panorama_ipsec_bgp_guide
Learn the required workflow for provisioning IPsec and BGP-over-IPsec on Panorama, including preflight checks, planning, sequencing, and validation steps.
Instructions
[READ-ONLY] Static playbook for provisioning IPsec + BGP-over-IPsec on any Panorama the server is connected to. Covers what to ask the human vs. what to auto-resolve, the hard rules (candidate-only, no-touch-prod, PSK-as-secret, IPsec-before-BGP), the required tool sequence (preflight → suggest resources → plan_ipsec → apply_ipsec → validate_ipsec_v2 → plan_bgp → apply_bgp → validate_bgp → optional runtime verify), the common plan contract, explicit BGP policy intent, the BGP local-address binding, the global BGP local-as/router-id reuse rule, the IKE gateway ikev2 version emission, and naming conventions. Call this first in a session to learn the workflow without trial-and-error. Performs no API calls and mutates nothing.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||