AS Path Prepending for Import Rule in BGP on Palo Alto Firewalls
2767
Created On 02/05/25 16:50 PM - Last Modified 07/03/25 14:27 PM
Symptom
AS Path prepend option does not let "prepend" the path for import rules.
Environment
- Palo Alto Networks Firewalls.
- Supported PAN-OS.
- BGP Routing configured.
- AS Path Prepend.
Cause
- Palo Alto Networks Firewalls only allow AS Path Prepend modifications in BGP Export Rules.
- Import Rules do not support AS Path Prepend. It only allows to preserve or remove the "AS Path".
Resolution
- AS Path Prepending is not supported in Import Rules.
- Use alternative methods to influence route selection. Some options below.
- Local Preference: Adjusting the Local Preference of BGP routes can influence inbound traffic.
- Weight: Assigning different BGP weights to routes can help in selecting the preferred route.
- Multi-Exit Discriminator (MED): Using MED to suggest preferred entry points to external AS peers.
- These can be configured at GUI: Network > Virtual Routers > BGP > Import > (Import tune) > Action >.
Additional Information
- If the goal is to influence inbound traffic from external AS, Work with upstream ISPs to prepend AS paths on their end.
- When applying Local Preference, ensure it aligns with your internal routing policies to avoid unintended routing loops.