Hi Charles, Here are replies inline to your questions: 1) Are the communities referred in it "65534:X " "65534:Y " "65534:Z " refers to the prisma mobile users IP pools allocation setting per region? The routes are Mobile User User pool addresses you have onboarded in certain regions. We will split up those larger pools into /24 blocks and tag then with the Prisma Access AS number /Community Strings (65534:x). The X/Y/Z is per Service Connection. You can say "regional" yes. 2) When we clicked on the BGP status, network detailed of the service connections, the community number shown in it refers to what? The X Y Z which i mentioned in point 1 above? I have 3 service connections (2 in US and 1 in EU and none in Asia).. these 3 service connections gave me different community numbers, so which is which region? The community string tag it is using is an ID of the active FW for the original active Service Connection Firewall. 3) The document only mentioned about mobile users IP prefixes.. I also uses Remote Network (traditional IPSEC) into Prisma.. i like to control the return routes of which service connection to be use based on community.. how do we do what community is being set based on the Prisma Access Locations? Is there a list published somewhere on the community numbers? If i checked on the IP prefix of the remote site specifically, i do see a community tag to it... searching all the BGP Ip prefix will be a big chore, will be good if the community numbers tagging is published somewhere. You can see the ID's in Panorama Managed Prisma Access GUI page: Panorama >>> Cloud Services >>>Status >>> Network Details >>> Service Connection >>> Show BGP Status (Look at the Community field) The community tags should be mostly static, so once you have mapped them out they should stay consistent unless you re-onboard the SC. I hope this helps! Wade
... View more