Cisco is trying to throw us off here - correct answers are A and C. As pfunky states, we can have up to 8 routes, meaning that C is a "valid" answer. The reason E is incorrect is that we cannot configure NSF for BGPv4 - we can only configure graceful restart, which relies on info from NSF capable/aware devices. For OSPF however, we can configure a device to be fully NSF capable/aware. Read through this if you are still in doubt: https://www.cisco.com/c/en/us/td/docs/security/firepower/660/fdm/fptd-fdm-config-guide-660/fptd-fdm-ospf.html
A :
https://www.cisco.com/c/en/us/td/docs/security/firepower/660/fdm/fptd-fdm-config-guide-660/fptd-fdm-bgp.html
" BGP IPv4 is supported both on global and user-defined virtual routers. However, only BGP IPv6 configuration is supported on a global virtual router."
Its about Cisco FTD devices and not Cisco FTDv appliance
B : https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/routing-ecmp.html
" You can have up to 8 equal cost static or dynamic routes across up to 8 interfaces within each zone." I read this as 1 equal cost route per interface. So 3 equal cost paths means 3 interfaces, not 1. So B must be valid and not C.
BGPv6 (A) is no doubt. So A is first answer. My confusion is this. B and C are saying up to 3. but all links that here mentioned up to 8 interfaces. "You can associate only 8 interfaces per ECMP zone." 3 is NOT same as 8? why B and C?
Supported Routing Protocols:
BGPv4: Cisco FTD supports BGPv4 for IPv4 routing, enabling it to exchange routes with other BGP-speaking devices and participate in dynamic routing environments.
OSPFv2: FTD also supports OSPFv2, another interior gateway protocol (IGP) commonly used within a single autonomous system for IPv4 routing.
Static routes: You can manually configure static routes to define specific paths for traffic to reach certain destinations.
Key Routing Features:
ECMP (Equal Cost Multi-Path): Allows for load balancing across up to three equal cost paths for improved performance and redundancy. However, it's important to note that ECMP is limited to multiple interfaces, not a single interface.
NSR (Nonstop Forwarding) with BGPv4: Ensures continuous forwarding of traffic even during BGP process restarts or failovers, enhancing network resilience.
https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/routing-ecmp.html
"You can associate only 8 interfaces per ECMP zone."
https://www.cisco.com/c/en/us/td/docs/security/firepower/622/configuration/guide/fpmc-config-guide-v622/bgp_for_firepower_threat_defense.html#:~:text=BGP%20is%20supported%20only%20in%20routed%20mode.
Guidelines for BGP
Firewall Mode Guidelines
Does not support transparent firewall mode. BGP is supported only in routed mode.
FTD supports BGPv6
https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/bgp_for_firepower_threat_defense.html
FTD ECMP
https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/routing-ecmp.html
The FTD device supports Equal-Cost Multi-Path (ECMP) routing. You can configure traffic zones per virtual router to contain a group of interfaces.
You can have up to 8 equal cost static or dynamic routes across up to 8 interfaces within each zone.
For example, you can configure multiple default routes across three interfaces in the zone
Why is not C an option to be considered ? I cannot find anything in the documentation related to BGP NSF , but I do about ECMP.
Equal-Cost Multi-Path (ECMP) Routing
The Firepower Threat Defense device supports Equal-Cost Multi-Path (ECMP) routing.
You can have up to 8 equal cost static or dynamic routes per interface.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
netwguy
Highly Voted 3 years, 3 months agorbrain
Most Recent 1 day, 16 hours agocaalbert
2 months, 3 weeks agogwb
10 months agoachille5
10 months, 1 week agobofu
11 months, 1 week agoBubu3k
11 months, 1 week agoAbetong
1 year, 3 months agoaadach
2 years, 11 months agoaadach
2 years, 11 months agopfunkylol
3 years, 4 months agoBobster02
3 years, 5 months agokakakayayaya
3 years, 6 months ago