Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

BGP AS-Path allow

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

BGP AS-Path allow

L3 Networker

Hi All,

 

I suspect the answer to this is in the Advanced Routing in PanOS 10.

 

We have configured a new system as Active-Active and BGP. The firewalls are in different DCs, the DMZ side of the firewall can talk to routers in both DCs but only its local router on the WAN side. If one DC goes down, the other firewall with a less favourable route from said DC would route for the named subnets. The requirement is to advertise the AS Number from the system on the DMZ to the WAN network so that the WAN router has both firewall and DMZ AS-Numbers for the return path and vice versa in the DMZ - this is so path selection can be performed within the DMZ BGP and WAN environment rather than on the firewall. Currently, the Palo Alto substitutes the AS-Number with its own AS so to make a path less favourable we need to perform AS-Prepending on certain paths.

 

Is there a way to achieve this on PanOS 9.1.14-h4 or is this an Advanced Routing requirement.

 

Regards

 

Adrian

3 REPLIES 3

L5 Sessionator

So are you looking for the PA to prepend AS to the path? That's definitely possible in any version of PAN-OS. Export rule actions have specific AS path options for prepend, remove and remove + prepend.

Hi,

 

I understand how to prepend the AS. What I was questioning was can the received AS seen in the Local RIB be included in the export and not replaced as we are seeing. So the connecting router path check would see the AS Number of the device behind the firewall rather than just the firewall.

With eBGP, the default option when creating a peer on the PA is to remove private AS. Is eBGP being used on the PA with the other devices and other AS are private?

  • 2265 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!