<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can we advertise an IP  of /32  from Palo Alto firewall to TG (Transit gateway) of AWS  via  BGP route advertisement in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/can-we-advertise-an-ip-of-32-from-palo-alto-firewall-to-tg/m-p/405459#M1187</link>
    <description>&lt;P&gt;Couldn't you create another TGW 'behind' the Palo Altos and attach VPC1 and VPC2 to it. This way traffic would have to flow through the Palos which is what you are trying to achieve.&lt;/P&gt;&lt;P&gt;Currently your topology looks as if you have placed all of your EC2 compute in the DMZ in front of the firewall perimeter, except maybe worse as traffic to those hosts is not secured by the firewall, so they are more like bastion hosts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Granted this is all a private network so the above statement is probably not that alarming(!) but it makes more sense to place the compute logically behind the firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers,&lt;/P&gt;&lt;P&gt;Seb.&lt;/P&gt;</description>
    <pubDate>Fri, 07 May 2021 11:33:18 GMT</pubDate>
    <dc:creator>SebRupik</dc:creator>
    <dc:date>2021-05-07T11:33:18Z</dc:date>
    <item>
      <title>Can we advertise an IP  of /32  from Palo Alto firewall to TG (Transit gateway) of AWS  via  BGP route advertisement</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/can-we-advertise-an-ip-of-32-from-palo-alto-firewall-to-tg/m-p/405255#M1184</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Loopback is configured on router in at a HUB&amp;nbsp; site and we want to ping the IP of&amp;nbsp; an instance in&amp;nbsp; VPC-1.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KhurshidAnjum_0-1620318033696.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33681i25DDF197B8BD08D9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="KhurshidAnjum_0-1620318033696.png" alt="KhurshidAnjum_0-1620318033696.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We are advertising the loopback IP (/32) from HUB site as shown in the above diagram. Loopback will be advertised from&amp;nbsp; Hub site to TG (Transit gateway in AWS) via BGP , then this will be advertised from TG &amp;nbsp;to Palo Alto firewall. Again from Palo Alto firewall this loopback should be advertised back to TG and from TG to destination&amp;nbsp; VPC 1.&lt;/P&gt;&lt;P&gt;Can we advertise the loopback IP from firewall back to TG vis BGP route advertisement. If yes , then how.&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2021 16:22:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/can-we-advertise-an-ip-of-32-from-palo-alto-firewall-to-tg/m-p/405255#M1184</guid>
      <dc:creator>KhurshidAnjum</dc:creator>
      <dc:date>2021-05-06T16:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: Can we advertise an IP  of /32  from Palo Alto firewall to TG (Transit gateway) of AWS  via  BGP route advertisement</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/can-we-advertise-an-ip-of-32-from-palo-alto-firewall-to-tg/m-p/405451#M1185</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;The TGW which the DX links are attached to will have been configured with an ASN. This ASN will be part of the AS_PATH attached to the /32 prefix which it is received by the Palo Altos. As such the TGW will not accept /32 being advertised from the Palo Alto as a loop avoidance measure. To mitigate this issue you need to have the TGW ASN only appear once in the routing path.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A possible solution would be to create a VPN tunnel from the on-premise hub site direct to the virtual Palo Alto, then allow the virtual Palo Alto to peer with the TGW via the VPN attachments. The TGW ASN would then only appear once in the AS_PATH.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers,&lt;/P&gt;&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 10:47:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/can-we-advertise-an-ip-of-32-from-palo-alto-firewall-to-tg/m-p/405451#M1185</guid>
      <dc:creator>SebRupik</dc:creator>
      <dc:date>2021-05-07T10:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can we advertise an IP  of /32  from Palo Alto firewall to TG (Transit gateway) of AWS  via  BGP route advertisement</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/can-we-advertise-an-ip-of-32-from-palo-alto-firewall-to-tg/m-p/405458#M1186</link>
      <description>Hi Seb,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks for your suggestion.&lt;BR /&gt;&lt;BR /&gt;Actually we need to land the /32 IPs in TG first as we have to associate this subnet with a routing table in TG.&lt;BR /&gt;&lt;BR /&gt;Hence a direct Tunnel from the Hub site to Palo Alto is not a favourable solution for me.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 07 May 2021 11:20:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/can-we-advertise-an-ip-of-32-from-palo-alto-firewall-to-tg/m-p/405458#M1186</guid>
      <dc:creator>KhurshidAnjum</dc:creator>
      <dc:date>2021-05-07T11:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can we advertise an IP  of /32  from Palo Alto firewall to TG (Transit gateway) of AWS  via  BGP route advertisement</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/can-we-advertise-an-ip-of-32-from-palo-alto-firewall-to-tg/m-p/405459#M1187</link>
      <description>&lt;P&gt;Couldn't you create another TGW 'behind' the Palo Altos and attach VPC1 and VPC2 to it. This way traffic would have to flow through the Palos which is what you are trying to achieve.&lt;/P&gt;&lt;P&gt;Currently your topology looks as if you have placed all of your EC2 compute in the DMZ in front of the firewall perimeter, except maybe worse as traffic to those hosts is not secured by the firewall, so they are more like bastion hosts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Granted this is all a private network so the above statement is probably not that alarming(!) but it makes more sense to place the compute logically behind the firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cheers,&lt;/P&gt;&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 11:33:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/can-we-advertise-an-ip-of-32-from-palo-alto-firewall-to-tg/m-p/405459#M1187</guid>
      <dc:creator>SebRupik</dc:creator>
      <dc:date>2021-05-07T11:33:18Z</dc:date>
    </item>
  </channel>
</rss>

