Skip to content

BFD for routing protocols

Bidirectional Forwarding Detection (BFD) monitors (Border Gateway Patrol) BGP neighbors and detects connectivity failures between the firewall and a neighbor faster than routing protocols themselves. BFD uses low-latency control packets and operates independently of routing protocols.

The firewall supports BFD tracking for eBGP, iBGP, eBGP multihop, and route reflector neighbors.

Experimental feature. Please read before you proceed.

This feature is currently experimental.

BFD is available for BGP, providing faster failure detection and enhanced routing resilience in standalone deployments. To configure BFD for other routing protocols, contact Sophos Support.

Requirements and behavior

Review the supported protocols, requirements, and limitations before you configure BFD.

  • The firewall supports BFD for BGP-IPv4 and BGP-IPv6 neighbors.
  • When a BGP neighbor with BFD tracking becomes unavailable, all routes learned from that neighbor are immediately removed from the routing table. If an alternative path is available, traffic switches to it.

    When the neighbor becomes available again the routes are restored to the routing table and traffic switches back to the original route.

  • BFD settings are removed if you make changes to a related setting, such as the destination address or remote gateway. You must reconfigure BFD.

Start BFD service

The BFD service is turned off by default. Turn on BFD and configure BFD tracking for BGP neighbors.

  1. To start the BFD service, do as follows:

    1. Sign in to the CLI and enter 5 for Device Management.
    2. Enter 3 for Advanced shell.
    3. Run the following command:

      service -ds nosync bfdd:start
      
  2. To go to route configuration mode, run the following command: vtysh

Configure BFD for BGP neighbors

Configure BFD tracking for BGP neighbors.

  1. Enter the router configuration mode: router#configure terminal
  2. Enter the BGP router configuration mode: router bgp
  3. Configure the neighbor if you haven't already:

    neighbor <IP address> remote-as <neighbor's AS number>
    
  4. Turn on BFD tracking for the neighbor: neighbor <neighbor's address> bfd

  5. Exit to router mode: end
  6. Save the configuration: write
Example
router# conf t
router(config)# router bgp
router(config-bgp)# neighbor 26.26.26.26 remote-as 20
router(config-bgp)# neighbor 26.26.26.26 bfd
router(config-bgp)# end
router# write
Integrated configuration saved to /conf/routing/frr.conf

Configure a BFD profile

Configure BFD detection and timing parameters to control how quickly the firewall detects peer failures.

Warning

Changing BFD timers or the detection multiplier can increase system processing load. Review and test the settings before applying them.

  1. Enter the router configuration mode: configure terminal
  2. Enter the BFD configuration mode: bfd
  3. Turn on BFD for a peer: peer <IP address>

    This starts peer tracking with the default timer values.

  4. Specify the detection multiplier to determine packet loss: detect-multiplier <number>

    Range: 1-155

    Default: 3

    The remote router calculates the detection time by multiplying this value by the larger of the local transmit interval and the remote receive interval.

  5. Specify the transmit interval: transmit-interval <number>

    Range: 10-4294967

    Default: 300 milliseconds

    Minimum interval, in milliseconds, between BFD control packets sent by this firewall, excluding jitter.

  6. Specify the receive interval: receive-interval <number>

    Range: 10-4294967

    Default: 300 milliseconds

    Minimum interval, in milliseconds, at which this firewall expects to receive BFD control packets.

  7. Exit to router mode: end

  8. Save the configuration: write
Example
router# conf t
router(config)# bfd
router(config-bfd)# peer 26.26.26.26
router(config-bfd-peer)# detect-multiplier 1
router(config-bfd-peer)# transmit-interval 10
router(config-bfd-peer)# receive-interval 10
router(config-bfd-peer)# end
router# write

Note

You can't change these timers through the BGP configuration mode. For example, the following command is invalid: neighbor 26.26.26.26 bfd 2 50 50

Verify BFD peers

Check BFD peer status and verify that BFD sessions are established and operating correctly.

  • Verify BFD peers: sh bfd peers or show bfd peers

    bfd
    peer 26.26.26.26
    exit
    !
    exit
    !
    end
    router# sh bfd peers
    BFD Peers:
        peer 26.26.26.26 vrf default
            ID: 1575224446
            Remote ID: 604561314
            Active mode
            Status: up
            Uptime: 51 second(s)
            Diagnostics: ok
            Remote diagnostics: ok
            Peer Type: configured
            RTT min/avg/max: 0/0/0 usec
            Local timers:
                Detect-multiplier: 3
                Receive interval: 300ms
                Transmission interval: 300ms
                Echo receive interval: 50ms
                Echo transmission interval: disabled
            Remote timers:
                Detect-multiplier: 3
                Receive interval: 300ms
                Transmission interval: 300ms
                Echo receive interval: 50ms
    
  • View all BFD peers and their current status: sh bfd peers brief or show bfd peers brief

    router# sh bfd peers brief
    Session count: 1
    SessionId  LocalAddress  PeerAddress  Status
    =========  ============  ===========  ======
    1575224446 26.26.26.32   26.26.26.26  up