In the case of a backup service connection, to
influence the routing preferences between service connections and a data center, the
following routing policies change: - If the data center connection uses static routes, the admin_distance setting
for the static route changes to a value higher than the iBGP admin_distance
setting, and customer static routes redistributed into BGP are advertised to
internal BGP peers with a lower local_pref setting. The customer also needs
to set a higher administrative distance for the static route on the CPE
device connecting to the backup service connection so that the CPE network
does not prefer the backup service connection over the primary service
connection.
- If the data center connection uses eBGP, routes learned from the data center
over the IPSec tunnel are advertised to internal BGP peers with a reduced
preference using BGP weight and local_pref settings; routes advertised to
the data center have a higher MED applied.
No routing changes are applied to a primary (non-backup) service connection.
The following table shows the routing policy changes for static routes
redistribution in default routing mode. The values for the primary (non-backup)
service connection don’t change.
| Admin_distance and local_pref for Static Routes
Redistribution | Primary (Non-Backup) Service Connection | Backup Service Connection |
| Customer static route in BGP loc-rib | local_pref = 10000 | local_pref = 5000 |
| Static route in RIB | admin_distance = 15 | admin_distance = 230 |
The following table shows the routing policy changes for backup service
connections with a single eBGP peer in default routing mode. The values for the
primary (non-backup) service connection are the same as before. Use this figure
as a reference for the information in the table that follows it.
| Import/Export | Prisma Access Policy for Service Connection, Single eBGP
Peer | Primary (Non-Backup) Service Connection | Backup Service Connection |
| Import | Import Routes learned from data center | MED unchanged local_pref = 100 | MED unchanged local_pref = 100 |
| Export | Export advertised transient routes toward data center | MED = 0 | MED = 500 |
| Export | Export service infrastructure routes toward data center | MED = 10000 | MED = 11000 |
| Import | Import eBGP routes from iBGP peers, secondary eBGP
disabled | MED unchanged local_pref unchanged | MED unchanged local_pref unchanged |
| Import | Import eBGP routes from iBGP peers, secondary eBGP
enabled | MED = 200 local_pref unchanged | MED = 200 local_pref unchanged |
The following table shows the routing policy changes for backup service
connections with dual eGBP peers in default routing mode. The values for the
primary (non-backup) service connection are the same as before. Use this figure
as a reference for the information in the table that follows it.
| Import/Export | Prisma Access Policy for Service Connection, Dual eBGP
Peers | Primary (Non-Backup) Service Connection | Backup Service Connection |
| Import | Import routes learned from data center, primary IPSec eBGP
peer | MED = 100 local_pref = 100 | MED = 100 local_pref = 50 |
| Import | Import routes learned from data center, secondary WAN IPSec
eBGP peer | MED = 200 local_pref = 100 | MED = 200 local_pref = 50 |
| Export | Export transient routes advertised to data center, primary
IPSec eBGP peer | MED = 100 | MED = 500 |
| Export | Export transient routes advertised to data center, secondary
WAN IPSec eBGP peer | MED = 200 | MED = 600 |
| Export | Export service infrastructure routes advertised to data
center, primary IPSec eBGP peer | MED = 100 | MED = 500 |
| Export | Export service infrastructure routes advertised to data
center, secondary WAN eBGP peer | MED = 200 | MED = 600 |
| Import | Import eBGP routes from iBGP peers, secondary eBGP
disabled | MED unchanged local_pref unchanged | MED unchanged local_pref unchanged |
| Import | Import eBGP routes from iBGP peers, secondary eBGP
enabled | MED = 200 local_pref unchanged | MED = 200 local_pref unchanged |