<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BGP routing question. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-routing-question/m-p/145222#M49013</link>
    <description>&lt;P&gt;I have multiple sites (50+ tunnels) doing ebgp with palo alto(VM-100). So PA is learning smaller subnets from all sites which are known to each other by bgp.&lt;/P&gt;&lt;P&gt;Additionally connected aws doing ebgp which is all good. But number of bgp routes advertised to aws goes above 100 bgp drops( aws can’t accept more than 100 routes).&lt;/P&gt;&lt;P&gt;aws can’t accept default route as they don’t want to come to fw for everything, few things needs to take different route.&lt;/P&gt;&lt;P&gt;I have tried export tab using option to be used by aws only but still (10.48.0.0/12) routes goes above 100. I have tried summarizing routes but then PA will advertise summaries to all the bgp peers which will break routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In theory I should be able to summarize 10.48.0.0/12 and send summary to only aws and not to any other peer&lt;/P&gt;</description>
    <pubDate>Tue, 28 Feb 2017 07:26:57 GMT</pubDate>
    <dc:creator>inderjit21</dc:creator>
    <dc:date>2017-02-28T07:26:57Z</dc:date>
    <item>
      <title>BGP routing question.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-routing-question/m-p/145222#M49013</link>
      <description>&lt;P&gt;I have multiple sites (50+ tunnels) doing ebgp with palo alto(VM-100). So PA is learning smaller subnets from all sites which are known to each other by bgp.&lt;/P&gt;&lt;P&gt;Additionally connected aws doing ebgp which is all good. But number of bgp routes advertised to aws goes above 100 bgp drops( aws can’t accept more than 100 routes).&lt;/P&gt;&lt;P&gt;aws can’t accept default route as they don’t want to come to fw for everything, few things needs to take different route.&lt;/P&gt;&lt;P&gt;I have tried export tab using option to be used by aws only but still (10.48.0.0/12) routes goes above 100. I have tried summarizing routes but then PA will advertise summaries to all the bgp peers which will break routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In theory I should be able to summarize 10.48.0.0/12 and send summary to only aws and not to any other peer&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2017 07:26:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp-routing-question/m-p/145222#M49013</guid>
      <dc:creator>inderjit21</dc:creator>
      <dc:date>2017-02-28T07:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: BGP routing question.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp-routing-question/m-p/145578#M49066</link>
      <description>&lt;P&gt;Use the BGP Aggregate Address functionality.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under your Virtual-Router &amp;gt; BGP &amp;gt; Aggregate &amp;gt; Create an aggregate prefix and set as Summary.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under Export, create a deny rule at the top of the list, and apply it to all peer groups except AWS (Make sure AWS is set up as its own Peer group) match against the prefix that you specified as an aggregate (check exact match).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Create another export rule at the bottom of the list (assuming you don't have any other deny rules), that is applied to your AWS peer group, with a match object of the aggregate prefix, and action allow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: In case it wasn't clear, you don't want any other export policies to match your AWS peer group. Configure your export policies as such that the only rule that matches AWS is the allow rule for the aggregate prefix.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2017 19:13:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp-routing-question/m-p/145578#M49066</guid>
      <dc:creator>Tyler_C</dc:creator>
      <dc:date>2017-03-01T19:13:10Z</dc:date>
    </item>
  </channel>
</rss>

