<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Conditional Advertisement, Revert Back Options in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/conditional-advertisement-revert-back-options/m-p/1225611#M5766</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/275741"&gt;@jortiztrb&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you provide more details?&amp;nbsp; You have conditional advertisement working.&amp;nbsp; Are you saying that when the Non-Exist prefix comes back, the NGFW does not automatically stop advertising the conditional prefix?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Thu, 03 Apr 2025 17:25:50 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2025-04-03T17:25:50Z</dc:date>
    <item>
      <title>Conditional Advertisement, Revert Back Options</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/conditional-advertisement-revert-back-options/m-p/1225503#M5762</link>
      <description>&lt;P&gt;Good day all, I was working with PA support I may be just be getting confused with the information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to use conditional advertisement to advertise a single subnet via BGP only when another a particular learned route is down. I got this portion working. But, how do I revert back when BGP learned route comes back?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;According to PA support this is not possible. They provided the document below but I still asked the question below&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="caseDetailComment"&gt;
&lt;DIV&gt;
&lt;P&gt;&lt;SPAN&gt;Reference document:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEUCA0" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEUCA0&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;In the scenario explained in the document, once FW-B starts advertising 55.55.55.100 route to FW-C, is there a method to undo this once 100.100.100.0/24 is in the local rib again?&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="caseDetailComment"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 02 Apr 2025 20:48:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/conditional-advertisement-revert-back-options/m-p/1225503#M5762</guid>
      <dc:creator>jortiztrb</dc:creator>
      <dc:date>2025-04-02T20:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: Conditional Advertisement, Revert Back Options</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/conditional-advertisement-revert-back-options/m-p/1225611#M5766</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/275741"&gt;@jortiztrb&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you provide more details?&amp;nbsp; You have conditional advertisement working.&amp;nbsp; Are you saying that when the Non-Exist prefix comes back, the NGFW does not automatically stop advertising the conditional prefix?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 17:25:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/conditional-advertisement-revert-back-options/m-p/1225611#M5766</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-04-03T17:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: Conditional Advertisement, Revert Back Options</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/conditional-advertisement-revert-back-options/m-p/1225624#M5768</link>
      <description>&lt;P&gt;That is correct. Unless I set it up incorrectly. I was able to get the BGP routes advertised when the monitored route went down. However, after route came back up, BGP was still advertising.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 19:21:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/conditional-advertisement-revert-back-options/m-p/1225624#M5768</guid>
      <dc:creator>jortiztrb</dc:creator>
      <dc:date>2025-04-03T19:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: Conditional Advertisement, Revert Back Options</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/conditional-advertisement-revert-back-options/m-p/1225657#M5769</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/275741"&gt;@jortiztrb&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That doesn't make sense.&amp;nbsp; You may be running into a bug.&amp;nbsp; I have configured BGP Conditional Advertisement on Cisco.&amp;nbsp; If you configure it good enough to advertise the route, then it should automatically withdraw it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is a good blog on the topic.&amp;nbsp; &lt;A href="https://blog.davidvassallo.me/2013/04/04/palo-alto-networks-implementing-conditional-advertising-in-bgp/" target="_blank"&gt;https://blog.davidvassallo.me/2013/04/04/palo-alto-networks-implementing-conditional-advertising-in-bgp/&lt;/A&gt;&amp;nbsp; He says&lt;/P&gt;
&lt;P&gt;"And turning it [ the monitored route ] back on reverses it, advertising only to GM, our primary peer."&amp;nbsp; When the conditional prefix is not withdrawn, what does the "show routing protocol bgp policy cond-adv" show?&amp;nbsp; He says you "may need to disable the primary ISP bgp peer, commit, and re-enable the bgp peer." That's a pain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 23:01:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/conditional-advertisement-revert-back-options/m-p/1225657#M5769</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-04-03T23:01:59Z</dc:date>
    </item>
  </channel>
</rss>

