<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Viewing BGP traffic logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/viewing-bgp-traffic-logs/m-p/455937#M101650</link>
    <description>&lt;P&gt;We have BGP setup between our core switches and out Palo Alto FWs but I never see any traffic logs for port 179 or application BGP on the Palo Altos.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do I go about seeing this traffic ?&lt;/P&gt;</description>
    <pubDate>Thu, 30 Dec 2021 01:05:58 GMT</pubDate>
    <dc:creator>iqbal786</dc:creator>
    <dc:date>2021-12-30T01:05:58Z</dc:date>
    <item>
      <title>Viewing BGP traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/viewing-bgp-traffic-logs/m-p/455937#M101650</link>
      <description>&lt;P&gt;We have BGP setup between our core switches and out Palo Alto FWs but I never see any traffic logs for port 179 or application BGP on the Palo Altos.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do I go about seeing this traffic ?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 01:05:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/viewing-bgp-traffic-logs/m-p/455937#M101650</guid>
      <dc:creator>iqbal786</dc:creator>
      <dc:date>2021-12-30T01:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Viewing BGP traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/viewing-bgp-traffic-logs/m-p/455945#M101652</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/204836"&gt;@iqbal786&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no special setting to enable to see BGP traffic log. As long as BGP peer's traffic is hitting a firewall policy where logging is enabled you will be able to see that traffic in the Traffic log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am thinking of 2 reasons why you do not see the log.&lt;/P&gt;&lt;P&gt;- Your BGP traffic might be hitting either: interzone-default or intrazone-default rule where by default logging is not enabled. These rules are located in very bottom and you can override them, then select under actions: Log at session end.&lt;/P&gt;&lt;P&gt;- If you have set BGP peers recently and policy that is being matched has enabled:&amp;nbsp;Log at session end, you will not see any log until BGP peering flaps/resets or you clear BGP peer to end BGP session to generate log. Unless session is ended you will not see any log unless you have enabled&amp;nbsp;Log at session start.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 01:29:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/viewing-bgp-traffic-logs/m-p/455945#M101652</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-12-30T01:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: Viewing BGP traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/viewing-bgp-traffic-logs/m-p/455958#M101654</link>
      <description>&lt;P&gt;So it was the second reason. I didn't realize what what the rule was used for until I broke the network. There were no comments and the rule was overly permissive&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 02:55:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/viewing-bgp-traffic-logs/m-p/455958#M101654</guid>
      <dc:creator>iqbal786</dc:creator>
      <dc:date>2021-12-30T02:55:39Z</dc:date>
    </item>
  </channel>
</rss>

