Post by Gowtham M

Palo Alto & Prisma Expert | Network Security Specialist | Security Delivery Team Lead | Creator of Troubleshooting Playbook & Interview Master Guide | DM me for Palo Alto Documents

š—§š—µš—² š—•š—šš—£ "š—¢š—»š—²-š—Ŗš—®š˜† š—¦š˜š—æš—²š—²š˜" š—§š—æš—®š—½ š——š˜‚š—æš—¶š—»š—“ š—® š—£š—®š—¹š—¼ š—”š—¹š˜š—¼ š— š—¶š—“š—æš—®š˜š—¶š—¼š—» 🌐 A branch migration looked perfect on paper. āœ… IPsec Tunnel: UP āœ… BGP Session: ESTABLISHED āœ… Spoke → Hub Traffic: Working But there was one problem... āŒ Hub → Spoke Traffic: Completely Broken The spoke firewall was advertising its local networks, and "show routing protocol bgp rib-out" confirmed the routes were being sent. Yet the Hub firewall never learned a single prefix. š—§š—µš—² š—›š—¶š—±š—±š—²š—» š—–š˜‚š—¹š—½š—æš—¶š˜ šŸ” During the migration, the new Palo Alto firewall was configured with Local-AS to maintain BGP adjacency using the legacy router's ASN. What many engineers don't realize is that, by default, Palo Alto may advertise routes with both: • The configured Local ASN • The firewall's actual System ASN When the Hub receives the route advertisement and detects its own ASN within the AS-Path, it assumes a routing loop and silently rejects the route. No BGP flaps. No alarms. No obvious errors. Just missing routes. š—§š—µš—² š—™š—¶š˜… šŸ› ļø Modify the BGP Peer Local-AS behavior: Network → Virtual Router → BGP → Peer Group → Peer → Local-AS Change the mode to: āœ” Replace-AS (Recommended) āœ” No-Prepend This ensures only the expected ASN is advertised, preventing AS-Path loop detection on the Hub. Within seconds, the Hub accepts the routes and full bidirectional communication is restored. š—žš—²š˜† š—Ÿš—²š˜€š˜€š—¼š—» šŸ“– A BGP session being established does not guarantee route exchange. Always verify: āœ” Received Routes āœ” Advertised Routes āœ” AS-Path Attributes āœ” Local-AS Behavior Sometimes the tunnel is healthy, BGP is up, and the real problem is hiding inside the AS-Path. #PaloAltoNetworks #BGP #NetworkSecurity #Routing #FirewallMigration #IPSec #NetworkEngineering #PANW #Troubleshooting #DataCenter