<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BGP Routing between vION and  Connect Peer TGW in AWS in Prisma SD-WAN Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/bgp-routing-between-vion-and-connect-peer-tgw-in-aws/m-p/1232564#M286</link>
    <description>&lt;P&gt;We have 2 vIONs deployed in AWS which are the Data Center devices and they are not in HA (Standalone). It has a BGP connections to the connect peer TGW (in AWS). How are the subnets of Branch Office advertised from vION to Connect Peer TGW. I can see the route map and prefix list are autogenerated and cannot be manually edited. Additionally I also see from CLI that the list of subnets being advertised via the prefix list varies with time in each vIONs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BGP Peer Type: Core&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jun 2025 09:49:41 GMT</pubDate>
    <dc:creator>M.S049558</dc:creator>
    <dc:date>2025-06-25T09:49:41Z</dc:date>
    <item>
      <title>BGP Routing between vION and  Connect Peer TGW in AWS</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/bgp-routing-between-vion-and-connect-peer-tgw-in-aws/m-p/1232564#M286</link>
      <description>&lt;P&gt;We have 2 vIONs deployed in AWS which are the Data Center devices and they are not in HA (Standalone). It has a BGP connections to the connect peer TGW (in AWS). How are the subnets of Branch Office advertised from vION to Connect Peer TGW. I can see the route map and prefix list are autogenerated and cannot be manually edited. Additionally I also see from CLI that the list of subnets being advertised via the prefix list varies with time in each vIONs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BGP Peer Type: Core&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 09:49:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/bgp-routing-between-vion-and-connect-peer-tgw-in-aws/m-p/1232564#M286</guid>
      <dc:creator>M.S049558</dc:creator>
      <dc:date>2025-06-25T09:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Routing between vION and  Connect Peer TGW in AWS</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/bgp-routing-between-vion-and-connect-peer-tgw-in-aws/m-p/1232578#M287</link>
      <description>&lt;P&gt;What you're seeing is expected, each Branch will chose one DC ION in the cluster as the active device, that DC ION is then responsible for advertising the Branch prefixes via the Core peer, so it's normal to see different subnets being advertised from each DC ION. The DC IONs are not in a HA Group like you would see in a Branch, but they are still HA but running in Active/Active from perspective of the DC, although from an individual Branch they see the DC as Active/Backup, see the diagram to hopefully explain.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Prisma SD-WAN + SASE Architecture - Branch + DC HA (2).png" style="width: 626px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68181iD91F9F05F7A269C2/image-size/large?v=v2&amp;amp;px=999" role="button" title="Prisma SD-WAN + SASE Architecture - Branch + DC HA (2).png" alt="Prisma SD-WAN + SASE Architecture - Branch + DC HA (2).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 12:26:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/bgp-routing-between-vion-and-connect-peer-tgw-in-aws/m-p/1232578#M287</guid>
      <dc:creator>rgallagher</dc:creator>
      <dc:date>2025-06-25T12:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Routing between vION and  Connect Peer TGW in AWS</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/bgp-routing-between-vion-and-connect-peer-tgw-in-aws/m-p/1232579#M288</link>
      <description>&lt;P&gt;Thanks for your response, we are planning for the Upgrade of DC vIONs. If we take down one of the vIONs, will all the subnets be automatically failed over to the other?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example: if we are rebooting vION2, will the subnets being advertised to AWS TGW by the BGP in vION2 automatically switch to advertise through&amp;nbsp;vION1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NOTE: We are running BGP between DC vIONs and AWS TGW (using Connect Peer)&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 13:10:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/bgp-routing-between-vion-and-connect-peer-tgw-in-aws/m-p/1232579#M288</guid>
      <dc:creator>M.S049558</dc:creator>
      <dc:date>2025-06-25T13:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Routing between vION and  Connect Peer TGW in AWS</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/bgp-routing-between-vion-and-connect-peer-tgw-in-aws/m-p/1232582#M289</link>
      <description>&lt;P&gt;Yes that's right, the active VPN will just failover automatically to the ION that is not being upgraded.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 14:38:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/bgp-routing-between-vion-and-connect-peer-tgw-in-aws/m-p/1232582#M289</guid>
      <dc:creator>rgallagher</dc:creator>
      <dc:date>2025-06-25T14:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Routing between vION and  Connect Peer TGW in AWS</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/bgp-routing-between-vion-and-connect-peer-tgw-in-aws/m-p/1232884#M290</link>
      <description>&lt;P&gt;Hi Richard,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just one last question, how does the Branch ION choose which DC ION to send the traffic (Active Tunnel). Are there any criteria or metrics.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2025 12:42:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/bgp-routing-between-vion-and-connect-peer-tgw-in-aws/m-p/1232884#M290</guid>
      <dc:creator>M.S049558</dc:creator>
      <dc:date>2025-06-30T12:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Routing between vION and  Connect Peer TGW in AWS</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/bgp-routing-between-vion-and-connect-peer-tgw-in-aws/m-p/1233425#M291</link>
      <description>&lt;P&gt;It's somewhat arbitrary given the DC ION that it choses will move after VPN flaps etc and therefore not persistent, but typically it will be the first one to come up.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 13:10:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/bgp-routing-between-vion-and-connect-peer-tgw-in-aws/m-p/1233425#M291</guid>
      <dc:creator>rgallagher</dc:creator>
      <dc:date>2025-07-07T13:10:10Z</dc:date>
    </item>
  </channel>
</rss>

