Bgp Vrf Dynamic Route Leaking; User Defined Martian Check - Cisco ASR 9000 Series Configuration Manual

Aggregation services router
Hide thumbs Also See for ASR 9000 Series:
Table of Contents

Advertisement

BGP VRF Dynamic Route Leaking

BGP VRF Dynamic Route Leaking
The Border Gateway Protocol (BGP) dynamic route leaking feature provides the ability to import routes
between the default-vrf (Global VRF) and any other non-default VRF, to provide connectivity between a
global and a VPN host. The import process installs the Internet route in a VRF table or a VRF route in the
Internet table, providing connectivity.
• Directly connected routes cannot be leaked using BGP VRF Dynamic Route Leaking from default
Note
The dynamic route leaking is enabled by:
• Importing from default-VRF to non-default-VRF, using the import from default-vrf route-policy
• Importing from non-default-VRF to default VRF, using the export to default-vrf route-policy
A route-policy is mandatory to filter the imported routes. This reduces the risk of unintended import of routes
between the Internet table and the VRF tables and the corresponding security issues.
There is no hard limit on the number of prefixes that can be imported. The import creates a new prefix in the
destination VRF, which increases the total number of prefixes and paths. However, each VRF importing
global routes adds workload equivalent to a neighbor receiving the global table. This is true even if the user
filters out all but a few prefixes. Hence, importing five to ten VRFs is ideal.

User Defined Martian Check

The Cisco IOS XR Software Release 5.1.0 allows disabling the Martian check for these IP address prefixes:
• IPv4 address prefixes
• IPv6 address prefixes
Cisco ASR 9000 Series Aggregation Services Router Routing Configuration Guide, Release 5.1.x
74
VRF to non-default VRF
route-policy-name [advertise-as-vpn] command in VRF address-family configuration mode.
If the advertise-as-vpn option is configured, the paths imported from the default-VRF to the
non-default-VRF are advertised to the PEs as well as to the CEs. If the advertise-as-vpn option is not
configured, the paths imported from the default-VRF to the non-default-VRF are not advertised to the
PE. However, the paths are still advertised to the CEs.
route-policy-name command in VRF address-family configuration mode.
◦ 0.0.0.0/8
◦ 127.0.0.0/8
◦ 224.0.0.0/4
◦ ::
◦ ::0002 - ::ffff
◦ ::ffff:a.b.c.d
◦ fe80:xxxx
Implementing BGP
OL-30423-03

Advertisement

Table of Contents
loading

Table of Contents