vWire Fails in BGP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

vWire Fails in BGP

L2 Linker

Hi,

We have a deployment of Palo Alto in vWire mode. But after it was setup, bgp is no longer functioning. I already created an allow all policy but it didn't work as well. Any advise that can help me to make this work?

Thanks,

Rex

4 REPLIES 4

L5 Sessionator

Hello Rex,

Please make sure you have two security policies for inbound and outbound traffic.

BGP negotiation can happen from either side.

Regards,

Hari Yadavalli

L2 Linker

Hi Hari,

Thanks for the response. We already have that policy but BGP is not working still Smiley Sad. Any more suggestions?

Regards,

Rex

Community Team Member

Hi Rex,

Are you seeing any sessions in the traffic log for the BGP traffic ?

You could set up a filter on tcp-port 179 and make a PCAP to see the BGP communication across the vwire.  Analysis of the PCAP could be useful in identifying the issue.

Also with the filter in place you can check the global counters on the PAN.  These counters could give an indication as to why it is failing.

The following DOC can assist you in setting up filter and checking the global counters :

Packet Capture, Debug Flow-basic and Counter Commands

Kind regards,

-Kim.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L4 Transporter

Hello,

Run the below command multiple times and pass the Bgp traffic.

"show session all filter application bgp"

If we identify the session in Active -> then the session is setup. If in Discard -> it is rejected by certain rule or so. If we do not see any output in the session command then the traffic is not hitting the PAN at all. As informed in the prior update we will have to take packet captures and global counters to see or gain more knowledge if we see the sessions building.

Thanks

  • 2923 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!