<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN-OS 10.2 : filter incoming OSPF routes in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-10-2-filter-incoming-ospf-routes/m-p/487040#M104675</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;If it is not the way to do that, how can we filter incoming prefix with OSPF ?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;</description>
    <pubDate>Fri, 13 May 2022 09:32:04 GMT</pubDate>
    <dc:creator>vloirat44</dc:creator>
    <dc:date>2022-05-13T09:32:04Z</dc:date>
    <item>
      <title>PAN-OS 10.2 : filter incoming OSPF routes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-10-2-filter-incoming-ospf-routes/m-p/486690#M104629</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to setup OSPFv2 between a PA-5220 in 10.2 and a Cisco ACI Fabric with "Advanced Routing" enabled.&lt;/P&gt;&lt;P&gt;For now, we are able to advertise routes to our ACI Fabric, we can filter outgoing advertisement but we are unable to filter incoming routes. We tried with RIB Filter - OSPFv2 without success (&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/network/network-routing-logical-routers/network-routing-logical-routers-general" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/network/network-routing-logical-routers/network-routing-logical-routers-general&lt;/A&gt;) :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EmilienRichard_1-1652344524666.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40965i2C223332EC89F0DC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="EmilienRichard_1-1652344524666.png" alt="EmilienRichard_1-1652344524666.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EmilienRichard_3-1652344694867.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40967i9C6A69B70AE79267/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="EmilienRichard_3-1652344694867.png" alt="EmilienRichard_3-1652344694867.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EmilienRichard_4-1652344728564.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40968iAF7A5D1562978BEF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="EmilienRichard_4-1652344728564.png" alt="EmilienRichard_4-1652344728564.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have-you an idea of what we are missing ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Emilien&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 08:41:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-10-2-filter-incoming-ospf-routes/m-p/486690#M104629</guid>
      <dc:creator>EmilienRichard</dc:creator>
      <dc:date>2022-05-12T08:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 10.2 : filter incoming OSPF routes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-10-2-filter-incoming-ospf-routes/m-p/487040#M104675</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;If it is not the way to do that, how can we filter incoming prefix with OSPF ?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2022 09:32:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-10-2-filter-incoming-ospf-routes/m-p/487040#M104675</guid>
      <dc:creator>vloirat44</dc:creator>
      <dc:date>2022-05-13T09:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 10.2 : filter incoming OSPF routes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-10-2-filter-incoming-ospf-routes/m-p/487085#M104680</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Please remember with OSPF in general there is no way to filter prefixes within the area, as all routers in the area should agree on the LSA database. Removing routes from the RIB, yet still having corresponding LSAs is a very bad practice. If you are looking for prefix filtering, follow OSPF design requirements for that (such as stub areas).&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2022 13:41:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-10-2-filter-incoming-ospf-routes/m-p/487085#M104680</guid>
      <dc:creator>rivanov</dc:creator>
      <dc:date>2022-05-13T13:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 10.2 : filter incoming OSPF routes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-10-2-filter-incoming-ospf-routes/m-p/487217#M104697</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/219137"&gt;@EmilienRichard&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with OSPF, the filtering of prefixes is typically done on device that is either ABR or ASBR. I have to admit that I have no hands on experience with Advanced Routing Engine, however by looking into documentation:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/advanced-routing/create-filters-for-the-advanced-routing-engine" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/advanced-routing/create-filters-for-the-advanced-routing-engine&lt;/A&gt;&amp;nbsp;under section:&amp;nbsp;Prefix Lists, there is below point:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1652537419039.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40994i7BEE08477660BCBA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1652537419039.png" alt="PavelK_0-1652537419039.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;From the screen shots you provided, it is not clear whether ACI is in a different OSPF area or the same area. If both devices are in the same area, then this would be my first guess that this is a reason why inbound filter does not work as Palo Alto firewall is not ABR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I would be in your place and OSPF area re-design would be an option on the table, I would place ACI into non backbone area and used the same filter you already created.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Sat, 14 May 2022 14:19:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-10-2-filter-incoming-ospf-routes/m-p/487217#M104697</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-05-14T14:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 10.2 : filter incoming OSPF routes</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-10-2-filter-incoming-ospf-routes/m-p/496810#M105115</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We tried to filter incoming OSPF routes without success so we switched to a BGP peering with our ACI Fabric and we configured inbound prefix filtering :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EmilienRichard_0-1654072806639.png" style="width: 697px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41524i611A832787A3A01E/image-dimensions/697x357/is-moderation-mode/true?v=v2" width="697" height="357" role="button" title="EmilienRichard_0-1654072806639.png" alt="EmilienRichard_0-1654072806639.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;with a prefix list :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EmilienRichard_1-1654072884491.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41525i0D2E9757F4666483/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="EmilienRichard_1-1654072884491.png" alt="EmilienRichard_1-1654072884491.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 08:44:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-10-2-filter-incoming-ospf-routes/m-p/496810#M105115</guid>
      <dc:creator>EmilienRichard</dc:creator>
      <dc:date>2022-06-01T08:44:23Z</dc:date>
    </item>
  </channel>
</rss>

