BFD for routing protocols
Bidirectional Forwarding Detection (BFD) monitors (Border Gateway Patrol) BGP neighbors and detects connectivity failures between the firewall and a neighbor faster than routing protocols themselves. BFD uses low-latency control packets and operates independently of routing protocols.
The firewall supports BFD tracking for eBGP, iBGP, eBGP multihop, and route reflector neighbors.
Experimental feature. Please read before you proceed.
This feature is currently experimental.
BFD is available for BGP, providing faster failure detection and enhanced routing resilience in standalone deployments. To configure BFD for other routing protocols, contact Sophos Support.
Requirements and behavior
Review the supported protocols, requirements, and limitations before you configure BFD.
- The firewall supports BFD for BGP-IPv4 and BGP-IPv6 neighbors.
-
When a BGP neighbor with BFD tracking becomes unavailable, all routes learned from that neighbor are immediately removed from the routing table. If an alternative path is available, traffic switches to it.
When the neighbor becomes available again the routes are restored to the routing table and traffic switches back to the original route.
-
BFD settings are removed if you make changes to a related setting, such as the destination address or remote gateway. You must reconfigure BFD.
Start BFD service
The BFD service is turned off by default. Turn on BFD and configure BFD tracking for BGP neighbors.
-
To start the BFD service, do as follows:
- Sign in to the CLI and enter 5 for Device Management.
- Enter 3 for Advanced shell.
-
Run the following command:
service -ds nosync bfdd:start
-
To go to route configuration mode, run the following command:
vtysh
Configure BFD for BGP neighbors
Configure BFD tracking for BGP neighbors.
- Enter the router configuration mode:
router#configure terminal - Enter the BGP router configuration mode:
router bgp -
Configure the neighbor if you haven't already:
neighbor <IP address> remote-as <neighbor's AS number> -
Turn on BFD tracking for the neighbor:
neighbor <neighbor's address> bfd - Exit to router mode:
end - Save the configuration:
write
Example
router# conf t
router(config)# router bgp
router(config-bgp)# neighbor 26.26.26.26 remote-as 20
router(config-bgp)# neighbor 26.26.26.26 bfd
router(config-bgp)# end
router# write
Integrated configuration saved to /conf/routing/frr.conf
Configure a BFD profile
Configure BFD detection and timing parameters to control how quickly the firewall detects peer failures.
Warning
Changing BFD timers or the detection multiplier can increase system processing load. Review and test the settings before applying them.
- Enter the router configuration mode:
configure terminal - Enter the BFD configuration mode:
bfd -
Turn on BFD for a peer:
peer <IP address>This starts peer tracking with the default timer values.
-
Specify the detection multiplier to determine packet loss:
detect-multiplier <number>Range: 1-155
Default: 3
The remote router calculates the detection time by multiplying this value by the larger of the local transmit interval and the remote receive interval.
-
Specify the transmit interval:
transmit-interval <number>Range: 10-4294967
Default: 300 milliseconds
Minimum interval, in milliseconds, between BFD control packets sent by this firewall, excluding jitter.
-
Specify the receive interval:
receive-interval <number>Range: 10-4294967
Default: 300 milliseconds
Minimum interval, in milliseconds, at which this firewall expects to receive BFD control packets.
-
Exit to router mode:
end - Save the configuration:
write
Example
router# conf t
router(config)# bfd
router(config-bfd)# peer 26.26.26.26
router(config-bfd-peer)# detect-multiplier 1
router(config-bfd-peer)# transmit-interval 10
router(config-bfd-peer)# receive-interval 10
router(config-bfd-peer)# end
router# write
Note
You can't change these timers through the BGP configuration mode. For example, the following command is invalid: neighbor 26.26.26.26 bfd 2 50 50
Verify BFD peers
Check BFD peer status and verify that BFD sessions are established and operating correctly.
-
Verify BFD peers:
sh bfd peersorshow bfd peersbfd peer 26.26.26.26 exit ! exit ! end router# sh bfd peers BFD Peers: peer 26.26.26.26 vrf default ID: 1575224446 Remote ID: 604561314 Active mode Status: up Uptime: 51 second(s) Diagnostics: ok Remote diagnostics: ok Peer Type: configured RTT min/avg/max: 0/0/0 usec Local timers: Detect-multiplier: 3 Receive interval: 300ms Transmission interval: 300ms Echo receive interval: 50ms Echo transmission interval: disabled Remote timers: Detect-multiplier: 3 Receive interval: 300ms Transmission interval: 300ms Echo receive interval: 50ms -
View all BFD peers and their current status:
sh bfd peers brieforshow bfd peers briefrouter# sh bfd peers brief Session count: 1 SessionId LocalAddress PeerAddress Status ========= ============ =========== ====== 1575224446 26.26.26.32 26.26.26.26 up