It is, in fact, a firewall rule that is preventing our iBGP peers from establishing. Here's the rule: add action=drop chain=input log-prefix="input drop" Adding the /29 to an access list and referencing that via a new firewall rule has resolved our issue. For context, we are running dual-m...