PAN-OS 10.2 : filter incoming OSPF routes

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

PAN-OS 10.2 : filter incoming OSPF routes

L1 Bithead



We are trying to setup OSPFv2 between a PA-5220 in 10.2 and a Cisco ACI Fabric with "Advanced Routing" enabled.

For now, we are able to advertise routes to our ACI Fabric, we can filter outgoing advertisement but we are unable to filter incoming routes. We tried with RIB Filter - OSPFv2 without success ( :








Have-you an idea of what we are missing ?





L0 Member


If it is not the way to do that, how can we filter incoming prefix with OSPF ?



L1 Bithead


Please remember with OSPF in general there is no way to filter prefixes within the area, as all routers in the area should agree on the LSA database. Removing routes from the RIB, yet still having corresponding LSAs is a very bad practice. If you are looking for prefix filtering, follow OSPF design requirements for that (such as stub areas).

Cyber Elite
Cyber Elite

Hello @EmilienRichard


with OSPF, the filtering of prefixes is typically done on device that is either ABR or ASBR. I have to admit that I have no hands on experience with Advanced Routing Engine, however by looking into documentation: under section: Prefix Lists, there is below point:


From the screen shots you provided, it is not clear whether ACI is in a different OSPF area or the same area. If both devices are in the same area, then this would be my first guess that this is a reason why inbound filter does not work as Palo Alto firewall is not ABR.


If I would be in your place and OSPF area re-design would be an option on the table, I would place ACI into non backbone area and used the same filter you already created.


Kind Regards


Help the community: Like helpful comments and mark solutions.

L1 Bithead


We tried to filter incoming OSPF routes without success so we switched to a BGP peering with our ACI Fabric and we configured inbound prefix filtering :



with a prefix list :



Thanks for your help.


  • 4 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!