Peer Keep-All-Routes - HP 5920 Series Command Reference Manual

Layer 3 - ip routing
Hide thumbs Also See for 5920 Series:
Table of Contents

Advertisement

Usage guidelines
IPsec can protect IPv6 BGP packets from data eavesdropping, tampering, and attacks caused by forged
IPv6 BGP packets.
When two IPv6 BGP neighbor devices, for example Device A and Device B, are configured with IPsec,
Device A encapsulates an IPv6 BGP packet with IPsec before sending it to Device B. If Device B
successfully receives and decapsulates the packet, it establishes an IPv6 BGP peer relationship with
Device A or learns IPv6 BGP routes to Device A. If Device B receives but fails to decapsulate the packet,
or receives a packet not protected by IPsec, it discards the packet.
Configure IPsec to protect IPv6 BGP packets through the following steps:
1.
Configure an IPsec transform set.
2.
Configure a manual IPsec profile.
3.
Execute this command to apply the IPsec profile to an IPv6 BGP peer or peer group.
For more information about IPsec transform sets and IPsec profiles, see Security Configuration Guide.
This command supports only IPsec profiles in manual mode.
If you configure IPsec on a device, you must configure IPsec on its IPv6 BGP peer. Otherwise, IPv6 BGP
packets cannot be received.
Examples
# In BGP view, apply IPsec profile profile001 to peer group test.
<Sysname> system-view
[Sysname] bgp 100
[Sysname-bgp] peer test ipsec-profile profile001
# In BGP-VPN instance view, apply IPsec profile profile001 to peer group test.
<Sysname> system-view
[Sysname] bgp 100
[Sysname-bgp] ip vpn-instance vpn1
[Sysname-bgp-vpn1] peer test ipsec-profile profile001
Related commands
display bgp group
display bgp peer

peer keep-all-routes

Use peer keep-all-routes to save all route updates from a peer or peer group, regardless of whether the
routes have passed the configured routing policy.
Use undo peer keep-all-routes to restore the default.
Syntax
In BGP IPv4 unicast address family view/BGP-VPN IPv4 unicast address family view/BGP VPNv4
address family view:
peer { group-name | ip-address } keep-all-routes
undo peer { group-name | ip-address } keep-all-routes
In BGP IPv6 unicast address family view:
365

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5900 series

Table of Contents