How to drop or reject an OSPF route in PA 3000 series if it receives a route from another vendor FW

Reply
Highlighted
L2 Linker

How to drop or reject an OSPF route in PA 3000 series if it receives a route from another vendor FW

In the data center end, the Cisco ASA firewall is advertising the OSPF route and at the perimeter end Palo alto receives the route, and PA will be forward that route toward Internet communication.

 
Expectation, if any, specific route received by Palo alto, it should be rejected or drop on Palo alto itself. Should not forward to any next hop.

 

How we can achieve in Palo Alto Firewall.

Highlighted
L7 Applicator

Re: How to drop or reject an OSPF route in PA 3000 series if it receives a route from another vendor

@Mohammed_Yasin,

You'll need to update your redistribution profile and ensure that you actually have the OSPF filters properly setup, sounds like you currently aren't doing anything for filtering. 

Highlighted
L2 Linker

Re: How to drop or reject an OSPF route in PA 3000 series if it receives a route from another vendor

Thank you for your comments:

 

I am looking for something similar like to suppress or LSA controller

 

Example: if I have multiple branches across the city. Connected to DC, I mean Cisco router (Branch) connected to the Cisco ASA and the Cisco firewall as a DC FW and it's connected to Paloalto as a perimeter firewall.

 

If any host wants have to access the perimeter end.

The host comes to DC firewall which is a Cisco ASA and Cisco has a role to forward the route to next-hop and its forwarding to Palo alto firewall as receiving and the route is an OSPF Route protocol

 

Now exception: if Palo alto receives an OSPF route from is neighbor CISCO ASA, and if OSPF has 10 routes in the table. Here Palo alto has to take a decision on receiving the OSPF route, it should filter the route and have to forward on his next hope or Palo alto have reject either drop itself.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!