Limitations; Bgp Flowspec Conceptual Architecture - Cisco NCS 6000 Series Configuration Manual

Ios xr release 6.4.x
Hide thumbs Also See for NCS 6000 Series:
Table of Contents

Advertisement

Limitations

• Allow it, but police it at a specific defined rate
Thus, instead of sending a route with a special community that the border routers must associate with a next
hop to drop in their route policy language, BGP flowspec sends a specific flow format to the border routers
instructing them to create a sort of ACL with class-map and policy-map to implement the rule you want
advertised. In order to accomplish this, BGP flowspec adds a new NLRI (network layer reachability information)
to the BGP protocol.
specifications, supported matching criteria and traffic filtering action.
Limitations
These limitations apply for BGP flow specification:
• For in-service software upgrade (ISSU), there is no support for zero packet loss (ZPL) for BGP Flowspec
• Flowspec supports IPv4 only.
• Flowspec is not supported on subscriber and satellite interfaces.
• A maximum of five multi-value range can be specified in a flowspec rule.
• A mix of address families is not allowed in flowspec rules.
• In multiple match scenario, only the first matching flowspec rule will be applied.
• A maximum of 3000 flowspec rules are supported per system.

BGP Flowspec Conceptual Architecture

In this illustration, a Flowspec router (controller) is configured on the Provider Edge with flows (match criteria
and actions). The Flowspec router advertises these flows to the other edge routers and the AS (that is, Transit
1, Transit 2 and PE). These transit routers then install the flows into the hardware. Once the flow is installed
into the hardware, the transit routers are able to do a lookup to see if incoming traffic matches the defined
flows and take suitable action. The action in this scenario is to 'drop' the DDoS traffic at the edge of the
network itself and deliver only clean and legitimate traffic to the Customer Edge.
Routing Configuration Guide for Cisco NCS 6000 Series Routers, IOS XR Release 6.4.x
104
Information About Implementing BGP Flowspec , on page 105
traffic.
Implementing BGP Flowspec
provides details on flow

Advertisement

Table of Contents
loading

Table of Contents