<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BGP Session flaps for every 3 minutes - PAN OS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-session-flaps-for-every-3-minutes-pan-os/m-p/447212#M100662</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a BGP running over IPSec VPN. The VPN is terminated between PA 5250 and SDN Gateway. The VPN is running fine but the BGP session is flapping for every 3 minutes. Normally this behavior observed due to MTU size detection in during PMTUD in Cisco devices.&amp;nbsp; Please help me to troubleshoot this further in the Palo Alto Firewall side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(active)&amp;gt; show routing protocol bgp peer peer-name ClientName-Int&lt;/P&gt;&lt;P&gt;==========&lt;BR /&gt;Peer: ClientName-Int (id 4)&lt;BR /&gt;virtual router: ClientName&lt;BR /&gt;Peer router id: 10.33.0.2&lt;BR /&gt;Remote AS: 64512&lt;BR /&gt;Peer group: PG_ClientName_Int (id 18)&lt;BR /&gt;Peer status: Established, for 179 seconds&lt;BR /&gt;Password set: no&lt;BR /&gt;Passive: no&lt;BR /&gt;Multi-hop TTL: 4&lt;BR /&gt;Remote Address: 10.33.0.2:179&lt;BR /&gt;Local Address: 10.204.22.230:53976&lt;BR /&gt;(R) reflector client: not-client&lt;BR /&gt;same confederation: no&lt;BR /&gt;send aggr confed as-path: yes&lt;BR /&gt;peering type: Unspecified&lt;BR /&gt;Connect-Retry interval: 1&lt;BR /&gt;Open Delay: 0&lt;BR /&gt;Idle Hold: 15&lt;BR /&gt;Prefix limit: 5000&lt;BR /&gt;Holdtime: 180 (config 3600)&lt;BR /&gt;Keep-Alive interval: 1 (config 30)&lt;BR /&gt;Update messages: in 780, out 18513&lt;BR /&gt;Total messages: in 3103, out 19697&lt;BR /&gt;Last update age: 23&lt;BR /&gt;Last error: HoldTimer expired (4)&lt;BR /&gt;Flap counts: 4655, established 390 times&lt;BR /&gt;(R) ORF entries: 0&lt;BR /&gt;Nexthop set to self: no&lt;BR /&gt;use 3rd party as next-hop: yes&lt;BR /&gt;override nexthop to peer: no&lt;BR /&gt;----------&lt;BR /&gt;remove private AS number: yes&lt;BR /&gt;----------&lt;BR /&gt;Capability: Multiprotocol Extensions(1) value: IPv4 Unicast&lt;BR /&gt;Capability: Route Refresh(yes)&lt;BR /&gt;----------&lt;BR /&gt;Prefix counter for: bgpAfiIpv4 / unicast&lt;BR /&gt;Incoming Prefix: Accepted 48, Rejected 2, Policy Rej 0, Total 50&lt;BR /&gt;Outgoing Prefix: 1513&lt;BR /&gt;Advertised Prefix: 264&lt;/P&gt;&lt;P&gt;(active)&amp;gt; show routing protocol bgp peer peer-name ClientName-Int&lt;/P&gt;&lt;P&gt;==========&lt;BR /&gt;Peer: ClientName-Int (id 4)&lt;BR /&gt;virtual router: ClientName&lt;BR /&gt;Peer router id: 10.33.0.2&lt;BR /&gt;Remote AS: 64512&lt;BR /&gt;Peer group: PG_ClientName_Int (id 18)&lt;BR /&gt;Peer status: Idle, for 0 seconds&lt;BR /&gt;Password set: no&lt;BR /&gt;Passive: no&lt;BR /&gt;Multi-hop TTL: 4&lt;BR /&gt;Remote Address: 10.33.0.2&lt;BR /&gt;Local Address: 10.204.22.230&lt;BR /&gt;(R) reflector client: not-client&lt;BR /&gt;same confederation: no&lt;BR /&gt;send aggr confed as-path: yes&lt;BR /&gt;peering type: Unspecified&lt;BR /&gt;Connect-Retry interval: 1&lt;BR /&gt;Open Delay: 0&lt;BR /&gt;Idle Hold: 15&lt;BR /&gt;Prefix limit: 5000&lt;BR /&gt;Holdtime: 180 (config 3600)&lt;BR /&gt;Keep-Alive interval: 1 (config 30)&lt;BR /&gt;Update messages: in 780, out 18513&lt;BR /&gt;Total messages: in 3104, out 19697&lt;BR /&gt;Last update age: 0&lt;BR /&gt;Last error: HoldTimer expired (4)&lt;BR /&gt;Flap counts: 4656, established 390 times&lt;BR /&gt;(R) ORF entries: 0&lt;BR /&gt;Nexthop set to self: no&lt;BR /&gt;use 3rd party as next-hop: yes&lt;BR /&gt;override nexthop to peer: no&lt;BR /&gt;----------&lt;BR /&gt;remove private AS number: yes&lt;BR /&gt;----------&lt;/P&gt;</description>
    <pubDate>Fri, 12 Nov 2021 14:23:13 GMT</pubDate>
    <dc:creator>ArunkumarDurais</dc:creator>
    <dc:date>2021-11-12T14:23:13Z</dc:date>
    <item>
      <title>BGP Session flaps for every 3 minutes - PAN OS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-session-flaps-for-every-3-minutes-pan-os/m-p/447212#M100662</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a BGP running over IPSec VPN. The VPN is terminated between PA 5250 and SDN Gateway. The VPN is running fine but the BGP session is flapping for every 3 minutes. Normally this behavior observed due to MTU size detection in during PMTUD in Cisco devices.&amp;nbsp; Please help me to troubleshoot this further in the Palo Alto Firewall side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(active)&amp;gt; show routing protocol bgp peer peer-name ClientName-Int&lt;/P&gt;&lt;P&gt;==========&lt;BR /&gt;Peer: ClientName-Int (id 4)&lt;BR /&gt;virtual router: ClientName&lt;BR /&gt;Peer router id: 10.33.0.2&lt;BR /&gt;Remote AS: 64512&lt;BR /&gt;Peer group: PG_ClientName_Int (id 18)&lt;BR /&gt;Peer status: Established, for 179 seconds&lt;BR /&gt;Password set: no&lt;BR /&gt;Passive: no&lt;BR /&gt;Multi-hop TTL: 4&lt;BR /&gt;Remote Address: 10.33.0.2:179&lt;BR /&gt;Local Address: 10.204.22.230:53976&lt;BR /&gt;(R) reflector client: not-client&lt;BR /&gt;same confederation: no&lt;BR /&gt;send aggr confed as-path: yes&lt;BR /&gt;peering type: Unspecified&lt;BR /&gt;Connect-Retry interval: 1&lt;BR /&gt;Open Delay: 0&lt;BR /&gt;Idle Hold: 15&lt;BR /&gt;Prefix limit: 5000&lt;BR /&gt;Holdtime: 180 (config 3600)&lt;BR /&gt;Keep-Alive interval: 1 (config 30)&lt;BR /&gt;Update messages: in 780, out 18513&lt;BR /&gt;Total messages: in 3103, out 19697&lt;BR /&gt;Last update age: 23&lt;BR /&gt;Last error: HoldTimer expired (4)&lt;BR /&gt;Flap counts: 4655, established 390 times&lt;BR /&gt;(R) ORF entries: 0&lt;BR /&gt;Nexthop set to self: no&lt;BR /&gt;use 3rd party as next-hop: yes&lt;BR /&gt;override nexthop to peer: no&lt;BR /&gt;----------&lt;BR /&gt;remove private AS number: yes&lt;BR /&gt;----------&lt;BR /&gt;Capability: Multiprotocol Extensions(1) value: IPv4 Unicast&lt;BR /&gt;Capability: Route Refresh(yes)&lt;BR /&gt;----------&lt;BR /&gt;Prefix counter for: bgpAfiIpv4 / unicast&lt;BR /&gt;Incoming Prefix: Accepted 48, Rejected 2, Policy Rej 0, Total 50&lt;BR /&gt;Outgoing Prefix: 1513&lt;BR /&gt;Advertised Prefix: 264&lt;/P&gt;&lt;P&gt;(active)&amp;gt; show routing protocol bgp peer peer-name ClientName-Int&lt;/P&gt;&lt;P&gt;==========&lt;BR /&gt;Peer: ClientName-Int (id 4)&lt;BR /&gt;virtual router: ClientName&lt;BR /&gt;Peer router id: 10.33.0.2&lt;BR /&gt;Remote AS: 64512&lt;BR /&gt;Peer group: PG_ClientName_Int (id 18)&lt;BR /&gt;Peer status: Idle, for 0 seconds&lt;BR /&gt;Password set: no&lt;BR /&gt;Passive: no&lt;BR /&gt;Multi-hop TTL: 4&lt;BR /&gt;Remote Address: 10.33.0.2&lt;BR /&gt;Local Address: 10.204.22.230&lt;BR /&gt;(R) reflector client: not-client&lt;BR /&gt;same confederation: no&lt;BR /&gt;send aggr confed as-path: yes&lt;BR /&gt;peering type: Unspecified&lt;BR /&gt;Connect-Retry interval: 1&lt;BR /&gt;Open Delay: 0&lt;BR /&gt;Idle Hold: 15&lt;BR /&gt;Prefix limit: 5000&lt;BR /&gt;Holdtime: 180 (config 3600)&lt;BR /&gt;Keep-Alive interval: 1 (config 30)&lt;BR /&gt;Update messages: in 780, out 18513&lt;BR /&gt;Total messages: in 3104, out 19697&lt;BR /&gt;Last update age: 0&lt;BR /&gt;Last error: HoldTimer expired (4)&lt;BR /&gt;Flap counts: 4656, established 390 times&lt;BR /&gt;(R) ORF entries: 0&lt;BR /&gt;Nexthop set to self: no&lt;BR /&gt;use 3rd party as next-hop: yes&lt;BR /&gt;override nexthop to peer: no&lt;BR /&gt;----------&lt;BR /&gt;remove private AS number: yes&lt;BR /&gt;----------&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 14:23:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp-session-flaps-for-every-3-minutes-pan-os/m-p/447212#M100662</guid>
      <dc:creator>ArunkumarDurais</dc:creator>
      <dc:date>2021-11-12T14:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Session flaps for every 3 minutes - PAN OS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-session-flaps-for-every-3-minutes-pan-os/m-p/447279#M100668</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/167879"&gt;@ArunkumarDurais&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;- Have you compare all timers between the PAN FW and Cisco? I believe some of the BGP timers default values are different for the two vendors&lt;/P&gt;
&lt;P&gt;- Have you tried to run packet capture for the BGP session on the PAN FW?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 18:42:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp-session-flaps-for-every-3-minutes-pan-os/m-p/447279#M100668</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-11-12T18:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Session flaps for every 3 minutes - PAN OS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-session-flaps-for-every-3-minutes-pan-os/m-p/448792#M100850</link>
      <description>&lt;P&gt;Hi Astardzheiv,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The peer end is actually SDN gateway. We can see there is a BGP notification message is being sent from SDN gateway to Palo alto for hold timers, then BGP is going to idle state. The flap is happening exactly after 180 seconds and it is idle for 15 seconds and established again every time. Is it might be SDN gateway have 180 seconds as in the timer and its trying to re-established every time.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Naspers_2-1637407324017.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37761iD81ED44B947F7E4B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Naspers_2-1637407324017.png" alt="Naspers_2-1637407324017.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Nov 2021 11:23:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp-session-flaps-for-every-3-minutes-pan-os/m-p/448792#M100850</guid>
      <dc:creator>ArunkumarDurais</dc:creator>
      <dc:date>2021-11-20T11:23:32Z</dc:date>
    </item>
  </channel>
</rss>

