<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable Inbound soft reconfiguration on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/4101994#M1070974</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I think you need to configure an extra command as:&amp;nbsp;&lt;STRONG class="cCN_CmdName"&gt;neighbor&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cCp_CmdPlain"&gt;{&lt;/SPAN&gt;&lt;EM class="cArgument"&gt;ip-address&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cCp_CmdPlain"&gt;|&lt;/SPAN&gt;&lt;STRONG class="cBold"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;EM class="cArgument"&gt;peer-group-name&lt;/EM&gt;&lt;SPAN class="cCp_CmdPlain"&gt;}&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="cCN_CmdName"&gt;soft-reconfiguratio&lt;/STRONG&gt;&lt;SPAN&gt;n&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cCp_CmdPlain"&gt;[&lt;/SPAN&gt;&lt;STRONG class="cKeyword"&gt;inbound&lt;/STRONG&gt;&lt;SPAN class="cCp_CmdPlain"&gt;]&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But make sure, you must read its advantage and disadvantage.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jun 2020 05:15:51 GMT</pubDate>
    <dc:creator>Deepak Kumar</dc:creator>
    <dc:date>2020-06-12T05:15:51Z</dc:date>
    <item>
      <title>Enable Inbound soft reconfiguration on ASA</title>
      <link>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/4101972#M1070973</link>
      <description>&lt;P&gt;I am getting the following error message when tried to see the received routes from BGP neighbour.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Cisco ASA 5555&amp;nbsp; running on 9.3(3).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ciscoasa# sh bgp neighbors &amp;lt;peer IP address&amp;gt; received-routes&lt;/P&gt;&lt;P&gt;% Inbound soft reconfiguration not enabled on &amp;lt;peer ip address&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please guide me to enable inbound soft to bgp neighbor on ASA&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 03:57:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/4101972#M1070973</guid>
      <dc:creator>Nvelu</dc:creator>
      <dc:date>2020-06-12T03:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Inbound soft reconfiguration on ASA</title>
      <link>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/4101994#M1070974</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I think you need to configure an extra command as:&amp;nbsp;&lt;STRONG class="cCN_CmdName"&gt;neighbor&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cCp_CmdPlain"&gt;{&lt;/SPAN&gt;&lt;EM class="cArgument"&gt;ip-address&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cCp_CmdPlain"&gt;|&lt;/SPAN&gt;&lt;STRONG class="cBold"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;EM class="cArgument"&gt;peer-group-name&lt;/EM&gt;&lt;SPAN class="cCp_CmdPlain"&gt;}&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="cCN_CmdName"&gt;soft-reconfiguratio&lt;/STRONG&gt;&lt;SPAN&gt;n&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cCp_CmdPlain"&gt;[&lt;/SPAN&gt;&lt;STRONG class="cKeyword"&gt;inbound&lt;/STRONG&gt;&lt;SPAN class="cCp_CmdPlain"&gt;]&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But make sure, you must read its advantage and disadvantage.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 05:15:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/4101994#M1070974</guid>
      <dc:creator>Deepak Kumar</dc:creator>
      <dc:date>2020-06-12T05:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Inbound soft reconfiguration on ASA</title>
      <link>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/4101998#M1070975</link>
      <description>&lt;P&gt;Hi Deepak Kumar,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the response. I tried to enable soft configuration to the peer but i do not see any option/configuration to enable.&lt;/P&gt;&lt;P&gt;Sorry that i copy paste the options available in the cli but i just want to show what are available&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ciscoasa(config-router-af)# neighbor 172.31.184.1 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;bgp address-family mode commands/options:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;activate&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Enable the Address Family for this Neighbor&lt;BR /&gt;advertise-map&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; specify route-map for conditional advertisement&lt;BR /&gt;advertisement-interval&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Minimum interval between sending BGP routing updates&lt;BR /&gt;default-originate&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Originate default route to this neighbor&lt;BR /&gt;description&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Neighbor specific description&lt;BR /&gt;disable-connected-check&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;one-hop away EBGP peer using loopback address&lt;BR /&gt;distribute-list&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Filter updates to/from this neighbor&lt;BR /&gt;ebgp-multihop&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Allow EBGP neighbors not on directly connected&lt;BR /&gt;networks&lt;BR /&gt;filter-list&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Establish BGP filters&lt;BR /&gt;ha-mode&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; high availability mode&lt;BR /&gt;local-as&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Specify a local-as number&lt;BR /&gt;maximum-prefix&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Maximum number of prefixes accepted from this peer&lt;BR /&gt;next-hop-self&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Disable the next hop calculation for this neighbor&lt;BR /&gt;password&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Set a password&lt;BR /&gt;prefix-list&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Filter updates to/from this neighbor&lt;BR /&gt;remote-as&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Specify a BGP neighbor&lt;BR /&gt;remove-private-as&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Remove private AS number from outbound updates&lt;BR /&gt;route-map&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Apply route map to neighbor&lt;BR /&gt;send-community&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Send Community attribute to this neighbor&lt;BR /&gt;shutdown&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Administratively shut down this neighbor&lt;BR /&gt;timers&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; BGP per neighbor timers&lt;BR /&gt;transport&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Transport options&lt;BR /&gt;ttl-security&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;BGP ttl security check&lt;BR /&gt;version&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Set the BGP version to match a neighbor&lt;BR /&gt;weight&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Set default weight for routes from this neighbor&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 05:26:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/4101998#M1070975</guid>
      <dc:creator>Nvelu</dc:creator>
      <dc:date>2020-06-12T05:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Inbound soft reconfiguration on ASA</title>
      <link>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/4102003#M1070976</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry, I have shared the command for a router. But ASA is not implemented yet till to 9.6. I didn't find in it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/general/asa-96-general-config/route-bgp.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/general/asa-96-general-config/route-bgp.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 05:44:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/4102003#M1070976</guid>
      <dc:creator>Deepak Kumar</dc:creator>
      <dc:date>2020-06-12T05:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Inbound soft reconfiguration on ASA</title>
      <link>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/4102502#M1070998</link>
      <description>&lt;P&gt;Although documentation states that this command was introduced in version 9.2(1), it would seem that this specific command has not yet been implemented.&amp;nbsp; Unfortunately I do not have an ASA running higher version in my lab for testing.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 21:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/4102502#M1070998</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-06-12T21:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Inbound soft reconfiguration on ASA</title>
      <link>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/4159768#M1074306</link>
      <description>&lt;P&gt;As of ASA OS version 9.14(1), BGP soft-reconfiguration is still not present, for anyone wondering if it was eventually added.&amp;nbsp; I can only guess that this was intentional as a security measure, so administrators would notice a BGP session being cleared to accept new routes rather than it being semi-transparent and potentially causing a security concern by accepting traffic from an unintended network (such as in the case of not using a route-map or prefix-list to filter out unwanted networks).&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 01:06:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/4159768#M1074306</guid>
      <dc:creator>Jesse Peden</dc:creator>
      <dc:date>2020-10-01T01:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Inbound soft reconfiguration on ASA</title>
      <link>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/4778552#M1097998</link>
      <description>&lt;P&gt;I am using ASA 9.14 on a 2K device and you can use "show bgp neighbors x.x.x.x&amp;nbsp; routes" to see your received routes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 13:12:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/4778552#M1097998</guid>
      <dc:creator>Ñnate</dc:creator>
      <dc:date>2023-02-20T13:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Inbound soft reconfiguration on ASA</title>
      <link>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/5259159#M1119490</link>
      <description>&lt;P&gt;Almost 5 years later and still not implemented, so if you want to check the received-routes before filtering, though luck.&lt;BR /&gt;Classic Cisco.&lt;/P&gt;&lt;P&gt;show bgp neighbors 10.126.0.254 received-routes&lt;/P&gt;&lt;P&gt;% Inbound soft reconfiguration not enabled on 10.126.0.254&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 15:08:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-inbound-soft-reconfiguration-on-asa/m-p/5259159#M1119490</guid>
      <dc:creator>laszlofarkas</dc:creator>
      <dc:date>2025-02-11T15:08:29Z</dc:date>
    </item>
  </channel>
</rss>

