Controlling BGP routing from my HQ to remote sistes
the more scalable way to perform this is to use BGP communities to tag BGP routes sent by HQ.
On remote sites you will have a route-map matching on BGP community value(s) using a community-list.
Instead of specifying what IP prefixes you want to learn on the remote site with an IP ACL or a prefix-list, you configure the router to accept all the routes that have a BGP community value as expected.
In this way, in the future you will need to make changes only on the HQ to add a new route to those that should be learned by remote sites, by simply adding a specific BGP community value to the BGP advertisement.
Multiple BGP communities values can be associated with a single BGP advertisement making the mechanism very flexible.
You can divide the routes in multiple groups and you can associate each of them with a BGP community value.
In this way you can also configure different remote sites to accept/import more then one group of routes as needed.
To be noted in order to propagate the BGP community attribute you will need the command
neighbor x.x.x.x send-community
if it is not present.
This approach should work also if your sites are interconnected with an MPLS L3VPN if the PE routers are configured for BGP community propagation ( and they should ).
The HQ router(s) need a route-map with the set community action in the route-map blocks.
To preserve the current set of BGP communities on the route you can use set community value additive.
Question We run asr9001 with XR 6.1.3, and we have a very long delay to
login w/ SSH 1 or 2 to the device compare to IOS device. After
investigation, the there is 1s delay between the client KEXDH_INIT and
the server (XR) KEXDH_REPLY. After debug ssh serv...
Introduction The purpose of this document is to demonstrate the Open
Shortest Path First (OSPF) behavior when the V-bit (Virtual-link bit) is
present in a non-backbone area. The V-bit is signaled in Type-1 LSA only
if the router is the endpoint of one or ...
Hi, I am seeing quite a few issues with patch install and wanted to
share my experience and workaround to this. Login to admin via CLI, then
access root with the “shell” command Issue “df –h” and you’ll probably
see the following directory full or nearly ...