Ping
- Trace Route
- Log Collector Connectivity
- External Dynamic List
- Update Server
- Test Cloud Logging Service Status
- Test Cloud GP Service Status
- Device > Virtual Systems
- Device > Shared Gateways
- Device > Certificate Management
- Device > Certificate Management > Certificate Profile
- Device > Certificate Management > OCSP Responder
- Device > Certificate Management > SSL/TLS Service Profile
- Device > Certificate Management > SCEP
- Device > Certificate Management > SSL Decryption Exclusion
- Device > Certificate Management > SSH Service Profile
- Device > Response Pages
- Device > Server Profiles
- Device > Server Profiles > SNMP Trap
- Device > Server Profiles > Syslog
- Device > Server Profiles > Email
- Device > Server Profiles > HTTP
- Device > Server Profiles > NetFlow
- Device > Server Profiles > RADIUS
- Device > Server Profiles > SCP
- Device > Server Profiles > TACACS+
- Device > Server Profiles > LDAP
- Device > Server Profiles > Kerberos
- Device > Server Profiles > SAML Identity Provider
- Device > Server Profiles > DNS
- Device > Server Profiles > Multi Factor Authentication
- Device > Local User Database > Users
- Device > Local User Database > User Groups
- Device > Scheduled Log Export
- Device > Software
- Device > Dynamic Updates
- Device > Licenses
- Device > Support
- Device > Policy Recommendation > IoT
- Device > Policy > Recommendation SaaS
- Device > Policy Recommendation > IoT or SaaS > Import Policy Rule
-
- Device > User Identification > Connection Security
- Device > User Identification > Terminal Server Agents
- Device > User Identification > Group Mapping Settings
- Device > User Identification> Trusted Source Address
- Device > User Identification > Authentication Portal Settings
- Device > User Identification > Cloud Identity Engine
-
- Network > GlobalProtect > MDM
- Network > GlobalProtect > Clientless Apps
- Network > GlobalProtect > Clientless App Groups
- Objects > GlobalProtect > HIP Profiles
-
- Use the Panorama Web Interface
- Context Switch
- Panorama Commit Operations
- Defining Policies on Panorama
- Log Storage Partitions for a Panorama Virtual Appliance in Legacy Mode
- Panorama > Setup > Interfaces
- Panorama > High Availability
- Panorama > Firewall Clusters
- Panorama > Administrators
- Panorama > Admin Roles
- Panorama > Access Domains
- Panorama > Device Groups
- Panorama > Plugins
- Panorama > Log Ingestion Profile
- Panorama > Log Settings
- Panorama > Server Profiles > SCP
- Panorama > Scheduled Config Export
- Panorama > Device Registration Auth Key
Network > Routing > Routing Profiles > OSPFv3
Create OSPFv3 routing profiles to efficiently configure
OSPFv3 for a logical router.
Add OSPFv3 routing profiles to
efficiently configure OSPFv3 for a logical router.
OSPFv3 Routing Profiles | Description |
---|---|
OSPFv3 Global Timer Profile | |
Name | Enter a name for the profile (maximum of
63 characters). The name must start with an alphanumeric character,
underscore (_), or hyphen (-), and contain zero or more alphanumeric
characters, underscore (_) or hyphen(-). No dot (.) or space is
allowed. |
LSA min-arrival | Enter the smallest interval at which the
firewall recalculates the SPF tree; range is 1 to 10; default is
5. The firewall would recalculate at a larger interval (less frequently
than the setting). |
SPF Throttle—Initial delay | Enter the initial delay (in seconds) from
when the logical router receives a topology change until it performs the
Shortest Path First (SPF) calculation; range is 0 to 600; default
is 5. |
Initial hold time | Enter the initial hold time (in seconds)
between the first two consecutive SPF calculations; range is 0 to
600; default is 5. Each subsequent hold time is twice as long as the
prior hold time until the hold time reaches the maximum hold time. |
Maximum hold time | Enter the largest value that the hold time
increases to until it remains steady; range is 0 to 600; default
is 5. |
OSPFv3 Auth Profile | |
Name | Enter a name for the Authentication profile (maximum
of 63 characters). The name must start with an alphanumeric character,
underscore (_), or hyphen (-), and contain zero or more alphanumeric
characters, underscore (_) or hyphen(-). No dot (.) or space is allowed. |
SPI | Enter the Security Policy Index, which must
match between both ends of the OSPFv3 adjacency. |
Protocol | Select the authentication protocol: ESP (Encapsulating
Security Payload) (recommended) or AH (Authentication
header). |
Authentication—Type | Select the type of authentication:
|
Key | Enter the authentication key in hexadecimal format:
xxxxxxxx[-xxxxxxxx] ... using a total of 5 sections and Confirm Key. |
Encryption—Algorithm | (ESP only) Select the encryption algorithm:
|
Key | (ESP only) Enter the encryption
key in hexadecimal format; use the correct number of sections based
on the type of ESP encryption and Confirm Key:
|
OSPFv3 Interface Timer Profile | |
Name | Enter a name for the profile (maximum of
63 characters). The name must start with an alphanumeric character,
underscore (_), or hyphen (-), and contain zero or more alphanumeric
characters, underscore (_) or hyphen(-). No dot (.) or space is
allowed. |
Hello Interval | Enter the interval (in seconds) at which
OSPFv3 sends Hello packets; range is 1 to 3,600; default is 10. |
Dead Count | Enter the number of times the Hello Interval
can occur from a neighbor without OSPFv3 receiving a Hello packet
from the neighbor, before OSPFv3 considers that neighbor down; range
is 3 to 20; default is 4. |
Retransmit Interval | Enter the number of seconds that OSPFv3
waits to receive an LSA from a neighbor before OSPFv3 retransmits
the LSA: range is 1 to 1,800; default is 5. |
Transmit Delay | Enter the number of seconds that OSPFv3
delays transmitting an LSA before sending the SLA out an interface;
range is 1 to 1,800; default is 1. |
Graceful Restart Hello Delay (sec) | Enter the Graceful Restart Hello Delay in
seconds; range is 1 to 10; default is 10. This setting applies to
an OSPFv3 interface when Active/Passive HA is configured. Graceful
Restart Hello Delay is the number of seconds during which the firewall
sends Grace LSA packets at 1-second intervals. During this time,
no Hello packets are sent from the restarting firewall. During the
restart, the dead time (which is the Hello Interval multiplied
by the Dead Count) is also counting down.
If the dead timer is too short, the adjacency will go down during
the graceful restart because of the hello delay. Therefore it is recommended
that the dead timer be at least four times the value of the Graceful
Restart Hello Delay. |
OSPFv3 Redistribution Profile | |
Name | Enter a name for the profile (maximum of
63 characters). The name must start with an alphanumeric character,
underscore (_), or hyphen (-), and contain zero or more alphanumeric
characters, underscore (_) or hyphen(-). No dot (.) or space is
allowed. |
IPv6 Static | Select to allow configuration of this portion
of the profile. |
Enable | Enable the IPv6 static portion of the profile. |
Metric | Specify the Metric to apply to the static
routes being redistributed into OSPFv3 (range is 1 to 65,535). |
Metric-Type | Select Type 1 or Type 2. |
Redistribute Route-Map | Select or create a Redistribution Route
Map to control which IPv6 static routes are redistributed to OSPFv3
and set their attributes. Default is None.
If the route map Set configuration includes a Metric Action and
Metric Value, they are applied to the redistributed route. Otherwise, the
Metric configured on this redistribution profile is applied to the
redistributed route. Likewise, the Metric Type in the route map
Set configuration takes precedence over the Metric Type configured
in this redistribution profile. |
Connected | Select to allow configuration of this portion
of the profile. |
Enable | Enable the Connected portion of the profile. |
Metric | Specify the Metric to apply to the Connected
routes being redistributed into OSPFv3 (range is 1 to 65,535). |
Metric-Type | Select Type 1 or Type 2. |
Redistribute Route-Map | Select or create a Redistribution Route
Map to control which Connected routes are redistributed to OSPFv3
and set their attributes. Default is None.
If the route map Set configuration includes a Metric Action and
Metric Value, they are applied to the redistributed route. Otherwise, the
Metric configured on this redistribution profile is applied to the
redistributed route. Likewise, the Metric Type in the route map
Set configuration takes precedence over the Metric Type configured
in this redistribution profile. |
BGP AFI IPv6 | Select to allow configuration of this portion
of the profile. |
Enable | Enable the BGP AFI IPv6 portion of the profile. |
Metric | Specify the Metric to apply to the BGP IPv6
routes being redistributed into OSPFv3 (range is 0 to 4,294,967,295). |
Metric-Type | Select Type 1 or Type 2. |
Redistribute Route-Map | Select or create a Redistribution Route
Map to control which BGP IPv6 routes are redistributed to OSPFv3
and set their attributes. Default is None.
If the route map Set configuration includes a Metric Action and
Metric Value, they are applied to the redistributed route. Otherwise, the
Metric configured on this redistribution profile is applied to the
redistributed route. Likewise, the Metric Type in the route map
Set configuration takes precedence over the Metric Type configured
in this redistribution profile. |
IPv6 Default Route | Select to allow configuration of this portion
of the profile. |
Always | Select to always create and redistribute
the IPv6 default route to OSPFv3, even if there is no default route on
the router; default is enabled. |
Enable | Enable the IPv6 Default Route portion of
the profile. |
Metric | Specify the Metric to apply to the IPv6
default route being redistributed into OSPFv3 (range is 0 to 4,294,967,295). |
Metric-Type | Select Type 1 or Type 2. |