- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-17-2013 11:37 PM
Hi,
We have a deployment of Palo Alto in vWire mode. But after it was setup, bgp is no longer functioning. I already created an allow all policy but it didn't work as well. Any advise that can help me to make this work?
Thanks,
Rex
12-18-2013 05:02 AM
Hello Rex,
Please make sure you have two security policies for inbound and outbound traffic.
BGP negotiation can happen from either side.
Regards,
Hari Yadavalli
12-19-2013 01:11 AM
Hi Rex,
Are you seeing any sessions in the traffic log for the BGP traffic ?
You could set up a filter on tcp-port 179 and make a PCAP to see the BGP communication across the vwire. Analysis of the PCAP could be useful in identifying the issue.
Also with the filter in place you can check the global counters on the PAN. These counters could give an indication as to why it is failing.
The following DOC can assist you in setting up filter and checking the global counters :
Packet Capture, Debug Flow-basic and Counter Commands
Kind regards,
-Kim.
12-19-2013 01:23 PM
Hello,
Run the below command multiple times and pass the Bgp traffic.
"show session all filter application bgp"
If we identify the session in Active -> then the session is setup. If in Discard -> it is rejected by certain rule or so. If we do not see any output in the session command then the traffic is not hitting the PAN at all. As informed in the prior update we will have to take packet captures and global counters to see or gain more knowledge if we see the sessions building.
Thanks
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!