<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto  rejecting one route in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/495837#M105096</link>
    <description>&lt;P&gt;I do see the PAN AS in the path for 10.240.0.0/16, didn't notice that as it is not expected. The 10.242.0.0/16 route is learned from the same neighbor and is just another route same as the 10.240, the PAN AS does not show up in this one, odd. Both routes are out the same interface and are NOT learned from any other peer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why would the PAN place it's own AS here?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the help Astardzhiev&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2022 15:56:30 GMT</pubDate>
    <dc:creator>StevenTurner</dc:creator>
    <dc:date>2022-05-31T15:56:30Z</dc:date>
    <item>
      <title>Palo Alto  rejecting one route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/491086#M104938</link>
      <description>&lt;P&gt;I'm having trouble seeing one route in my RIB and FIB. My BGP peer shows it is advertising the route to the Palo Alto, however I see the following when showing the peer at the PAN:&lt;/P&gt;&lt;P&gt;sstadmin@200-PFW-01&amp;gt; show routing protocol bgp peer peer-name DMVPN-Router&lt;/P&gt;&lt;P&gt;Prefix counter for: bgpAfiIpv4 / unicast&lt;BR /&gt;Incoming Prefix: Accepted 49, Rejected 0, Policy Rej 1, Total 49&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Notice one router is rejected by policy. I feel this is my missing route. FYI the reject default route but is not ticked in the BGP configuration, so this rejected route is not that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is causing this one rejected route by policy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 22:10:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/491086#M104938</guid>
      <dc:creator>StevenTurner</dc:creator>
      <dc:date>2022-05-24T22:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  rejecting one route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/491139#M104939</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110489"&gt;@StevenTurner&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just looked into my BGP peer and I can see hundreds of policy rejected routes. In my case, I credit this to BGP Import map with exact match. Import list would be the first thing I would be looking into. If you have any filter in place, add this route to the list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 00:23:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/491139#M104939</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-05-25T00:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  rejecting one route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/491172#M104940</link>
      <description>Thanks for the reply. My import list is allow 10.0.0.0/16 &amp;amp; the route I’m missing is 10.240.0.0/16. Exact match is not checked. It’s odd to me as non of my FW are having this drop by policy ticking. They are all on the same template with the same BGP peer.&lt;BR /&gt;&lt;BR /&gt;I’m have trouble finding any documentation on what this policy deny is meaning.&lt;BR /&gt;&lt;BR /&gt;Anyone know?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;</description>
      <pubDate>Wed, 25 May 2022 02:37:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/491172#M104940</guid>
      <dc:creator>StevenTurner</dc:creator>
      <dc:date>2022-05-25T02:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  rejecting one route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/491177#M104941</link>
      <description>&lt;P&gt;Do you have 10.240.0.0/16 allowed on an import list? That doesn't fall in 10.0.0.0/16.&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 02:58:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/491177#M104941</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2022-05-25T02:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  rejecting one route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/491920#M104970</link>
      <description>&lt;P&gt;Sorry, you are correct. My allow list is 10.0.0.0/8. Had a brain fart.&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 19:10:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/491920#M104970</guid>
      <dc:creator>StevenTurner</dc:creator>
      <dc:date>2022-05-25T19:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  rejecting one route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/491922#M104971</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StevenTurner_0-1653506017036.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41147iF91F028DB3908D98/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="StevenTurner_0-1653506017036.png" alt="StevenTurner_0-1653506017036.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;screen shot of my Import rule "Import-From-DMVPN" is the one we are looking at. The exact match button is not checked.&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 19:15:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/491922#M104971</guid>
      <dc:creator>StevenTurner</dc:creator>
      <dc:date>2022-05-25T19:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  rejecting one route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/492075#M104973</link>
      <description>&lt;P&gt;Have you looked at routed.log or run any debugs or captures? The captures could verify you're receiving the prefix and the log may show why it's not being installed.&lt;/P&gt;&lt;P&gt;If the advertising device of 10.240.0.0 is an ibgp neighbor, is 'next-hop-self' configured? Maybe the advertised next hop for 10.240.0.0 isn't reachable by the PA?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2022 00:04:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/492075#M104973</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2022-05-26T00:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  rejecting one route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/492089#M104974</link>
      <description>&lt;P&gt;The peer is ebgp. The next hop is available, same as all the other routes. That is the oddity here, this route is no different than all the others.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What logs and degus would you recommend? I have not had much experience going down that route to troubleshoot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2022 00:30:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/492089#M104974</guid>
      <dc:creator>StevenTurner</dc:creator>
      <dc:date>2022-05-26T00:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  rejecting one route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/492561#M104985</link>
      <description>&lt;P&gt;In Monitor-Packet Capture, you could start a capture on a specific interface, with filters for the BGP peer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then reset the BGP peer so that you can generate some fresh traffic for the capture and logs. If you go through the capture in Wireshark, you can find which prefixes are being sent from the peer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You might find something interesting with these at the CLI:&lt;/P&gt;&lt;P&gt;show log system direction equal backward subtype equal routing&lt;/P&gt;&lt;P&gt;less mp-log routed.log&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2022 15:05:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/492561#M104985</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2022-05-26T15:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  rejecting one route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/493719#M105019</link>
      <description>&lt;P&gt;So with a capture I can see my route getting sent in the update message. In fact, I see a second route 10.242.0.0/16 that is accepted and placed in the fib. However the 10.240.0.0/16 seems to be rejected. Next hop on both destinations is the same. The suggested logs did not produce any insight to the cause.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;10.200.250.26 - is the PAN&lt;/P&gt;&lt;P&gt;10.200.250.25 - is the DMVP peer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StevenTurner_0-1653665913900.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41447i1865F5DC6412B965/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="StevenTurner_0-1653665913900.png" alt="StevenTurner_0-1653665913900.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 15:40:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/493719#M105019</guid>
      <dc:creator>StevenTurner</dc:creator>
      <dc:date>2022-05-27T15:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  rejecting one route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/494283#M105051</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110489"&gt;@StevenTurner&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Unfortunately I also not able to explain what "reject by policy" means, but looking at the two screenshots you provide it seems the prefix is rejected because of the BGP loop prevention:&lt;/P&gt;
&lt;P&gt;- From first screenshot it seems that PAN FW is using ASN 65200&lt;/P&gt;
&lt;P&gt;- From the packet capture screenshot you can see that 65200 is part of the AS PATH advertised for this prefix. BGP loop prevention will reject any prefix when it sees its own ASN in the path. You can see that for 10.24&lt;STRONG&gt;2&lt;/STRONG&gt;.0.0/16 FW ASN is no in the AS PATH, therefor it is accepted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are absolutetly sure that you need to accept this prefix, even if FW ASN is in AS PATH, you can tell the firewall to remove specific AS from the path with Import rule. That way BGP loop prevention will not kick in and will accept the route. The following link gives example how to configure Import rule that will remove ASN &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEkCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEkCAK&lt;/A&gt; In the example they use regex, that will remove any of the two ASN, but in your case you can simply remove only 65200&lt;/P&gt;</description>
      <pubDate>Sun, 29 May 2022 06:44:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/494283#M105051</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-05-29T06:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  rejecting one route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/495837#M105096</link>
      <description>&lt;P&gt;I do see the PAN AS in the path for 10.240.0.0/16, didn't notice that as it is not expected. The 10.242.0.0/16 route is learned from the same neighbor and is just another route same as the 10.240, the PAN AS does not show up in this one, odd. Both routes are out the same interface and are NOT learned from any other peer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why would the PAN place it's own AS here?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the help Astardzhiev&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 15:56:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/495837#M105096</guid>
      <dc:creator>StevenTurner</dc:creator>
      <dc:date>2022-05-31T15:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  rejecting one route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/495857#M105098</link>
      <description>&lt;P&gt;The PAN didn't place it's own AS in the path, that was inserted along the way. It looks like 10.240 was originated by AS 65201, which peers with AS 65200. Is there another 65200, or another device besides the PAN in 65200?&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 16:08:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/495857#M105098</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2022-05-31T16:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto  rejecting one route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/496021#M105106</link>
      <description>&lt;P&gt;One of my peers did remember another site using the same AS. Didn't even know it was there. Thanks for the help&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 17:57:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-rejecting-one-route/m-p/496021#M105106</guid>
      <dc:creator>StevenTurner</dc:creator>
      <dc:date>2022-05-31T17:57:33Z</dc:date>
    </item>
  </channel>
</rss>

