Skip to content

Configure BGP from the CLI

Learn how to configure Border Gateway Protocol (BGP) on the firewall using the CLI. You can define networks and manage routing updates.

The firewall supports BGP when it's deployed in gateway mode. It can advertise its routing table, learn routes from neighboring autonomous systems (AS), and automatically determine the best path to reach destination networks.

Configure BGP networks and neighbors

Configure BGP settings, establish peer relationships, and advertise routes.

The commands are common to BGP-IPv4 and BGP-IPv6.

Basic BGP settings

Enter BGP configuration mode and configure the AS number and router ID.

  1. To enter the BGP configuration mode, enter the following options:

    1. For Route configuration: 3
    2. For Configure unicast routing: 1

    You'll see the following prompt: router#

  2. Enter the router configuration mode: router# configure terminal

  3. Enter the BGP router configuration mode using one of the following commands:

    • To assign an AS number for the first time or change the existing one, do as follows:

      router(config)# router bgp <AS number>
      
    • If an AS number already exists, run the following command:

      router(config)# router bgp
      
  4. (Optional) Manually configure the router ID.

    router(config-bgp)# bgp router-id <ip address format>
    

    If you don't enter a value, the firewall uses the highest interface IP address of all the configured interfaces as the router ID.

    • Use the IPv4 address format, for example, 12.13.14.15.
    • It doesn't need to be a valid IP address in your routing domain.
    • We recommend that you use unique IDs within your routing domain.
    • You can't use 0.0.0.0.

      Warning

      If you change the router ID, the firewall resets all BGP sessions.

Neighbors and networks

Configure BGP neighbors and specify the IPv4 or IPv6 networks to advertise.

  1. To configure a neighbor, enter the neighbor's IPv4 or IPv6 address and AS number:

    router(config-bgp)# neighbor <ip address> remote-as <neighbor's AS number>
    
  2. To configure a network, do as follows:

    1. Enter the specific IP family mode using one of the following commands:

      • router(config-bgp)# address-family ipv4 unicast
      • router(config-bgp)# address-family ipv6 unicast

      Note

      To change the IP version, exit the address family mode (exit), then enter the IP version command you want.

    2. Enter the IPv4 or IPv6 network:

      • IPv4: router(config-bgp-af)# network <ipv4 address>/<subnet mask>
      • IPv6: router(config-bgp-af)# network <ipv6 address>/<prefix>
      Example
      network 10.10.10.0/24
      
      network 2008:DB9::/32
      
    3. (Optional) Don't advertise IPv4 networks to IPv6 neighbors:

      1. router(config-bgp)# address-family ipv4 unicast
      2. router(config-bgp-af)# no neighbor <ipv6 address> activate

      Note

      By default, the firewall advertises IPv4 networks to all neighbors. Enter this command to prevent IPv4 networks from being advertised to IPv6 neighbors when you configure an IPv6 neighbor on the CLI.

      For web admin console configurations, the firewall automatically adds this command to IPv4 networks.

    4. Advertise IPv6 networks to IPv6 neighbors:

      1. router(config-bgp-af)# exit (If you're in IPv4 mode.)
      2. router(config-bgp)# address-family ipv6 unicast
      3. router(config-bgp-af)# neighbor <ipv6 address> activate

      Note

      By default, the firewall doesn't advertise IPv6 networks to any neighbors. Enter the command to advertise these to IPv6 neighbors when you configure an IPv6 neighbor on the CLI.

      For web admin console configurations, the firewall automatically adds this command to IPv6 networks.

    5. Exit the address family mode: exit

Save and exit

Verify the configuration, save the changes, and exit BGP configuration mode.

  1. Exit to router mode: end
  2. Verify the configuration: router# show running-config

    To run it from the configuration mode, the command is as follows:

    router(config-bgp)# do show running-config
    

    If you used automatic router ID assignment on the web admin console, the ID isn't shown with this command.

    Current configuration:
    !
    frr version 10.5.1
    frr defaults traditional
    log stdout
    hostname router
    !
    router bgp 2000
    bgp router-id 2.2.2.2
    neighbor 172.16.16.32 remote-as 65006
    !
    address-family ipv4 unicast
    network 10.10.10.0/24
    exit-address-family
    exit
    !
    end
    
  3. Save the configuration: router# write

    From a specific protocol mode, run the command as follows: do write

    The following message appears: Integrated configuration saved to /conf/routing/frr.conf

    Note

    You must run the write command to save route configurations made through the CLI so they reflect on the web admin console and persist on a firewall or daemon restart.

  4. Exit router configuration mode: router# exit

Default settings

The firewall automatically applies the following BGP settings when you configure BGP in the web admin console. If you configure BGP through the CLI, enter these commands manually to achieve the same behavior.

  • When you apply the Global configuration settings in the web admin console, the firewall removes your changes to the following default settings:

    • bgp log-neighbor-changes
    • no bgp ebgp-requires-policy
  • The firewall only shows custom values when you run the do show running-config command. For example, it doesn't show the maximum-paths ibgp value if it's set to the default value of 16.

Example commands

Example
router# conf t
router(config)# router bgp
router(config-bgp)# router bgp 2000
router(config-bgp)# bgp router-id 2.2.2.2
router(config-bgp)# neighbor 172.16.16.32  remote-as 65006
router(config-bgp)# address-family ipv4 unicast
router(config-bgp-af)# network 10.10.10.0/24
router(config-bgp-af)# no neighbor 2008:DB9::/32 activate
router(config-bgp-af)# end
router# show running-config
router# write

Commands

Use the following commands to configure common BGP settings and route advertisement behavior:

Commands Description
router(config-bgp)# no bgp ebgp-requires-policy The command removes the need for BGP route policies to learn and advertise BGP routes.
router(config-bgp)# bgp log-neighbor-changes The firewall logs a message when a neighbor becomes available or unavailable.