<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Primary MPLS/BGP and secondary Internet site to site vpn in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/primary-mpls-bgp-and-secondary-internet-site-to-site-vpn/m-p/586425#M117032</link>
    <description>&lt;P&gt;I recently started a new job and they have their firewalls setup with two circuit connections.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Primary is MPLS running BGP and secondary is internet with a Site to Site VPN and static routes pointing to this tunnel.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I'm not aware of what has been set/configured to make the traffic choose the MPLS/BGP interface vs the Site to Site interface, in my mind since the tunnel has static routes pointing to it in the VR it would have precedence. I'm mainly curious for when I need to setup a new site, how to make sure it chooses the MPLS/BGP interface connection over the Site to Site tunnel interface. Thanks in advance.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 12 May 2024 00:53:03 GMT</pubDate>
    <dc:creator>C.Rowe724515</dc:creator>
    <dc:date>2024-05-12T00:53:03Z</dc:date>
    <item>
      <title>Primary MPLS/BGP and secondary Internet site to site vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/primary-mpls-bgp-and-secondary-internet-site-to-site-vpn/m-p/586425#M117032</link>
      <description>&lt;P&gt;I recently started a new job and they have their firewalls setup with two circuit connections.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Primary is MPLS running BGP and secondary is internet with a Site to Site VPN and static routes pointing to this tunnel.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I'm not aware of what has been set/configured to make the traffic choose the MPLS/BGP interface vs the Site to Site interface, in my mind since the tunnel has static routes pointing to it in the VR it would have precedence. I'm mainly curious for when I need to setup a new site, how to make sure it chooses the MPLS/BGP interface connection over the Site to Site tunnel interface. Thanks in advance.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2024 00:53:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/primary-mpls-bgp-and-secondary-internet-site-to-site-vpn/m-p/586425#M117032</guid>
      <dc:creator>C.Rowe724515</dc:creator>
      <dc:date>2024-05-12T00:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Primary MPLS/BGP and secondary Internet site to site vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/primary-mpls-bgp-and-secondary-internet-site-to-site-vpn/m-p/586430#M117033</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/705384019"&gt;@C.Rowe724515&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for posting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are two things that come to my mind. Either BGP learned routes have smaller prefixes compared to what is configured with static routes or static routes are configured with higher administrative distance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you go to: Network &amp;gt; Virtual Router &amp;gt; [VR name] &amp;gt; More Runtime Stats &amp;gt; Routing &amp;gt; Forwarding Table. Refer to destination column, then check subnet masks of routes from remote sites. If these routes have more specific subnet mask to what is configured in static routes, then BGP learned routes will take a precedence.&lt;/P&gt;
&lt;P&gt;Regarding administrative distance, could you go to:&amp;nbsp;Network &amp;gt; Virtual Router &amp;gt; [VR name] &amp;gt; Router Settings, then refer to Administrative Distances. If all prefixes have the same length, then a tie breaker will be the&amp;nbsp;Administrative Distance (Lower value is preferred). In your case if BGP routes are in forwarding table, then static routes should have higher&amp;nbsp;Administrative Distance value than BGP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2024 21:44:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/primary-mpls-bgp-and-secondary-internet-site-to-site-vpn/m-p/586430#M117033</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-05-12T21:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: Primary MPLS/BGP and secondary Internet site to site vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/primary-mpls-bgp-and-secondary-internet-site-to-site-vpn/m-p/586489#M117042</link>
      <description>&lt;P&gt;Thank you, after checking I do see that the routes in the forwarding table are more specific than the static routes which are all /16's.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 12:30:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/primary-mpls-bgp-and-secondary-internet-site-to-site-vpn/m-p/586489#M117042</guid>
      <dc:creator>C.Rowe724515</dc:creator>
      <dc:date>2024-05-13T12:30:02Z</dc:date>
    </item>
  </channel>
</rss>

