<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BGP, Community settings for Prisma in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/bgp-community-settings-for-prisma/m-p/332210#M100</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have some questions regarding community settings because we use this in our org to influence routes selection.&lt;/P&gt;&lt;P&gt;Based on this document "&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prepare-the-prisma-access-infrastructure/route-preferences-for-service-connection-traffic.html" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prepare-the-prisma-access-infrastructure/route-preferences-for-service-connection-traffic.html&lt;/A&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Are the communities referred in it "65534:X "&amp;nbsp;"65534:Y "&amp;nbsp;"65534:Z " refers to the prisma mobile users IP pools allocation setting per region?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) When we clicked on the BGP status, network detailed of the service connections, the community number shown in it refers to what? The X Y Z which i mentioned in point 1 above? I have 3 service connections (2 in US and 1 in EU and none in Asia).. these 3 service connections gave me different community numbers, so which is which region?&lt;BR /&gt;&lt;BR /&gt;3) The document only mentioned about mobile users IP prefixes.. I also uses Remote Network (traditional IPSEC) into Prisma.. i like to control the return routes of which service connection to be use based on community.. how do we do what community is being set based on the Prisma Access Locations? Is there a list published somewhere on the community numbers? If i checked on the IP prefix of the remote site specifically, i do see a community tag to it... searching all the BGP Ip prefix will be a big chore, will be good if the community numbers tagging is published somewhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jun 2020 03:34:29 GMT</pubDate>
    <dc:creator>CharlesKoh</dc:creator>
    <dc:date>2020-06-08T03:34:29Z</dc:date>
    <item>
      <title>BGP, Community settings for Prisma</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/bgp-community-settings-for-prisma/m-p/332210#M100</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have some questions regarding community settings because we use this in our org to influence routes selection.&lt;/P&gt;&lt;P&gt;Based on this document "&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prepare-the-prisma-access-infrastructure/route-preferences-for-service-connection-traffic.html" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-access/prisma-access-panorama-admin/prepare-the-prisma-access-infrastructure/route-preferences-for-service-connection-traffic.html&lt;/A&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Are the communities referred in it "65534:X "&amp;nbsp;"65534:Y "&amp;nbsp;"65534:Z " refers to the prisma mobile users IP pools allocation setting per region?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) When we clicked on the BGP status, network detailed of the service connections, the community number shown in it refers to what? The X Y Z which i mentioned in point 1 above? I have 3 service connections (2 in US and 1 in EU and none in Asia).. these 3 service connections gave me different community numbers, so which is which region?&lt;BR /&gt;&lt;BR /&gt;3) The document only mentioned about mobile users IP prefixes.. I also uses Remote Network (traditional IPSEC) into Prisma.. i like to control the return routes of which service connection to be use based on community.. how do we do what community is being set based on the Prisma Access Locations? Is there a list published somewhere on the community numbers? If i checked on the IP prefix of the remote site specifically, i do see a community tag to it... searching all the BGP Ip prefix will be a big chore, will be good if the community numbers tagging is published somewhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 03:34:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/bgp-community-settings-for-prisma/m-p/332210#M100</guid>
      <dc:creator>CharlesKoh</dc:creator>
      <dc:date>2020-06-08T03:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: BGP, Community settings for Prisma</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/bgp-community-settings-for-prisma/m-p/333478#M114</link>
      <description>&lt;P&gt;Hi Charles,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are replies inline to your questions:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Are the communities referred in it "65534:X "&amp;nbsp;"65534:Y "&amp;nbsp;"65534:Z " refers to the prisma mobile users IP pools allocation setting per region?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;The routes are Mobile User User pool addresses you have onboarded in certain regions. We will split up those larger pools into /24 blocks and tag then with the Prisma Access AS number /Community Strings&amp;nbsp; (65534:x). The X/Y/Z is per Service Connection. You can say "regional" yes.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) When we clicked on the BGP status, network detailed of the service connections, the community number shown in it refers to what? The X Y Z which i mentioned in point 1 above? I have 3 service connections (2 in US and 1 in EU and none in Asia).. these 3 service connections gave me different community numbers, so which is which region?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;The community string tag it is using is an ID of the active FW for the original active Service Connection Firewall.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;3) The document only mentioned about mobile users IP prefixes.. I also uses Remote Network (traditional IPSEC) into Prisma.. i like to control the return routes of which service connection to be use based on community.. how do we do what community is being set based on the Prisma Access Locations? Is there a list published somewhere on the community numbers? If i checked on the IP prefix of the remote site specifically, i do see a community tag to it... searching all the BGP Ip prefix will be a big chore, will be good if the community numbers tagging is published somewhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;You can see the ID's in Panorama Managed Prisma Access GUI page:&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;FONT color="#FF0000"&gt;Panorama &amp;gt;&amp;gt;&amp;gt; Cloud Services &amp;gt;&amp;gt;&amp;gt;Status &amp;gt;&amp;gt;&amp;gt; Network Details &amp;gt;&amp;gt;&amp;gt; Service Connection &amp;gt;&amp;gt;&amp;gt; Show BGP Status&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT color="#FF0000"&gt;(Look at the Community field)&amp;nbsp;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT color="#FF0000"&gt;The community tags should be mostly static, so once you have mapped them out they should stay consistent unless you re-onboard the SC.&lt;/FONT&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I hope this helps!&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Wade&lt;/FONT&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 15 Jun 2020 17:39:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/bgp-community-settings-for-prisma/m-p/333478#M114</guid>
      <dc:creator>wprice</dc:creator>
      <dc:date>2020-06-15T17:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: BGP, Community settings for Prisma</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/bgp-community-settings-for-prisma/m-p/333561#M115</link>
      <description>&lt;P&gt;Hi Wade,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for replying.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just further question on the point 3 with regards to Remote Network sites. I do see the community setting based on the BGP status of the remote network. But on my CPE peering with service connections, i checked the BGP prefixes advertised by these remote sites, i do not see the community tag on it like what i've seen on the mobile user prefixes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that the case it should be?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 00:53:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/bgp-community-settings-for-prisma/m-p/333561#M115</guid>
      <dc:creator>CharlesKoh</dc:creator>
      <dc:date>2020-06-16T00:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: BGP, Community settings for Prisma</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/bgp-community-settings-for-prisma/m-p/333718#M116</link>
      <description>&lt;P&gt;Hi Charles,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We do not tag the Remote Network prefixes with a community string, because we fully mesh the RNs to each Service connection. If all you want to do is identify which routes are RN's you can tag them by advertising them from the branch with a global or regional community string tag and we will advertise / preserve them to the SC with those Community value tags. If you want to identify which regions are which routes, you can advertise specific community tags for specific "regions" or "Geos".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Wade&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 22:10:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/bgp-community-settings-for-prisma/m-p/333718#M116</guid>
      <dc:creator>wprice</dc:creator>
      <dc:date>2020-06-16T22:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: BGP, Community settings for Prisma</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/bgp-community-settings-for-prisma/m-p/415256#M202</link>
      <description>&lt;P&gt;Hi Wade,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that Prisma will advertise the User Mobile IP Pool prefixes using the previously mentioned Community Strings over BGP Peering Sessions inside the Service Connection. There will be in&amp;nbsp;region a Primary Tunnel and Secondary with Tertiary Tunnels in another region. Is there a way for Prisma to signal over the various BGP Peerings which Tunnel is the Primary Tunnel in an effort to avoid asymmetric routing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Paul.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 14:56:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/bgp-community-settings-for-prisma/m-p/415256#M202</guid>
      <dc:creator>Paul_Timmons</dc:creator>
      <dc:date>2021-06-25T14:56:57Z</dc:date>
    </item>
  </channel>
</rss>

