<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic static route with path monitor down not removing BGP route in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-with-path-monitor-down-not-removing-bgp-route/m-p/1238235#M125164</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I am having issues with trying to get failover setup between vendor routers. We have vendor provided routers at our hub site and at one of our branch sites. We would like to have the traffic be routed to the branch vendor router in the event the hub vendor router is offline. I have setup a static route on the hub firewall to the hub vendor router with path monitor. I have setup a static route on the branch firewall to the branch vendor router with no path monitor and the administrative distance higher than BGP. I have the vendor network prefix to redistribute in both the hub and branch in the panorama sdwan devices. The issue I am seeing is when the hub vendor router is offline, path monitor shows it down but the hub firewall route is still being used. The branch firewall is still trying to use the route to the hub firewall and not advertising its static route to the hub.&amp;nbsp;&amp;nbsp;There must be something I am missing but not where else to look. I have included a generic diagram.&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="vendor-router-failover.jpg" style="width: 854px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69273iA82D4BCAFD1579CD/image-size/large?v=v2&amp;amp;px=999" role="button" title="vendor-router-failover.jpg" alt="vendor-router-failover.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Sep 2025 16:12:24 GMT</pubDate>
    <dc:creator>Clint_UICCU</dc:creator>
    <dc:date>2025-09-17T16:12:24Z</dc:date>
    <item>
      <title>static route with path monitor down not removing BGP route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-with-path-monitor-down-not-removing-bgp-route/m-p/1238235#M125164</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I am having issues with trying to get failover setup between vendor routers. We have vendor provided routers at our hub site and at one of our branch sites. We would like to have the traffic be routed to the branch vendor router in the event the hub vendor router is offline. I have setup a static route on the hub firewall to the hub vendor router with path monitor. I have setup a static route on the branch firewall to the branch vendor router with no path monitor and the administrative distance higher than BGP. I have the vendor network prefix to redistribute in both the hub and branch in the panorama sdwan devices. The issue I am seeing is when the hub vendor router is offline, path monitor shows it down but the hub firewall route is still being used. The branch firewall is still trying to use the route to the hub firewall and not advertising its static route to the hub.&amp;nbsp;&amp;nbsp;There must be something I am missing but not where else to look. I have included a generic diagram.&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="vendor-router-failover.jpg" style="width: 854px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69273iA82D4BCAFD1579CD/image-size/large?v=v2&amp;amp;px=999" role="button" title="vendor-router-failover.jpg" alt="vendor-router-failover.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 16:12:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-with-path-monitor-down-not-removing-bgp-route/m-p/1238235#M125164</guid>
      <dc:creator>Clint_UICCU</dc:creator>
      <dc:date>2025-09-17T16:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: static route with path monitor down not removing BGP route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-with-path-monitor-down-not-removing-bgp-route/m-p/1239849#M125322</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/209312"&gt;@Clint_UICCU&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Are you still experiencing this issue? &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On the hub: &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Confirm the path monitor on the static route to the hub vendor router is actually causing the route to be removed from the hub's routing table when the vendor router is down. If not, the path monitor itself is not functioning as expected and I would recommend going over that config.&amp;nbsp;When path monitoring fails, the static route should be removed from the routing table. Check the RIB and the FIB to ensure its not in play anymore.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Verify that if the static route is being removed, the hub's BGP redistribution is correctly withdrawing that route from its BGP advertisements.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On the branch:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Ensure the static route to the branch vendor router is correctly redistributed into BGP. Next, verify that the BGP export policy on the branch firewall permits the advertisement of this static route to the hub as well as make sure your higher AD is committed successfully.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This should point you towards the right direction in figuring out where exactly this process is failing. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 11:51:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-with-path-monitor-down-not-removing-bgp-route/m-p/1239849#M125322</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2025-10-10T11:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: static route with path monitor down not removing BGP route</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/static-route-with-path-monitor-down-not-removing-bgp-route/m-p/1240529#M125402</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Other things to try:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Policy Based Forwarding. Have a static route that points over the SD-Wan and a Policy Based Forward route that points to the local vendor router. The PBF routes takes effect prior to the default router so it wont mess things up.&lt;/LI&gt;
&lt;LI&gt;OSPF between your devices. This way the routes are learned and if they go down, then it'll take the best path.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 22 Oct 2025 19:23:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/static-route-with-path-monitor-down-not-removing-bgp-route/m-p/1240529#M125402</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-10-22T19:23:44Z</dc:date>
    </item>
  </channel>
</rss>

