panorama_suggest_ipsec_bgp_resources
Suggest scoped non-overlapping tunnel interfaces and /30 link-local pairs for BGP-over-IPsec on Panorama-managed firewalls, flagging BGP policy choices and returning candidate config for human verification.
Instructions
[READ-ONLY] Resolves the template context, inspects target-template tunnel units and target-VR BGP link-local addresses, then suggests bare tunnel interfaces and /30 near/far pairs that do not overlap within that limited scope. These are scoped suggestions, not global collision guarantees; human and merged/effective-config verification is required. Also returns WAN loopback detection and flags BGP policy choices requiring human intent. Candidate configuration only; no commit or push is performed.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| vsys | No | Virtual system name | vsys1 |
| serial | No | Managed firewall serial number. OPTIONAL — auto-resolved from the template's device assignment when omitted. Only supply it when the template is bound to more than one device. | |
| firewall | No | Target firewall name (from firewalls.json). Required when multiple firewalls are configured; optional otherwise. | |
| template | Yes | Panorama template name (one per firewall) | |
| deployment | Yes | Short unique label for this deployment (e.g. 'istanbul-branch-01'). Every created object is prefixed with it, and it must not collide with any existing name — it is the ownership boundary that keeps prod safe. | |
| tunnel_count | No | Number of tunnel/BGP link pairs to suggest | |
| virtualRouter | No | Virtual router name (Legacy Virtual Router). OPTIONAL — auto-detected from the template's single virtual-router when omitted. Falls back to 'default'/'vr_root' if detection is inconclusive. | |
| link_local_pool | No | Link-local IPv4 CIDR from which scoped, non-overlapping /30s are selected | 169.254.0.0/16 |
| preferred_tunnel_range | No | Preferred inclusive tunnel unit range |