Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.
The administrator has enabled BGP on a virtual router on the Palo Alto Networks NGFW, but new routes do not seem to be populating the virtual router. Which two options would help the administrator troubleshoot this issue? (Choose two.)
A.
View the System logs and look for the error messages about BGP.
B.
Perform a traffic pcap on the NGFW to see any BGP problems.
C.
View the Runtime Stats and look for problems with BGP configuration.
Correct: B,C
=======
PAN-EDU-311 Advanced Troubleshooting Dynamic Routing module
"Confirm virtual router runtime status on the active firewall, go to the Network > Virtual Router screen and click on More Runtime Stats"
=======
https://live.paloaltonetworks.com/t5/general-topics/bgp-traffic-pcap/td-p/237407
For troubleshooting purposes it may be necessary to collect the PCAPs of the OSPF and BGP traffic that the Palo Alto Networks device is processing. The quickest way to perform troubleshooting is through the CLI.
To start the BGP capture, use the following CLI command:
> debug routing pcap bgp on
I would say AC. The question is very similar to the next on (#74) concerning OSPF. They're both routing protocols so it's reasonable to begin basic troubleshooting the same way -- look at the system logs and stats.
It cant be A because, the system logs doesn't generate logs when it comes to traffic, Ive been through the system logs loads of times and never seen BGP traffic errors being logged.
B and C looks more relevant
Which two options would help the administrator troubleshoot this issue? Can it be A and B?
When I view the Runtime Stats, can I troubleshoot? or only see the stats?
When I look into the sytem log I see info why not onlu stats (just think out loud)
so C is correct.
Second answer = Could be A as inside system logs we can filter is based on BGP and see what errors we get. PCAP could possibly valid too....
Also if we are saying no new routes are being populated to vRouter, what is the point of checking runtime logs :/ zzz
I think that A and C are correct. We can check BGP events on System tab and Virtual Router Runtime Status. Capturing traffic is required when we must check if connectivity between peers works correctly.
'Which two options would help...' Not conclusively identify.
Troubleshooting best practices dictate you start with the least involved measures. Of the options, performing a PCAP is the most involved.
A, B.
B is definitely one of the correct options. BGP debug pcap commands will show by far the most detail when troubleshooting BGP.
However, A and C could both be correct. You can view status of BGP in the Runtime Stats section of the Virtual Router and this could tell you if BGP is configured incorrectly (but BGP not establishing isn't necessarily an indicator there is a misconfiguration locally); however this is not where BGP is configured (you have to open/edit the actual VR to configure BGP.)
For that reason I think A would be the other correct answer, as you can view BGP events in System logs with this filter: (subtype eq routing) and (description contains 'BGP'), which is more useful for actual troubleshooting than just seeing current status.
B,C are correct
For troubleshooting purposes it may be necessary to collect the PCAPs of the OSPF and BGP traffic that the Palo Alto Networks device is processing. The quickest way to perform troubleshooting is through the CLI.
To start the BGP capture, use the following CLI command:
> debug routing pcap bgp on
To view the BGP data on the device without the need to export:
> debug routing pcap bgp view
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
ChiaPet75
Highly Voted 3 years, 10 months agoBreyarg
2 years, 4 months agoEdu147
Highly Voted 4 years, 9 months agotester12
4 years, 7 months agojonboy22
1 year, 10 months ago123XYZT
Most Recent 1 week, 5 days agotechplus
6 months, 2 weeks agosov4
8 months, 4 weeks agoplaythegamewithme
10 months, 3 weeks agoDenskyDen
1 year, 2 months agolildevil
1 year agohdrnzienlaoroljol
1 year, 2 months agomic_mic
1 year, 3 months agoTAKUM1y
1 year, 7 months agoUFanat
1 year, 10 months agodatz
1 year, 11 months agoasdasd123123iu
2 years agoJoey456
2 years, 11 months agotrashboat
2 years, 12 months agomohr22
1 year, 2 months agoAdamabdi
3 years agotheroghert
3 years, 2 months ago