<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SDWAN BGP over pre-existing BGP internet. in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/599549#M3837</link>
    <description>&lt;P&gt;- Multi-VR will only work on HUB;&lt;BR /&gt;- And if you want to use both, it`s not possible. It only allows to use one VR in SD-WAN;&lt;BR /&gt;- Loopbacks might be an issue on &lt;STRONG&gt;Global Protect&lt;/STRONG&gt; with SD-WAN.&lt;BR /&gt;&lt;BR /&gt;In&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Oct 2024 14:10:50 GMT</pubDate>
    <dc:creator>Kenya_Vieira</dc:creator>
    <dc:date>2024-10-04T14:10:50Z</dc:date>
    <item>
      <title>SDWAN BGP over pre-existing BGP internet.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598154#M3758</link>
      <description>&lt;P&gt;Hi Guys.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're deploying SDWAN in a customer who already has two ISPs connected in his hub, and talking BGP ECMP with them, using his public ASN and his own prefixes.&lt;/P&gt;
&lt;P&gt;According to documentation, the SDWAN plugin requires the same BGP Router ID and ASN when declaring the hub in devices, but it won't allow to use the public ASN here.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, my question is, do you need to create another VR in order to run a separate BGP process for the SDWAN side of things? Or there's a workaround to directly use the public ASN?. The closest scenario I could find is this one,&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/sd-wan/3-0/sd-wan-admin/configure-sd-wan/configure-multi-vr-on-sd-wan-hub" target="_blank"&gt;https://docs.paloaltonetworks.com/sd-wan/3-0/sd-wan-admin/configure-sd-wan/configure-multi-vr-on-sd-wan-hub&lt;/A&gt;. The main difference is I wouldn't need a VR2, but I'm strugging to understand what interfaces need to be attached to VR1, and how the traffic needs to be forwarded between VRs. If that's the case, I would need to set up and maintain a lot of static routes there right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 17:28:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598154#M3758</guid>
      <dc:creator>PabloArduino</dc:creator>
      <dc:date>2024-09-18T17:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: SDWAN BGP over pre-existing BGP internet.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598175#M3759</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;You shouldn't need two VR's.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLL8CAO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClElCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClElCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 18:21:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598175#M3759</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-09-18T18:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: SDWAN BGP over pre-existing BGP internet.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598178#M3760</link>
      <description>&lt;P&gt;Thanks for the reply. But the problem isn't at the internet side of the firewall. It's on the SDWAN plugin, and it's limitation to only accept private ASNs for its internal BGP routing. On my default virtual router (the one that's similar to the DIA one in the example from my posted link), I'm using the public ASN, because it's not possible to end the AS-Path with a private number. So, to sum it up, ISP faced side cannot use private ASN, and SDWAN plugin doesn't accept public ASNs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 18:26:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598178#M3760</guid>
      <dc:creator>PabloArduino</dc:creator>
      <dc:date>2024-09-18T18:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: SDWAN BGP over pre-existing BGP internet.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598183#M3763</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Sorry I misread you initial question. I think you might need the two VR's. One internal and one external. However I do not use the SDWAN feature.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 18:32:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598183#M3763</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-09-18T18:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: SDWAN BGP over pre-existing BGP internet.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598580#M3790</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I'm encountering a similar scenario.&lt;/P&gt;
&lt;P&gt;In an environment with BGP configured (Public AS), is there any way to use this Public AS in the automation of the SD-WAN plugin within the BGP settings?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have the following topology:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Kenya_Vieira_0-1727114860486.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62363i84F8305D2131AB0F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Kenya_Vieira_0-1727114860486.png" alt="Kenya_Vieira_0-1727114860486.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I try to insert the BGP configurations for automated tunnel creation, I receive a failure notification when inputting this information:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Kenya_Vieira_0-1727117137100.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62365i80BF2A40EDE7BB2D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Kenya_Vieira_0-1727117137100.png" alt="Kenya_Vieira_0-1727117137100.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Kenya_Vieira_1-1727117327673.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62366i70B4209412FFEF54/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Kenya_Vieira_1-1727117327673.png" alt="Kenya_Vieira_1-1727117327673.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;According to the documentation, it should be possible to use BGP in this context, but it doesn’t specify if there are any issues related to using a Public vs. Private AS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The versions I am using are:&lt;BR /&gt;SD-WAN plugin: 3.2.1&lt;BR /&gt;VM-50 device: 11.1.2-h3&lt;BR /&gt;Panorama: 11.1.2-h3&lt;BR /&gt;&lt;BR /&gt;Update:&lt;BR /&gt;The firewall's direct documentation states that Palo Alto's SD-WAN only supports private BGP. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Kenya_Vieira_0-1727118132595.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62367i0E808F381B4F5D69/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Kenya_Vieira_0-1727118132595.png" alt="Kenya_Vieira_0-1727118132595.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/plugins/sd-wan/2-1/panorama-sd-wan-plugin-help/panorama-sd-wan-plugin/sd-wan-devices" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/plugins/sd-wan/2-1/panorama-sd-wan-plugin-help/panorama-sd-wan-plugin/sd-wan-devices&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;However, in my humble opinion, using multi-VR doesn’t solve the scenario, as it’s not possible to add the same device in the SD-WAN automation while needing to use both VRs.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 19:15:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598580#M3790</guid>
      <dc:creator>Kenya_Vieira</dc:creator>
      <dc:date>2024-09-23T19:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: SDWAN BGP over pre-existing BGP internet.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598582#M3791</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;That is beyond my expertise. I would suggest reaching out to your sales engineer, they can message other sales engineers and might be able to answer it for you. However if its preventing you from doing so, there could be a reason why.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 19:40:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598582#M3791</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-09-23T19:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: SDWAN BGP over pre-existing BGP internet.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598664#M3795</link>
      <description>&lt;P&gt;Hi, I couldn't find a solution yet. Using a second VR might fix this problem, but I'm thinking that in the hub, I would need to assign 2 interfaces (loopbacks maybe?) in the upstream NAT section of the plugin. Then NAT and forward traffic from the internet directed to the assigned IP address. In my case would require 2 loopbacks, one for each ISP on the default VR. Such a complication, it would be so much easier to allow public ASNs in the plugin....&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 16:26:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598664#M3795</guid>
      <dc:creator>PabloArduino</dc:creator>
      <dc:date>2024-09-24T16:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: SDWAN BGP over pre-existing BGP internet.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598782#M3804</link>
      <description>&lt;P&gt;Hi, haven't tried yet. But I think we might have something here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/sd-wan/3-0/sd-wan-admin/configure-sd-wan/add-sd-wan-devices-to-panorama/add-an-sd-wan-device" target="_blank"&gt;https://docs.paloaltonetworks.com/sd-wan/3-0/sd-wan-admin/configure-sd-wan/add-sd-wan-devices-to-panorama/add-an-sd-wan-device&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the step 6, says:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ph cmd"&gt;Select the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Virtual Router Name&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to use for routing between the SD-WAN hub and branches. &lt;STRONG&gt;By default, an&amp;nbsp;&lt;SPAN class="ph systemoutput"&gt;sdwan-default&lt;/SPAN&gt;&amp;nbsp;virtual router is created and enables Panorama to automatically push router configurations.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="itemgroup info" data-product="10-2-8-multi-vr-hub" data-label="ADDITIONAL INFORMATION"&gt;
&lt;DIV class="p"&gt;(&lt;TT class="ph tt"&gt;PAN-OS 10.2.8 and later 10.2 releases, and SD-WAN Plugin 3.0.7 and later 3.0 releases&lt;/TT&gt;) When multiple virtual router (&lt;SPAN class="ph uicontrol"&gt;Enable Multi-VR Support&lt;/SPAN&gt;) is enabled, select DIA virtual router for the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Virtual Router Name&lt;/SPAN&gt;.&lt;/DIV&gt;
&lt;DIV class="p"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p"&gt;So, if I'm right, just by ticking that multi VR support box, it should generate that sdwan-default VR just for exchanging sdwan BGP routes over the links.&lt;/DIV&gt;
&lt;DIV class="p"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p"&gt;I won't be able to test it in a few days. If you can check it out, please share your findings.&lt;/DIV&gt;
&lt;DIV class="p"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p"&gt;Thanks&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 25 Sep 2024 18:00:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/598782#M3804</guid>
      <dc:creator>PabloArduino</dc:creator>
      <dc:date>2024-09-25T18:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: SDWAN BGP over pre-existing BGP internet.</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/599549#M3837</link>
      <description>&lt;P&gt;- Multi-VR will only work on HUB;&lt;BR /&gt;- And if you want to use both, it`s not possible. It only allows to use one VR in SD-WAN;&lt;BR /&gt;- Loopbacks might be an issue on &lt;STRONG&gt;Global Protect&lt;/STRONG&gt; with SD-WAN.&lt;BR /&gt;&lt;BR /&gt;In&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 14:10:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/sdwan-bgp-over-pre-existing-bgp-internet/m-p/599549#M3837</guid>
      <dc:creator>Kenya_Vieira</dc:creator>
      <dc:date>2024-10-04T14:10:50Z</dc:date>
    </item>
  </channel>
</rss>

