<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BGP session flapping with error code 3 subcode 11 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-session-flapping-with-error-code-3-subcode-11/m-p/587961#M117264</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have an issue with setting up a BGP Establish connection. On my side is a PA firewall connected to the a ISP with BGP session. The first time, the ISP side sent only the default route to PA, and there was no problem in the BGP session. And now we require the full routing table that involves 4000+ routes sent to us. And I do a Max-prefix=400 on my side. After that, the BGP session is flapping all the time. It will reset the peer session every 60 sec or 30 sec. And I notice that there is an error on PA, it shows error code 3 subcode 11 in PA.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HenryITP_0-1716779129951.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60049i11B370CE37928BB4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="HenryITP_0-1716779129951.png" alt="HenryITP_0-1716779129951.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And there are some configure that show you to reference.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HenryITP_1-1716779216937.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60050iFD8B3E17F6F36FCB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="HenryITP_1-1716779216937.png" alt="HenryITP_1-1716779216937.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HenryITP_2-1716779245756.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60051i8B560C19E7F0F67E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="HenryITP_2-1716779245756.png" alt="HenryITP_2-1716779245756.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I am not very&amp;nbsp;familiar with PA firewall, if you guys have any idea or any other info want to see, please tell me! This case is very urgent! Thank you guys!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 27 May 2024 03:11:30 GMT</pubDate>
    <dc:creator>Henry-ITP</dc:creator>
    <dc:date>2024-05-27T03:11:30Z</dc:date>
    <item>
      <title>BGP session flapping with error code 3 subcode 11</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-session-flapping-with-error-code-3-subcode-11/m-p/587961#M117264</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have an issue with setting up a BGP Establish connection. On my side is a PA firewall connected to the a ISP with BGP session. The first time, the ISP side sent only the default route to PA, and there was no problem in the BGP session. And now we require the full routing table that involves 4000+ routes sent to us. And I do a Max-prefix=400 on my side. After that, the BGP session is flapping all the time. It will reset the peer session every 60 sec or 30 sec. And I notice that there is an error on PA, it shows error code 3 subcode 11 in PA.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HenryITP_0-1716779129951.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60049i11B370CE37928BB4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="HenryITP_0-1716779129951.png" alt="HenryITP_0-1716779129951.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And there are some configure that show you to reference.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HenryITP_1-1716779216937.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60050iFD8B3E17F6F36FCB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="HenryITP_1-1716779216937.png" alt="HenryITP_1-1716779216937.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HenryITP_2-1716779245756.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60051i8B560C19E7F0F67E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="HenryITP_2-1716779245756.png" alt="HenryITP_2-1716779245756.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I am not very&amp;nbsp;familiar with PA firewall, if you guys have any idea or any other info want to see, please tell me! This case is very urgent! Thank you guys!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 03:11:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp-session-flapping-with-error-code-3-subcode-11/m-p/587961#M117264</guid>
      <dc:creator>Henry-ITP</dc:creator>
      <dc:date>2024-05-27T03:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: BGP session flapping with error code 3 subcode 11</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-session-flapping-with-error-code-3-subcode-11/m-p/588002#M117269</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/666927525"&gt;@Henry-ITP&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It looks like the EBGP neighbors are not transitioning to established state due to the reason that Palo Alto Firewall reject the BGP connection since it treats the AS Sequence in the AS_PATH Attribute advertised by the EBGP peer as Malformed AS_PATH or Unacceptable AS_PATH.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Palo Alto Networks Firewall has a default behavior in which the EBGP neighbor that advertises the AS_PATH attributes&amp;nbsp;in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700);"&gt;BGP UPDATE&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;message will be inspected, &amp;nbsp;The firewall expect the EBGP neighbors to fill the neighbor's own AS number as the first AS number while advertising the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700);"&gt;AS_PATH&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;attributes. The PAN-OS behavior is to drop the connection as&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700);"&gt;PAN-OS&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is enabled with&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700);"&gt;Enforce First AS for EBGP&amp;nbsp;&lt;/STRONG&gt;by default.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will see the error &lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700);"&gt;AS-PATH Unacceptable &lt;/STRONG&gt;in the output of&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700);"&gt; &amp;gt;show routing protocol bgp peer &amp;lt;peer-name&amp;gt; virtual-router default.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The routed debug outputs collected using the command&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700);"&gt;&amp;gt;debug routed on debug&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;will show the following error snippets while tailing the debug logs:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Error code = UPDATE Message Error (3)
Error subcode = Malformed AS_PATH (11)&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Examine and compare the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700); color: #181818; font-family: -apple-system, 'system-ui', 'Segoe UI', Roboto, Helvetica, Arial, sans-serif, 'Apple Color Emoji', 'Segoe UI Emoji', 'Segoe UI Symbol'; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;BGP UPDATE&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;messages&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700); color: #181818; font-family: -apple-system, 'system-ui', 'Segoe UI', Roboto, Helvetica, Arial, sans-serif, 'Apple Color Emoji', 'Segoe UI Emoji', 'Segoe UI Symbol'; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt; BGP Attributes&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;in the BGP packet captures with the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700); color: #181818; font-family: -apple-system, 'system-ui', 'Segoe UI', Roboto, Helvetica, Arial, sans-serif, 'Apple Color Emoji', 'Segoe UI Emoji', 'Segoe UI Symbol'; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;&amp;nbsp;&amp;gt;show routing protocol BGP peer &amp;lt;peer-name&amp;gt;&amp;nbsp; virtual-router default&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;output to determine if the remote AS number seen as in&amp;nbsp;the output is advertised&amp;nbsp;in the top left or as the first AS in the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700); color: #181818; font-family: -apple-system, 'system-ui', 'Segoe UI', Roboto, Helvetica, Arial, sans-serif, 'Apple Color Emoji', 'Segoe UI Emoji', 'Segoe UI Symbol'; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;AS_PATH Attribute&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;in the&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700); color: #181818; font-family: -apple-system, 'system-ui', 'Segoe UI', Roboto, Helvetica, Arial, sans-serif, 'Apple Color Emoji', 'Segoe UI Emoji', 'Segoe UI Symbol'; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;BGP UPDATE&amp;nbsp;message packet.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A solution here would be to configure the EBGP Peer to append the AS Path attributes&amp;nbsp;in a manner that&amp;nbsp;includes it's own AS as left most AS or the first of&amp;nbsp;the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700);"&gt;AS_PATH&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;attributes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Work-around configuration that Palo Alto Networks provides to address this situation is to disable the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700);"&gt;Enforce First AS-Option&lt;/STRONG&gt;&amp;nbsp;in the&amp;nbsp;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700);"&gt;BGP &amp;gt;&amp;nbsp;Advanced&amp;nbsp;&lt;/STRONG&gt;settings from the&amp;nbsp;&lt;STRONG style="box-sizing: border-box; font-weight: var(--lwc-fontWeightBold,700);"&gt;Network&amp;gt;Virtual Router&lt;/STRONG&gt;s. (Step 4 - &lt;A style="box-sizing: border-box; background-color: #ffffff; color: var(--lwc-brandtextlink,#0176d3); text-decoration: none; transition: color 0.1s linear 0s; cursor: pointer; font-family: -apple-system, 'system-ui', 'Segoe UI', Roboto, Helvetica, Arial, sans-serif, 'Apple Color Emoji', 'Segoe UI Emoji', 'Segoe UI Symbol'; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal;" href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/bgp/configure-bgp" target="_blank" rel="noopener" data-aura-rendered-by="259:41924;a"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/bgp/configure-bgp&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2024 09:58:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp-session-flapping-with-error-code-3-subcode-11/m-p/588002#M117269</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-05-27T09:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: BGP session flapping with error code 3 subcode 11</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-session-flapping-with-error-code-3-subcode-11/m-p/588196#M117294</link>
      <description>&lt;P&gt;Hi Kiwi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your help!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I checked the pacp and found there are some of prefixes sent by the provider do not incloud the right AS-number at the first place in AS-path attribute. I have already told them and let them diagnose.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I still have another question about max-prefix setting. If set max-prefix=400, and the provider gives more than 400+ prefixes, will the peer session shutdown immediately?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Henry.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 04:08:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp-session-flapping-with-error-code-3-subcode-11/m-p/588196#M117294</guid>
      <dc:creator>Henry-ITP</dc:creator>
      <dc:date>2024-05-29T04:08:25Z</dc:date>
    </item>
  </channel>
</rss>

