<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic BGP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/bgp/m-p/190020#M57422</link>
    <description>&lt;P&gt;hello i am new to palo alto&amp;nbsp;&lt;/P&gt;&lt;P&gt;i recently configured bgp on my palo alto pa 500 device and my bgp peer is getting connected and then after a minute it gets disconnected and the bgp state becomes active. also i am using md5 key for authentication. could you please help me with a possible solution or reason. thank you&lt;/P&gt;</description>
    <pubDate>Tue, 05 Dec 2017 07:19:09 GMT</pubDate>
    <dc:creator>CirrostratusNetworks</dc:creator>
    <dc:date>2017-12-05T07:19:09Z</dc:date>
    <item>
      <title>BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp/m-p/190020#M57422</link>
      <description>&lt;P&gt;hello i am new to palo alto&amp;nbsp;&lt;/P&gt;&lt;P&gt;i recently configured bgp on my palo alto pa 500 device and my bgp peer is getting connected and then after a minute it gets disconnected and the bgp state becomes active. also i am using md5 key for authentication. could you please help me with a possible solution or reason. thank you&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 07:19:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp/m-p/190020#M57422</guid>
      <dc:creator>CirrostratusNetworks</dc:creator>
      <dc:date>2017-12-05T07:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp/m-p/190053#M57426</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/50811"&gt;@CirrostratusNetworks&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It would help to know how you set it up.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The forwarding table size for the PA-500 supports upto&amp;nbsp;1250 entries.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will need more debugging.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Start with enabling debug on BGP:&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;admin@PA-VM&amp;gt; debug routing pcap bgp on&lt;/PRE&gt;
&lt;P&gt;You can view with:&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;admin@PA-VM&amp;gt; debug routing pcap bgp view&lt;/PRE&gt;
&lt;P&gt;or even follow live with:&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;admin@PA-VM&amp;gt; view-pcap follow yes debug-pcap &amp;lt;bgp_capture_file&amp;gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 10:33:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp/m-p/190053#M57426</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-12-05T10:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp/m-p/190067#M57434</link>
      <description>&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;Thank you for your reply&lt;/P&gt;&lt;P&gt;I am getting the following messages&amp;nbsp;&lt;SPAN&gt;BGP peer MP extension negotiation. MP-EXTENSION negotiation to peer&amp;nbsp; successful, AFI/SAFI 1/1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;BGP peer session enters established state. peer IP:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;BGP peer session left established state. peer IP:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also the peer side has more than 2000 bgp routes and the number of forwarding routes on pa 500 device from our end is only 24.&amp;nbsp; so does those routes count too from the peer side ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also on the peer side they are getting the following log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Error wait: 63/300&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Last error: Received: Malformed AS_PATH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank You for your support.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Param&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 11:27:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp/m-p/190067#M57434</guid>
      <dc:creator>CirrostratusNetworks</dc:creator>
      <dc:date>2017-12-05T11:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp/m-p/190124#M57445</link>
      <description>&lt;P&gt;&lt;SPAN&gt;If the peer is advertising all 2000+ prefixes to you, then it will be a problem.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you need all 2000 prefixes?&amp;nbsp;You can configure inbound rules to permit specific prefixes or maybe the peer could send a summary.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 17:00:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp/m-p/190124#M57445</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2017-12-05T17:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp/m-p/190134#M57449</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt;&amp;nbsp;thank you&lt;/P&gt;&lt;P&gt;Actually we are connected to the internet exchange with palo alto pa 500 so we need all the routes.&lt;/P&gt;&lt;P&gt;since it is not an isp we cannot configure default route or receive a summary&lt;/P&gt;&lt;P&gt;currently the only option available is to configure inbound rules to permit specific prefixes as per your suggestion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any other alternative or do i have to upgrade to another device due to hardware ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;param&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 17:22:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp/m-p/190134#M57449</guid>
      <dc:creator>CirrostratusNetworks</dc:creator>
      <dc:date>2017-12-05T17:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp/m-p/190145#M57452</link>
      <description>&lt;P&gt;You can create filters but that would be used to allow only certain prefixes. Some would be blocked so you wouldn't have routes to these networks.&lt;/P&gt;&lt;P&gt;If you need to support over 2000 prefixes, you'll need a larger device.&amp;nbsp; &amp;nbsp;You should check with your reseller or PA to size correctly.&lt;/P&gt;&lt;P&gt;Also, for the malformed AS message, are you using a 2 byte or 4 byte AS number? Did you select the correct option in the BGP config on the PA?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 17:51:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp/m-p/190145#M57452</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2017-12-05T17:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: BGP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bgp/m-p/190353#M57495</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt;&amp;nbsp;sir i am using 4byte AS number.&lt;/P&gt;&lt;P&gt;Also i have created route filter but still BGP is getting connected and then disconnected.&lt;/P&gt;&lt;P&gt;so that is also not working. what could be the possbile issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 14:39:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bgp/m-p/190353#M57495</guid>
      <dc:creator>CirrostratusNetworks</dc:creator>
      <dc:date>2017-12-06T14:39:24Z</dc:date>
    </item>
  </channel>
</rss>

