<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BGP Community on Inbound Routemaps in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/250289#M48902</link>
    <description>&lt;P&gt;I know that communities are optional attributes and we are implementing by the RFCs, but in large ISP networks (I found our interpretation of processing communities in such a network) it's a common practice to append ISP's communities to prefixes received by the customer (that may already have other communities as attributes), to have those prefixes imported in the routing tables for various policed exports based on appended communities. It's not a big deal and there are workarounds, but an ISP that has entire routing and forwarding infrastructure based on, let's say, Junipers, that implement the feature, might find cumbersome to accommodate our peculiarities. Usually I'm saying that it might be better to do dynamic routing through the firewall not with the firewall (remember gated?) .&lt;/P&gt;</description>
    <pubDate>Sat, 31 May 2025 18:55:25 GMT</pubDate>
    <dc:creator>APopisteru</dc:creator>
    <dc:date>2025-05-31T18:55:25Z</dc:date>
    <item>
      <title>BGP Community on Inbound Routemaps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206144#M38940</link>
      <description>&lt;P&gt;Hi CheckMates,&lt;/P&gt;&lt;P&gt;I have a BGP peering with Cisco N9K and need to add a community to routes received from the N9K.&lt;/P&gt;&lt;P&gt;This doesn't seem to work on with inbound routemap, but only outbound, tested with Maestro and non-Maestro and iBGP/eBGP, all with the same outcome.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Inbound routemap example:&lt;/P&gt;&lt;P&gt;set routemap lab id 10 on&lt;BR /&gt;set routemap lab id 10 allow&lt;BR /&gt;set routemap lab id 10 match community 1000 as 65000 on&lt;BR /&gt;set routemap lab id 10 match protocol bgp&lt;BR /&gt;set routemap lab id 10 action community 100 as 65099 on&lt;BR /&gt;set routemap lab id 10 action community append on&lt;BR /&gt;set routemap lab id 10 action localpref 400&lt;BR /&gt;set routemap lab id 10 action preference 500&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The expectation is community 65099:100 to be added to the routes.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;set bgp external remote-as 65000 import-routemap lab preference 10 on&lt;/P&gt;&lt;P&gt;show route bgp detailed&lt;BR /&gt;1_01:&lt;BR /&gt;Route: 10.101.0.0/24&lt;BR /&gt;Next Hop: 10.101.199.2, via bond1.1199&lt;BR /&gt;MED: None&lt;BR /&gt;Local Preference: 400&lt;BR /&gt;Age: 25691&lt;BR /&gt;Rank: 170&lt;BR /&gt;Weight: 500&lt;BR /&gt;AS Path: (65099),65000,Incomplete.(Id-8),comm-65000.1000&lt;BR /&gt;Local AS: 65099&lt;BR /&gt;Peer AS: 65000&lt;BR /&gt;Origin: Incomplete&lt;BR /&gt;Originator ID: 10.101.0.2&lt;BR /&gt;BGP Next Hop Attribute: 10.101.199.2&lt;BR /&gt;Communities: 65000:1000&lt;BR /&gt;Route: 10.101.198.0/24&lt;BR /&gt;Next Hop: 10.101.199.2, via bond1.1199&lt;BR /&gt;MED: None&lt;BR /&gt;Local Preference: 400&lt;BR /&gt;Age: 25691&lt;BR /&gt;Rank: 170&lt;BR /&gt;Weight: 500&lt;BR /&gt;AS Path: (65099),65000,Incomplete.(Id-8),comm-65000.1000&lt;BR /&gt;Local AS: 65099&lt;BR /&gt;Peer AS: 65000&lt;BR /&gt;Origin: Incomplete&lt;BR /&gt;Originator ID: 10.101.0.2&lt;BR /&gt;BGP Next Hop Attribute: 10.101.199.2&lt;BR /&gt;Communities: 65000:1000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With outbound routemaps, everything works the peer receives the community.&lt;/P&gt;&lt;P&gt;set routemap lab-out id 10 on&lt;BR /&gt;set routemap lab-out id 10 allow&lt;BR /&gt;set routemap lab-out id 10 match network 10.101.0.0/16 all&lt;BR /&gt;set routemap lab-out id 10 match network 10.102.0.0/16 all&lt;BR /&gt;set routemap lab-out id 10 match protocol direct&lt;BR /&gt;set routemap lab-out id 10 action community 200 as 65099 on&lt;BR /&gt;&lt;BR /&gt;set bgp external remote-as 65000 export-routemap lab-out preference 10 on&lt;/P&gt;&lt;P&gt;show bgp peer 10.101.199.2 advertise&lt;BR /&gt;1_01:&lt;/P&gt;&lt;P&gt;IPv4 Route MED LocalPref Nexthop Communities&lt;BR /&gt;10.101.199.0/24 None N/A(EBGP) 10.101.199.254 65099:200&lt;BR /&gt;10.102.199.0/24 None N/A(EBGP) 10.101.199.254 65099:200&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas? Am I missing something or is it a limitation?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 03:25:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206144#M38940</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2024-02-15T03:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Community on Inbound Routemaps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206182#M38951</link>
      <description>&lt;P&gt;What version/JHF?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 13:52:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206182#M38951</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-02-15T13:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Community on Inbound Routemaps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206228#M38956</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried on several deployments, R81.20 JHF 41 (tried both Maestro and non-Maestro) and R81.10 JHF 109, all tests produced the same results.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 19:56:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206228#M38956</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2024-02-15T19:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Community on Inbound Routemaps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206239#M38957</link>
      <description>&lt;P&gt;Last time I worked with TAC on this 2 years ago, they said it was not supported. Maybe its changed, you can ask them.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 21:04:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206239#M38957</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-15T21:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Community on Inbound Routemaps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206240#M38958</link>
      <description>&lt;P&gt;Enabled BGP trace all and got the below:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Feb 15 16:14:40.529306 [routed] WARNING: Task BGP_65000: Routemap lab (inst 10) Actions (Set Community List|Append To Community List) not supported during IMPORT by Protocol BGP.They will be ignored&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, it looks like a weird limitation ...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 22:31:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206240#M38958</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2024-02-15T22:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Community on Inbound Routemaps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206243#M38959</link>
      <description>&lt;P&gt;Looks like still not supported, thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 22:33:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206243#M38959</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2024-02-15T22:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Community on Inbound Routemaps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206244#M38960</link>
      <description>&lt;P&gt;No worries.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 12:15:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206244#M38960</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-16T12:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Community on Inbound Routemaps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206246#M38961</link>
      <description>&lt;P&gt;I will open an RFE through our local SE here in New Zealand.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 23:06:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206246#M38961</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2024-02-15T23:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Community on Inbound Routemaps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206247#M38962</link>
      <description>&lt;P&gt;That sounds like a good idea.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 23:07:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/206247#M38962</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-15T23:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Community on Inbound Routemaps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/240705#M46701</link>
      <description>&lt;P&gt;R82: the limitation persists, trace says:&lt;/P&gt;
&lt;P&gt;Task BGP_xxxxx: Routemap xxxxxx (inst 100) Actions (Set Community List|Append To Community List) not supported during IMPORT by Protocol BGP. They will be ignored&lt;/P&gt;
&lt;P&gt;Will open a RFE too.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2025 17:02:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/240705#M46701</guid>
      <dc:creator>APopisteru</dc:creator>
      <dc:date>2025-02-07T17:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Community on Inbound Routemaps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/250238#M48879</link>
      <description>&lt;P&gt;Appends in BGP for community are an export feature only.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RFC 1997 describes&amp;nbsp;&lt;/P&gt;
&lt;PRE class="newpage"&gt;   A BGP speaker may use this attribute to control which routing
   information it accepts, prefers or distributes to other neighbors.

   A BGP speaker receiving a route that does not have the COMMUNITIES
   path attribute may append this attribute to the route when
   propagating it to its peers.&lt;BR /&gt;Key word and phrase to understand. BGP Speaker is stating that the community will be spoken to others. Not listening to set the append.  "propagating it to its peers." Reinforcing that this attribute will be sent to the peers.&lt;BR /&gt;&lt;BR /&gt;I hope this helps.  &lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 14:41:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/250238#M48879</guid>
      <dc:creator>KlowikiOne</dc:creator>
      <dc:date>2025-05-30T14:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: BGP Community on Inbound Routemaps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/250289#M48902</link>
      <description>&lt;P&gt;I know that communities are optional attributes and we are implementing by the RFCs, but in large ISP networks (I found our interpretation of processing communities in such a network) it's a common practice to append ISP's communities to prefixes received by the customer (that may already have other communities as attributes), to have those prefixes imported in the routing tables for various policed exports based on appended communities. It's not a big deal and there are workarounds, but an ISP that has entire routing and forwarding infrastructure based on, let's say, Junipers, that implement the feature, might find cumbersome to accommodate our peculiarities. Usually I'm saying that it might be better to do dynamic routing through the firewall not with the firewall (remember gated?) .&lt;/P&gt;</description>
      <pubDate>Sat, 31 May 2025 18:55:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-Community-on-Inbound-Routemaps/m-p/250289#M48902</guid>
      <dc:creator>APopisteru</dc:creator>
      <dc:date>2025-05-31T18:55:25Z</dc:date>
    </item>
  </channel>
</rss>

