<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prisma Access Cloudblade BGP options in Prisma SD-WAN CloudBlades Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-cloudblades/prisma-access-cloudblade-bgp-options/m-p/590638#M4</link>
    <description>&lt;P&gt;I hope you found your answer by now, but to answer the question: Yes, with a twist.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unchecking that instructs Prisma Access not to advertise learned routes from RNs down to the other RNs. The main purpose of this feature is to allow for site to site traffic within Prisma Access and for other mechanisms like traffic steering, etc. That said, keep in mind that this is relevant only to Remote Networks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mobile Users isn't on the same network as Remote Networks (separate routing domains) so having this enabled doesn't impact the routing of Mobile Users unless you have service connections that have the RN subnets defined where the MU traffic can hairpin. Without other SCs that advertise the specifc RN subnets into MU (called dummy SCs since they don't terminate), the traffic will go to the nearest (or only) SC that has the best match for the destination prefix and thus to the endpoint they terminate to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Miguel&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jun 2024 17:47:25 GMT</pubDate>
    <dc:creator>miguel_mejia</dc:creator>
    <dc:date>2024-06-27T17:47:25Z</dc:date>
    <item>
      <title>Prisma Access Cloudblade BGP options</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-cloudblades/prisma-access-cloudblade-bgp-options/m-p/576837#M3</link>
      <description>&lt;P&gt;I have a question on one of the BGP settings when Cloudblades is set up.&lt;/P&gt;
&lt;P&gt;In the BGP config on the site, one of the options is "Prisma forward received Branch Routes from Prisma SD-WAN"&lt;/P&gt;
&lt;P&gt;Would leaving this unchecked be the equivalent of setting a BGP no-advertise community string?&lt;/P&gt;
&lt;P&gt;My customer doesn't have the network-interconnect license for Prisma so I need to ensure that traffic from mobile users to remote networks doesn't go direct as it will drop. I need the traffic to go back down the service connection and to the DC IONs and over the fabric.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Prisma SD-WAN" id="Prisma_SD-WAN"&gt;&lt;/LI-PRODUCT&gt; &lt;LI-PRODUCT title="Prisma Access" id="Prisma_Access"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 15:29:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-cloudblades/prisma-access-cloudblade-bgp-options/m-p/576837#M3</guid>
      <dc:creator>Jon_Woloshyn</dc:creator>
      <dc:date>2024-02-09T15:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Cloudblade BGP options</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-cloudblades/prisma-access-cloudblade-bgp-options/m-p/590638#M4</link>
      <description>&lt;P&gt;I hope you found your answer by now, but to answer the question: Yes, with a twist.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unchecking that instructs Prisma Access not to advertise learned routes from RNs down to the other RNs. The main purpose of this feature is to allow for site to site traffic within Prisma Access and for other mechanisms like traffic steering, etc. That said, keep in mind that this is relevant only to Remote Networks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mobile Users isn't on the same network as Remote Networks (separate routing domains) so having this enabled doesn't impact the routing of Mobile Users unless you have service connections that have the RN subnets defined where the MU traffic can hairpin. Without other SCs that advertise the specifc RN subnets into MU (called dummy SCs since they don't terminate), the traffic will go to the nearest (or only) SC that has the best match for the destination prefix and thus to the endpoint they terminate to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Miguel&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 17:47:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-cloudblades/prisma-access-cloudblade-bgp-options/m-p/590638#M4</guid>
      <dc:creator>miguel_mejia</dc:creator>
      <dc:date>2024-06-27T17:47:25Z</dc:date>
    </item>
  </channel>
</rss>

