<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BGP AS-Path allow in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-as-path-allow/m-p/518563#M107578</link>
    <description>&lt;P&gt;With eBGP, the default option when creating a peer on the PA is to remove private AS. Is eBGP being used on the PA with the other devices and other AS are private?&lt;/P&gt;</description>
    <pubDate>Thu, 20 Oct 2022 20:19:08 GMT</pubDate>
    <dc:creator>rmfalconer</dc:creator>
    <dc:date>2022-10-20T20:19:08Z</dc:date>
    <item>
      <title>BGP AS-Path allow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-as-path-allow/m-p/517465#M107390</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I suspect the answer to this is in the Advanced Routing in PanOS 10.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have configured a new system as Active-Active and BGP. The firewalls are in different DCs, the DMZ side of the firewall can talk to routers in both DCs but only its local router on the WAN side. If one DC goes down, the other firewall with a less favourable route from said DC would route for the named subnets. The requirement is to advertise the AS Number from the system on the DMZ to the WAN network so that the WAN router has both firewall and DMZ AS-Numbers for the return path and vice versa in the DMZ - this is so path selection can be performed within the DMZ BGP and WAN environment rather than on the firewall. Currently, the Palo Alto substitutes the AS-Number with its own AS so to make a path less favourable we need to perform AS-Prepending on certain paths.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to achieve this on PanOS 9.1.14-h4 or is this an Advanced Routing requirement.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Adrian&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 14:43:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp-as-path-allow/m-p/517465#M107390</guid>
      <dc:creator>a.jones</dc:creator>
      <dc:date>2022-10-11T14:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: BGP AS-Path allow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-as-path-allow/m-p/517642#M107411</link>
      <description>&lt;P&gt;So are you looking for the PA to prepend AS to the path? That's definitely possible in any version of PAN-OS. Export rule actions have specific AS path options for prepend, remove and remove + prepend.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 16:02:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp-as-path-allow/m-p/517642#M107411</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2022-10-12T16:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: BGP AS-Path allow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-as-path-allow/m-p/517771#M107432</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand how to prepend the AS. What I was questioning was can the received AS seen in the Local RIB be included in the export and not replaced as we are seeing. So the connecting router path check would see the AS Number of the device behind the firewall rather than just the firewall.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 10:31:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp-as-path-allow/m-p/517771#M107432</guid>
      <dc:creator>a.jones</dc:creator>
      <dc:date>2022-10-13T10:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: BGP AS-Path allow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-as-path-allow/m-p/518563#M107578</link>
      <description>&lt;P&gt;With eBGP, the default option when creating a peer on the PA is to remove private AS. Is eBGP being used on the PA with the other devices and other AS are private?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 20:19:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp-as-path-allow/m-p/518563#M107578</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2022-10-20T20:19:08Z</dc:date>
    </item>
  </channel>
</rss>

