Configure BGP from the CLI
Learn how to configure Border Gateway Protocol (BGP) on the firewall using the CLI. You can define networks and manage routing updates.
The firewall supports BGP when it's deployed in gateway mode. It can advertise its routing table, learn routes from neighboring autonomous systems (AS), and automatically determine the best path to reach destination networks.
Configure BGP networks and neighbors
Configure BGP settings, establish peer relationships, and advertise routes.
The commands are common to BGP-IPv4 and BGP-IPv6.
Basic BGP settings
Enter BGP configuration mode and configure the AS number and router ID.
-
To enter the BGP configuration mode, enter the following options:
- For Route configuration: 3
- For Configure unicast routing: 1
You'll see the following prompt:
router# -
Enter the router configuration mode:
router# configure terminal -
Enter the BGP router configuration mode using one of the following commands:
-
To assign an AS number for the first time or change the existing one, do as follows:
router(config)# router bgp <AS number> -
If an AS number already exists, run the following command:
router(config)# router bgp
-
-
(Optional) Manually configure the router ID.
router(config-bgp)# bgp router-id <ip address format>If you don't enter a value, the firewall uses the highest interface IP address of all the configured interfaces as the router ID.
- Use the IPv4 address format, for example,
12.13.14.15. - It doesn't need to be a valid IP address in your routing domain.
- We recommend that you use unique IDs within your routing domain.
-
You can't use
0.0.0.0.Warning
If you change the router ID, the firewall resets all BGP sessions.
- Use the IPv4 address format, for example,
Neighbors and networks
Configure BGP neighbors and specify the IPv4 or IPv6 networks to advertise.
-
To configure a neighbor, enter the neighbor's IPv4 or IPv6 address and AS number:
router(config-bgp)# neighbor <ip address> remote-as <neighbor's AS number> -
To configure a network, do as follows:
-
Enter the specific IP family mode using one of the following commands:
router(config-bgp)# address-family ipv4 unicastrouter(config-bgp)# address-family ipv6 unicast
Note
To change the IP version, exit the address family mode (
exit), then enter the IP version command you want. -
Enter the IPv4 or IPv6 network:
- IPv4:
router(config-bgp-af)# network <ipv4 address>/<subnet mask> - IPv6:
router(config-bgp-af)# network <ipv6 address>/<prefix>
Example
network 10.10.10.0/24network 2008:DB9::/32 - IPv4:
-
(Optional) Don't advertise IPv4 networks to IPv6 neighbors:
router(config-bgp)# address-family ipv4 unicastrouter(config-bgp-af)# no neighbor <ipv6 address> activate
Note
By default, the firewall advertises IPv4 networks to all neighbors. Enter this command to prevent IPv4 networks from being advertised to IPv6 neighbors when you configure an IPv6 neighbor on the CLI.
For web admin console configurations, the firewall automatically adds this command to IPv4 networks.
-
Advertise IPv6 networks to IPv6 neighbors:
router(config-bgp-af)# exit(If you're in IPv4 mode.)router(config-bgp)# address-family ipv6 unicastrouter(config-bgp-af)# neighbor <ipv6 address> activate
Note
By default, the firewall doesn't advertise IPv6 networks to any neighbors. Enter the command to advertise these to IPv6 neighbors when you configure an IPv6 neighbor on the CLI.
For web admin console configurations, the firewall automatically adds this command to IPv6 networks.
-
Exit the address family mode:
exit
-
Save and exit
Verify the configuration, save the changes, and exit BGP configuration mode.
- Exit to router mode:
end -
Verify the configuration:
router# show running-configTo run it from the configuration mode, the command is as follows:
router(config-bgp)# do show running-configIf you used automatic router ID assignment on the web admin console, the ID isn't shown with this command.
Current configuration: ! frr version 10.5.1 frr defaults traditional log stdout hostname router ! router bgp 2000 bgp router-id 2.2.2.2 neighbor 172.16.16.32 remote-as 65006 ! address-family ipv4 unicast network 10.10.10.0/24 exit-address-family exit ! end -
Save the configuration:
router# writeFrom a specific protocol mode, run the command as follows:
do writeThe following message appears:
Integrated configuration saved to /conf/routing/frr.confNote
You must run the
writecommand to save route configurations made through the CLI so they reflect on the web admin console and persist on a firewall or daemon restart. -
Exit router configuration mode:
router# exit
Default settings
The firewall automatically applies the following BGP settings when you configure BGP in the web admin console. If you configure BGP through the CLI, enter these commands manually to achieve the same behavior.
-
When you apply the Global configuration settings in the web admin console, the firewall removes your changes to the following default settings:
bgp log-neighbor-changesno bgp ebgp-requires-policy
-
The firewall only shows custom values when you run the
do show running-configcommand. For example, it doesn't show themaximum-paths ibgpvalue if it's set to the default value of 16.
Example commands
Example
router# conf t
router(config)# router bgp
router(config-bgp)# router bgp 2000
router(config-bgp)# bgp router-id 2.2.2.2
router(config-bgp)# neighbor 172.16.16.32 remote-as 65006
router(config-bgp)# address-family ipv4 unicast
router(config-bgp-af)# network 10.10.10.0/24
router(config-bgp-af)# no neighbor 2008:DB9::/32 activate
router(config-bgp-af)# end
router# show running-config
router# write
Commands
Use the following commands to configure common BGP settings and route advertisement behavior:
| Commands | Description |
|---|---|
router(config-bgp)# no bgp ebgp-requires-policy | The command removes the need for BGP route policies to learn and advertise BGP routes. |
router(config-bgp)# bgp log-neighbor-changes | The firewall logs a message when a neighbor becomes available or unavailable. |