You can associate one BGP filter with a single BGP filter group. Each BGP filter
group can be used across multiple service connections. In some situations, the
service connections must have the same groups. For example, if you configure a
cloud redundancy managed site, all
service connections within the same site group must have the same filter groups
attached to them.
BGP filter groups can't be connected on traffic-steering dedicated service
connections.
- Log in to Panorama.
- Go to and select the Service Connection tab.
- From the BGP Filtering section, select
Edit. The BGP Filtering
window opens.
- Select BGP Filter Groups and
Add to associate multiple filters with a new BGP
filter group.
- Give the filter group a meaningful Group
Name.
- Configure the direction, Inbound or
Outbound, on which the BGP filter is
applied.
Each service connection can
have one inbound and one outbound BGP filter group.
- Select Add to enable a drop-down with filters
you can select. Select as many filters as you want to add to the
group. A BGP filter group can have multiple rules; routes are
evaluated against the rules in sequential order. When a route
matches a rule, the deny or permit action occurs and the route will
not be evaluated against subsequent rules.
Be careful about the rule order in a
filter group. If you decide to want to reorder the rules after
you associate the filter group with a service connection push
the filter group to the firewall, you need to disassociate the
filter group from the service connection, reconfigure the filter
group with rules in the order you want, and reapply it to the
service connection.
- After you configure the BGP filter group, apply it to a service
connection. Go to Onboarding and select a
check box next to a service connection.
- Select .
- Select one group from the drop-downs next to the Inbound
Filter Group and Outbound Filter
Group.
- Save your changes.