AS Path Prepending for Import Rule in BGP on Palo Alto Firewalls

AS Path Prepending for Import Rule in BGP on Palo Alto Firewalls

2767
Created On 02/05/25 16:50 PM - Last Modified 07/03/25 14:27 PM


Symptom


AS Path prepend option does not let "prepend" the path for import rules.



Environment


  • Palo Alto Networks Firewalls.
  • Supported PAN-OS.
  • BGP Routing configured.
  • AS Path Prepend.


Cause


  • Palo Alto Networks Firewalls only allow AS Path Prepend modifications in BGP Export Rules.
  • Import Rules do not support AS Path Prepend. It only allows to preserve or remove the "AS Path".

 



Resolution


  1. AS Path Prepending is not supported in Import Rules.
  2. Use alternative methods to influence route selection. Some options below.
    • Local Preference: Adjusting the Local Preference of BGP routes can influence inbound traffic.
    • Weight: Assigning different BGP weights to routes can help in selecting the preferred route.
    • Multi-Exit Discriminator (MED): Using MED to suggest preferred entry points to external AS peers.
  3. These can be configured at GUI: Network > Virtual Routers > BGP > Import > (Import tune) > Action >.


Additional Information


  • If the goal is to influence inbound traffic from external AS, Work with upstream ISPs to prepend AS paths on their end.
  • When applying Local Preference, ensure it aligns with your internal routing policies to avoid unintended routing loops.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000PRBdCAO&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail