<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to implement BGP and eBGP on Palo in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-implement-bgp-and-ebgp-on-palo/m-p/524586#M108536</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BTW,, if you need the BGP learned best routes to be installed in the routing table, add this from CLI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;[edit]&lt;BR /&gt;admin@PAFW1# set network virtual-router default protocol bgp install-route yes&lt;BR /&gt;&lt;BR /&gt;[edit]&lt;BR /&gt;&lt;A href="mailto:admin@PAFW1" target="_blank"&gt;admin@PAFW1#commit&lt;/A&gt;&lt;BR /&gt;[edit]&lt;BR /&gt;admin@PAFW1# run show routing route type bgp  &lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Dec 2022 11:34:56 GMT</pubDate>
    <dc:creator>rkvsenthil</dc:creator>
    <dc:date>2022-12-20T11:34:56Z</dc:date>
    <item>
      <title>How to implement BGP and eBGP on Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-implement-bgp-and-ebgp-on-palo/m-p/524353#M108499</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am migrating WatchGuard to Palo and there seems to be a lot more configuration options on the Palo.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WatchGuard configuration is below. What is the best way to configure this within Palo?&lt;/P&gt;
&lt;P&gt;Where is the option to set default-originate?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;router bgp 64801&lt;BR /&gt;bgp router-id 169.254.3.3&lt;BR /&gt;timers bgp 4 12&lt;BR /&gt;neighbor 10.200.34.2 remote-as 64601&lt;BR /&gt;neighbor 10.200.34.3 remote-as 64601&lt;BR /&gt;neighbor 10.200.52.2 remote-as 64601&lt;BR /&gt;neighbor 10.200.52.3 remote-as 64601&lt;BR /&gt;neighbor 10.200.64.130 remote-as 64601&lt;BR /&gt;neighbor 10.200.64.131 remote-as 64601&lt;BR /&gt;neighbor 10.200.34.2 default-originate&lt;BR /&gt;neighbor 10.200.34.3 default-originate&lt;BR /&gt;neighbor 10.200.52.2 default-originate&lt;BR /&gt;neighbor 10.200.52.3 default-originate&lt;BR /&gt;neighbor 10.200.64.130 default-originate&lt;BR /&gt;neighbor 10.200.64.131 default-originate&lt;BR /&gt;neighbor 10.200.34.2 ebgp-multihop 4&lt;BR /&gt;neighbor 10.200.34.3 ebgp-multihop 4&lt;BR /&gt;neighbor 10.200.52.2 ebgp-multihop 4&lt;BR /&gt;neighbor 10.200.52.3 ebgp-multihop 4&lt;BR /&gt;neighbor 10.200.64.130 ebgp-multihop 4&lt;BR /&gt;neighbor 10.200.64.131 ebgp-multihop 4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 09:23:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-implement-bgp-and-ebgp-on-palo/m-p/524353#M108499</guid>
      <dc:creator>LimaSupport</dc:creator>
      <dc:date>2022-12-16T09:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to implement BGP and eBGP on Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-implement-bgp-and-ebgp-on-palo/m-p/524580#M108535</link>
      <description>&lt;P&gt;&lt;STRONG&gt;For default-originate&lt;/STRONG&gt; -- In GUI,, go to Network -- Virtual Router --&amp;nbsp; &amp;lt;VR name or default&amp;gt; --- BGP --- Redist Rule and&amp;nbsp;&amp;nbsp;add a Redistribution rule for ip subnet 0.0.0.0/0 and enable "Allow Redistribute Default route" option ..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also,, use the below config example as template. This should give you clues on how and where, you can change the timer settings and TTL value (ebgp-multihop), etc..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;admin@PAFW1&amp;gt; configure&lt;BR /&gt;&lt;BR /&gt;set network virtual-router default protocol bgp enable yes&lt;BR /&gt;set network virtual-router default protocol bgp routing-options graceful-restart enable yes&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers type ebgp remove-private-as no&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers type ebgp import-nexthop original&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers type ebgp export-nexthop resolve&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 peer-address ip 10.0.18.2&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 connection-options incoming-bgp-connection remote-port 0&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 connection-options incoming-bgp-connection allow yes&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 connection-options outgoing-bgp-connection local-port 0&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 connection-options outgoing-bgp-connection allow yes&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 connection-options multihop 0&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 connection-options keep-alive-interval 30&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 connection-options open-delay-time 0&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 connection-options hold-time 90&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 connection-options idle-hold-time 15&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 connection-options min-route-adv-interval 30&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 subsequent-address-family-identifier unicast yes&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 subsequent-address-family-identifier multicast no&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 local-address ip 10.0.18.1/30&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 local-address interface ethernet1/1&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 bfd profile Inherit-vr-global-setting&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 max-prefixes 5000&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 enable yes&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 peer-as 64513&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 enable-mp-bgp no&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 address-family-identifier ipv4&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 enable-sender-side-loop-detection no&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 reflector-client non-client&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer upstream_R5 peering-type unspecified&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 peer-address ip 100.100.100.1&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 connection-options incoming-bgp-connection remote-port 0&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 connection-options incoming-bgp-connection allow yes&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 connection-options outgoing-bgp-connection local-port 0&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 connection-options outgoing-bgp-connection allow yes&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 connection-options multihop 4&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 connection-options keep-alive-interval 30&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 connection-options open-delay-time 0&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 connection-options hold-time 90&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 connection-options idle-hold-time 15&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 connection-options min-route-adv-interval 30&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 subsequent-address-family-identifier unicast yes&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 subsequent-address-family-identifier multicast no&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 local-address ip 192.168.102.2/30&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 local-address interface ethernet1/2&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 bfd profile Inherit-vr-global-setting&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 max-prefixes 5000&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 enable yes&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 peer-as 64512&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 enable-mp-bgp no&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 address-family-identifier ipv4&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 enable-sender-side-loop-detection no&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 reflector-client non-client&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers peer inside_core_2 peering-type bilateral&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers aggregated-confed-as-path yes&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers soft-reset-with-stored-info yes&lt;BR /&gt;set network virtual-router default protocol bgp peer-group stub_ebgp_peers enable yes&lt;BR /&gt;set network virtual-router default protocol bgp reject-default-route no&lt;BR /&gt;set network virtual-router default protocol bgp allow-redist-default-route yes&lt;BR /&gt;set network virtual-router default protocol bgp router-id 192.168.102.2&lt;BR /&gt;set network virtual-router default protocol bgp local-as 65535&lt;BR /&gt;set network virtual-router default protocol bgp redist-rules 0.0.0.0/0 address-family-identifier ipv4&lt;BR /&gt;set network virtual-router default protocol bgp redist-rules 0.0.0.0/0 enable yes&lt;BR /&gt;set network virtual-router default protocol bgp redist-rules 0.0.0.0/0 set-origin incomplete&lt;BR /&gt;set network virtual-router default protocol bgp policy export rules default-route-only action allow update as-path none&lt;BR /&gt;set network virtual-router default protocol bgp policy export rules default-route-only action allow update origin incomplete&lt;BR /&gt;set network virtual-router default protocol bgp policy export rules default-route-only action allow update community none&lt;BR /&gt;set network virtual-router default protocol bgp policy export rules default-route-only action allow update extended-community none&lt;BR /&gt;set network virtual-router default protocol bgp policy export rules default-route-only match address-prefix 0.0.0.0/0 exact no&lt;BR /&gt;set network virtual-router default protocol bgp policy export rules default-route-only match route-table unicast&lt;BR /&gt;set network virtual-router default protocol bgp policy export rules default-route-only used-by stub_ebgp_peers&lt;BR /&gt;set network virtual-router default protocol bgp policy export rules default-route-only enable yes&lt;BR /&gt;[edit]&lt;BR /&gt;admin@PAFW1# commit&lt;BR /&gt;Commit job 6 is in progress. Use Ctrl+C to return to command prompt&lt;BR /&gt;..........100%&lt;BR /&gt;Configuration committed successfully&lt;BR /&gt;[edit]&lt;BR /&gt;admin@PAFW1# run show routing protocol bgp rib-out&lt;BR /&gt;&lt;BR /&gt;VIRTUAL ROUTER: default (id 1)&lt;BR /&gt;==========&lt;BR /&gt;Prefix Nexthop Peer Originator Adv Status Aggr Status AS-Path&lt;BR /&gt;0.0.0.0/0 10.0.18.1 upstream_R5 0.0.0.0 advertised no aggregation 65535&lt;BR /&gt;192.168.100.0/30 10.0.18.1 upstream_R5 0.0.0.0 advertised no aggregation 65535,64512&lt;BR /&gt;192.168.101.0/30 10.0.18.1 upstream_R5 0.0.0.0 advertised no aggregation 65535,64512&lt;BR /&gt;0.0.0.0/0 192.168.102.2 inside_core_2 0.0.0.0 advertised no aggregation 65535&lt;BR /&gt;5.5.5.5/32 192.168.102.2 inside_core_2 0.0.0.0 advertised no aggregation 65535,64513&lt;BR /&gt;&lt;BR /&gt;total routes shown: 5&lt;BR /&gt;&lt;BR /&gt;[edit]&lt;BR /&gt;admin@PAFW1# set network virtual-router default protocol bgp policy export rules default-route-only match address-prefix 0.0.0.0/0 exact yes&lt;BR /&gt;&lt;BR /&gt;[edit]&lt;BR /&gt;admin@PAFW1# commit&lt;BR /&gt;Commit job 6 is in progress. Use Ctrl+C to return to command prompt&lt;BR /&gt;..........100%&lt;BR /&gt;Configuration committed successfully&lt;BR /&gt;&lt;BR /&gt;[edit]&lt;BR /&gt;admin@PAFW1# run show routing protocol bgp rib-out&lt;BR /&gt;&lt;BR /&gt;VIRTUAL ROUTER: default (id 1)&lt;BR /&gt;==========&lt;BR /&gt;Prefix Nexthop Peer Originator Adv Status Aggr Status AS-Path&lt;BR /&gt;0.0.0.0/0 10.0.18.1 upstream_R5 0.0.0.0 advertised no aggregation 65535&lt;BR /&gt;0.0.0.0/0 192.168.102.2 inside_core_2 0.0.0.0 advertised no aggregation 65535&lt;BR /&gt;&lt;BR /&gt;total routes shown: 2&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 11:16:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-implement-bgp-and-ebgp-on-palo/m-p/524580#M108535</guid>
      <dc:creator>rkvsenthil</dc:creator>
      <dc:date>2022-12-20T11:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to implement BGP and eBGP on Palo</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-implement-bgp-and-ebgp-on-palo/m-p/524586#M108536</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BTW,, if you need the BGP learned best routes to be installed in the routing table, add this from CLI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;[edit]&lt;BR /&gt;admin@PAFW1# set network virtual-router default protocol bgp install-route yes&lt;BR /&gt;&lt;BR /&gt;[edit]&lt;BR /&gt;&lt;A href="mailto:admin@PAFW1" target="_blank"&gt;admin@PAFW1#commit&lt;/A&gt;&lt;BR /&gt;[edit]&lt;BR /&gt;admin@PAFW1# run show routing route type bgp  &lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 11:34:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-implement-bgp-and-ebgp-on-palo/m-p/524586#M108536</guid>
      <dc:creator>rkvsenthil</dc:creator>
      <dc:date>2022-12-20T11:34:56Z</dc:date>
    </item>
  </channel>
</rss>

