Configuring Gtsm For Bgp - HP FlexFabric 12900E Series Configuration Manual

Hide thumbs Also See for FlexFabric 12900E Series:
Table of Contents

Advertisement

Step
2.
Enter BGP instance view or
BGP-VPN instance view.
3.
Disable BGP to establish a
session to a peer or peer
group.
To disable BGP to establish a session to a peer or peer group (IPv6 unicast address family):
Step
1.
Enter system view.
2.
Enter BGP instance view or
BGP-VPN instance view.
3.
Disable BGP to establish a
session to a peer or peer
group.

Configuring GTSM for BGP

The Generalized TTL Security Mechanism (GTSM) protects a BGP session by comparing the TTL
value in the IP header of incoming BGP packets against a valid TTL range. If the TTL value is within
the valid TTL range, the packet is accepted. If not, the packet is discarded.
The valid TTL range is from 255 – the configured hop count + 1 to 255.
When GTSM is configured, the BGP packets sent by the device have a TTL of 255.
GTSM provides best protection for directly connected EBGP sessions, but not for multihop EBGP or
IBGP sessions because the TTL of packets might be modified by intermediate devices.
IMPORTANT:
• When GTSM is configured, the local device can establish an EBGP session to the peer after both
devices pass GTSM check, regardless of whether the maximum number of hops is reached.
• To use GTSM, you must configure GTSM on both the local and peer devices. You can specify
different hop-count values for them.
Command
Enter BGP instance view:
bgp as-number [ instance
instance-name
[ multi-session-thread ]
Enter
BGP-VPN
view:
a. bgp
as-number
[
instance-name
[ multi-session-thread ]
b. ip
vpn-instance
vpn-instance-name
peer { group-name | ipv4-address
[ mask-length ] } ignore
Command
system-view
Enter BGP instance view:
bgp as-number [ instance
instance-name
[ multi-session-thread ]
Enter
BGP-VPN
view:
a. bgp
as-number
[
instance-name
[ multi-session-thread ]
b. ip
vpn-instance
vpn-instance-name
peer { group-name | ipv6-address
[ prefix-length ] } ignore
267
Remarks
]
instance
N/A
instance
]
By default, BGP can establish a
session to a peer or peer group.
Remarks
N/A
]
instance
N/A
instance
]
By default, BGP can establish a
session to a peer.

Advertisement

Table of Contents
loading

Table of Contents