0% found this document useful (0 votes)
5 views756 pages

CP R82.10 Gaia Advanced Routing AdminGuide

The document is the Administration Guide for Check Point's R82.10 Gaia Advanced Routing, detailing software installation, configuration, and monitoring for various routing protocols including DHCP, BGP, OSPF, and RIP. It includes important information about software updates, certifications, and feedback mechanisms for documentation improvement. The guide is structured with a comprehensive table of contents covering all aspects of advanced routing features and configurations.

Uploaded by

bergjonas21
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views756 pages

CP R82.10 Gaia Advanced Routing AdminGuide

The document is the Administration Guide for Check Point's R82.10 Gaia Advanced Routing, detailing software installation, configuration, and monitoring for various routing protocols including DHCP, BGP, OSPF, and RIP. It includes important information about software updates, certifications, and feedback mechanisms for documentation improvement. The guide is structured with a comprehensive table of contents covering all aspects of advanced routing features and configurations.

Uploaded by

bergjonas21
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

29 December 2025

GAIA ADVANCED
ROUTING

R82.10

Administration Guide
Check Point Copyright Notice
© 2025 Check Point Software Technologies Ltd.

All rights reserved. This product and related documentation are protected by copyright and
distributed under licensing restricting their use, copying, distribution, and decompilation. No
part of this product or related documentation may be reproduced in any form or by any means
without prior written authorization of Check Point. While every precaution has been taken in
the preparation of this book, Check Point assumes no responsibility for errors or omissions.
This publication and features described herein are subject to change without notice.

RESTRICTED RIGHTS LEGEND:


Use, duplication, or disclosure by the government is subject to restrictions as set forth in
subparagraph (c)(1)(ii) of the Rights in Technical Data and Computer Software clause at
DFARS 252.227-7013 and FAR 52.227-19.

TRADEMARKS:
Refer to the Copyright page for a list of our trademarks.
Refer to the Third Party copyright notices for a list of relevant copyrights and third-party
licenses.
Important Information

Important Information
Latest Software
We recommend that you install the most recent software release to stay up-to-
date with the latest functional improvements, stability fixes, security
enhancements and protection against new and evolving attacks.

Certifications
For third party independent certification of Check Point products, see the Check
Point Certifications page.

Check Point R82.10


For more about this release, see the R82.10 home page.

Latest Version of this Document in English


Open the latest version of this document in a Web browser.
Download the latest version of this document in PDF format.

Feedback
Check Point is engaged in a continuous effort to improve its documentation.
Please help us by sending your comments.

R82.10 Gaia Advanced Routing Administration Guide | 3


Important Information

Revision History

Date Description

DD MMM 2025 First release of this document

R82.10 Gaia Advanced Routing Administration Guide | 4


Table of Contents

Table of Contents
Introduction to Gaia Advanced Routing 15
IPv6 Support 16
Syntax Legend for CLI Commands 17
DHCP Relay 19
Configuring IPv4 DHCP Relay on Security Gateways 20
Configuring IPv4 DHCP Relay in Gaia Portal 20
Configuring IPv4 DHCP Relay in Gaia Clish 24
Configuring IPv4 DHCP Relay Security Policy on Management Servers 29
Configuring IPv4 DHCP Services on Management Servers 29
Configuring Security Policy in SmartConsole 30
Monitoring IPv4 DHCP Relay 33
IPv6 DHCP Relay 34
Configuring IPv6 DHCP Relay on Security Gateways 35
Configuring IPv6 DHCP Relay in Gaia Portal 36
Configuring IPv6 DHCP Relay in Gaia Clish 38
Configuring IPv6 DHCP Relay Security Policy on Management Servers 41
IPv6 DHCP Services on Management Servers 41
Configuring Security Policy in SmartConsole 41
Monitoring IPv6 DHCP Relay 44
BGP 45
Configuring BGP in Gaia Portal 46
Configuring BGP Global Settings in Gaia Portal 47
Configuring BGP Miscellaneous Settings in Gaia Portal 50
Configuring BGP AS Peer Group Settings in Gaia Portal 54
Configuring BGP Remote Peers in Gaia Portal 56
Restarting BGP Peers in Gaia Portal 65
Monitoring BGP in Gaia Portal 66

R82.10 Gaia Advanced Routing Administration Guide | 5


Table of Contents

Configuring BGP in Gaia Clish 67


Configuring External BGP in Gaia Clish 68
Configuring Internal BGP in Gaia Clish 70
Configuring BGP Remote Peers in Gaia Clish 81
Configuring BGP Confederation in Gaia Clish 90
Configuring BGP Confederations 90
Configuring BGP Confederation Peers 92
Configuring BGP Route Reflection in Gaia Clish 100
Configuring BGP Route Dampening in Gaia Clish 102
Configuring BGP Communities in Gaia Clish 104
Restarting BGP Peers in Gaia Clish 105
Monitoring BGP in Gaia Clish 106
Support for IPv6 BGP (BGP-4 Multiprotocol Extensions) 107
BGP Sessions (Internal and External) 108
Introduction 108
Preventing Private AS Numbers from Propagating 109
BGP Route Refresh 109
BGP Path Attributes 111
BGP Multi-Exit Discriminator 113
BGP Interactions with IGP 114
BGP Inbound Route Filters 115
Redistributing Routes to BGP 116
BGP Communities 117
BGP Route Reflection 118
BGP Confederations 120
External BGP (eBGP) Multihop Support 121
BGP Route Dampening 122
TCP MD5 Authentication for BGP 123
BGP Behavior During ClusterXL Failover 123
Overview 123

R82.10 Gaia Advanced Routing Administration Guide | 6


Table of Contents

Required Configuration 123


Additional Configuration 124
IGMP 126
Introduction 126
IGMPv3 127
Configuring Local and Static IGMP Groups 127
Configuring IGMP in Gaia Portal 129
Configuring IGMP in Gaia Clish 133
Monitoring IGMP 137
Multicast Listener Discovery (MLD) 138
Configuring MLD in Gaia Portal 138
Configuring MLD in Gaia Clish 142
Monitoring and Troubleshooting MLD 147
Monitoring MLD in Gaia Portal 147
Monitoring MLD in Gaia Clish 147
Troubleshooting MLD 148
IP Broadcast Helper 149
Configuring IP Broadcast Helper in Gaia Portal 150
Configuring IP Broadcast Helper in Gaia Clish 151
Monitoring IP Broadcast Helper 154
PIM 155
Introduction 155
IPv4 PIM Dense Mode (DM) 156
IPv4 PIM Sparse Mode (SM) 156
IPv4 PIM Source-Specific Multicast (SSM) Mode 157
Configuring IPv4 PIM in Gaia Portal 158
Configuring IPv4 PIM Modes 158
Configuring IPv4 PIM on Interfaces 161
Configuring IPv4 PIM Advanced Options 164
Configuring IPv4 PIM Bootstrap and Rendezvous Point Settings 167

R82.10 Gaia Advanced Routing Administration Guide | 7


Table of Contents

Configuring IPv4 PIM in Gaia Clish 172


Monitoring and Troubleshooting IPv4 PIM 182
Monitoring IPv4 PIM in Gaia Portal 182
Monitoring IPv4 PIM in Gaia Clish 182
Troubleshooting IPv4 PIM 184
IPv6 PIM 185
Introduction 185
IPv6 PIM Sparse Mode (SM) 185
IPv6 PIM Source-Specific Multicast (SSM) Mode 186
Configuring IPv6 PIM in Gaia Portal 187
Configuring IPv6 PIM Modes 187
Configuring IPv6 PIM on Interfaces 189
Configuring IPv6 PIM Advanced Options 192
Configuring IPv6 PIM Bootstrap and Rendezvous Point Settings 195
Configuring IPv6 PIM in Gaia Clish 200
Monitoring and Troubleshooting IPv6 PIM 210
Monitoring IPv6 PIM in Gaia Portal 210
Monitoring IPv6 PIM in Gaia Clish 210
Troubleshooting IPv6 PIM 212
Static Multicast Routes 213
Configuring Static Multicast Routes in Gaia Portal 214
Configuring Static Multicast Routes in Gaia Clish 216
Monitoring Static Multicast Routes 219
RIP 220
RIPv1 221
RIPv2 222
Configuring RIP in Gaia Portal 223
Configuring RIP in Gaia Clish 229
VRRP Support for RIP 234
Monitoring RIP 235

R82.10 Gaia Advanced Routing Administration Guide | 8


Table of Contents

RIPng 236
Configuring RIPng in Gaia Portal 237
Configuring RIPng in Gaia Clish 239
Monitoring RIPng 242
IP Reachability Detection 243
Configuring IP Reachability Detection in Gaia Portal 244
Configuring IP Reachability Detection in Gaia Clish 253
Monitoring IP Reachability Detection 261
IPsec Routing 264
Configuring IPsec Routing in Gaia Portal 264
Configuring IPsec Routing in Gaia Clish 265
Monitoring IPsec Routing 267
OSPF 268
Configuring IPv4 OSPFv2 Router ID 269
Configuring IPv4 OSPFv2 in Gaia Portal 271
Configuring IPv4 OSPFv2 Global Options in Gaia Portal 273
Configuring IPv4 OSPFv2 Areas in Gaia Portal 276
Configuring a Normal Area 276
Configuring a Stub Area 279
Configuring a Not So Stubby Area 282
Configuring IPv4 OSPFv2 Interfaces in Gaia Portal 285
Configuring IPv4 OSPFv2 Virtual Links in Gaia Portal 292
Configuring IPv4 OSPFv2 in Gaia Clish 298
Configuring IPv4 OSPFv2 Global Options in Gaia Clish 300
Configuring IPv4 OSPFv2 Areas in Gaia Clish 304
Configuring IPv4 OSPFv2 Interfaces in Gaia Clish 312
Configuring IPv4 OSPFv2 Virtual Links in Gaia Clish 318
Configuring IPv4 OSPFv2 Multiple Instances 323
Introduction 323
Adding a New IPv4 OSPFv2 Instance 324

R82.10 Gaia Advanced Routing Administration Guide | 9


Table of Contents

Deleting an Existing IPv4 OSPFv2 Instance 325


Restarting an IPv4 OSPFv2 Instance 326
Resetting IPv4 OSPFv2 Counters 327
Monitoring IPv4 OSPFv2 329
IPv4 OSPF Types of Areas 330
IPv4 OSPFv2 Area Border Routers 332
Cluster Support for IPv4 OSPFv2 333
IPv6 OSPF 335
Configuring IPv6 OSPFv3 Router ID 336
Configuring IPv6 OSPFv3 in Gaia Portal 338
Configuring IPv6 OSPFv3 Global Options in Gaia Portal 339
Configuring IPv6 OSPFv3 Areas in Gaia Portal 342
Configuring a Normal Area 342
Configuring a Stub Area 345
Configuring IPv6 OSPFv3 Interfaces in Gaia Portal 348
Configuring IPv6 OSPFv3 in Gaia Clish 352
Configuring IPv6 OSPFv3 Global Options in Gaia Clish 354
Configuring IPv6 OSPFv3 Areas in Gaia Clish 357
Configuring IPv6 OSPFv3 Interfaces in Gaia Clish 362
Configuring IPv6 OSPFv3 Multiple Instances 366
Introduction 366
Adding a New IPv6 OSPFv3 Instance 367
Deleting an Existing IPv6 OSPFv3 Instance 368
Restarting an IPv6 OSPFv3 Instance 369
Monitoring IPv6 OSPFv3 370
ClusterXL Support for IPv6 OSPFv3 371
VRRPv3 Support for IPv6 OSPFv3 373
IPv6 OSPFv3 Types of Areas 375
IS-IS 376
IS-IS Terms 376

R82.10 Gaia Advanced Routing Administration Guide | 10


Table of Contents

Cluster Support for IS-IS 378


Configuring IS-IS in Gaia Portal 380
Procedure 380
Configuring IS-IS IPv6 Multi-Topology in Gaia Portal 408
Restarting IS-IS 414
Configuring IS-IS in Gaia Clish 415
Workflow 415
Configuring IS-IS Global Options 415
Configuring IS-IS Interfaces 441
Configuring IS-IS IPv6 Multi-Topology Options 459
Monitoring IS-IS 468
Monitoring IS-IS in Gaia Portal 468
Monitoring IS-IS in Gaia Clish 468
Route Aggregation 472
Configuring Route Aggregation in Gaia Portal 473
Configuring Route Aggregation in Gaia Clish 479
Routing Policy Configuration 484
Configuring Inbound Route Filters in Gaia Portal 486
Procedure 486
Configuring the "Add BGP Policy Filter (Based on AS-PATH)" 487
Configuring the "Add BGP Policy Filter (Based on AS)" 495
Configuring the "Add Individual IPv4 Route Filter" 501
Configuring the "Add Individual IPv6 Route Filter" 505
Configuring Inbound Route Filters for IPv4 BGP in Gaia Clish 509
Configuring Inbound Route Filters for IPv4 OSPFv2 in Gaia Clish 522
Configuring Inbound Route Filters for IPv4 RIP in Gaia Clish 526
Configuring Inbound Route Filters for IPv6 OSPFv3 in Gaia Clish 530
Configuring Route Redistribution in Gaia Portal 534
Procedure to Configure Route Redistribution 534
Add Redistribution From - Interface 535

R82.10 Gaia Advanced Routing Administration Guide | 11


Table of Contents

Add Redistribution From - Static 536


Add Redistribution From - Aggregate 537
Add Redistribution From - NAT Pool 537
Add Redistribution From - Kernel 538
Add Redistribution From - RIP 539
Add Redistribution From - OSPFv2, or OSPFv2 External 540
Add Redistribution From - BGP Based on AS-Path 541
Add Redistribution From - BGP Based on AS 544
Add Redistribution From - BGP Default Origin 545
Add Redistribution From - RIPng 546
Add Redistribution From - OSPFv3, or OSPFv3 External 547
Procedure to Configure BGP Redistribution Settings 548
Configuring IPv4 Route Redistribution in Gaia Clish 552
Configuring IPv4 Route Redistribution to BGP in Gaia Clish 554
Configuring IPv4 Route Redistribution to OSPFv2 in Gaia Clish 566
Configuring IPv4 Route Redistribution to RIP in Gaia Clish 577
Configuring IPv6 Route Redistribution in Gaia Clish 588
Configuring IPv6 Route Redistribution to OSPFv3 in Gaia Clish 589
Configuring IPv6 Route Redistribution to RIPng in Gaia Clish 598
Configuring Route Maps in Gaia Clish 606
Route Maps - Configuration Commands 607
Route Maps - Export and Import 637
Route Maps - Supported Route Map Statements by Protocol 642
Route Maps - Examples 644
Prefix Lists and Prefix Trees 649
Prefix List Syntax 649
Prefix Tree Syntax 651
Routing Options 652
Equal Cost Path Splitting 653
Configuring Equal Cost Path Splitting in Gaia Portal 653

R82.10 Gaia Advanced Routing Administration Guide | 12


Table of Contents

Configuring Equal Cost Path Splitting in Gaia Clish 654


Kernel Options 655
Introduction 655
Configuring Kernel Routes in Gaia Portal 655
Configuring Kernel Routes in Gaia Clish 656
Protocol Rank 657
Introduction 657
Default Protocol Ranks 658
Configuring Protocol Rank in Gaia Portal 659
Configuring Protocol Rank in Gaia Clish 659
Auto Restore of Interface Routes 661
Configuring "Auto Restore of Interface Routes" in Gaia Portal 661
Configuring "Auto Restore of Interface Routes" in Gaia Clish 662
Multithreading 663
Configuring "Multithreading" in Gaia Portal 663
Configuring "Multithreading" in Gaia Clish 664
Active-Active Mode for Routing Daemon 665
Configuring "Active-Active Mode" in Gaia Portal 665
Configuring "Active-Active Mode" in Gaia Clish 666
Routing Process Message Logging Options 667
RFC 1403 Compatibility 670
Configuring "RFC 1403 Compatibility" in Gaia Clish 671
Trace Options 672
Configuring Trace Options in Gaia Portal 673
Configuring Trace Options in Gaia Clish 675
Description of Trace Options 678
Routing Event Triggers 682
Overview 682
Configuring Routing Event Triggers in Gaia Clish 682
Monitoring Routing Event Triggers in Gaia Portal 686

R82.10 Gaia Advanced Routing Administration Guide | 13


Table of Contents

Router Discovery 687


Configuring Router Discovery in Gaia Portal 689
Configuring Router Discovery in Gaia Clish 691
Monitoring Router Discovery 694
IPv6 Router Discovery 695
Configuring IPv6 Discovery in Gaia Portal 696
Configuring IPv6 Discovery in Gaia Clish 702
Monitoring IPv6 Router Discovery 708
Policy Based Routing 709
Configuring Policy Based Routing in Gaia Portal 710
Configuring Policy Based Routing in Gaia Clish 715
Monitoring Policy Based Routing 725
NAT Pools 726
Configuring NAT Pools in Gaia Portal 726
Configuring NAT Pools in Gaia Clish 727
Monitoring NAT Pools 729
Multicast Forwarding Cache (MFC) 730
Overview 730
Known Limitations 730
Configuring MFC in Gaia Portal 730
Configuring MFC in Gaia Clish 734
Monitoring MFC Entries 740
Troubleshooting MFC 741
Routing Monitor 742
IPv6 VRRP 743
Regular Expressions and Character Sets 745
Regular Expression Syntax 745
Special Characters in Gaia Clish 746
Glossary 747

R82.10 Gaia Advanced Routing Administration Guide | 14


Introduction to Gaia Advanced Routing

Introduction to Gaia Advanced


Routing
Gaia OS supports:
n Dynamic Routing protocols - OSPF, BGP, and RIP.
n Dynamic Multicast Routing - PIM Sparse Mode (SM), PIM Dense Mode (DM), PIM
Source-Specific Multicast (SSM), and IGMP.
n Different routing options.
You can configure these routing protocols and options in Gaia Portal and Gaia Clish.

For information about Dynamic Routing features that are newly supported in Gaia updates and
releases, see sk98226 - Dynamic Routing and VRRP Features on Gaia OS.

R82.10 Gaia Advanced Routing Administration Guide | 15


IPv6 Support

IPv6 Support
Gaia OS supports IPv6.

Before you can configure IPv6 addresses and IPv6 static routes, you must:

Step Instructions

1 Enable the IPv6 support.

2 Reboot.

For more information, see the R82.10 Gaia Administration Guide > Chapter System
Management > Section System Configuration.

Important:
n R82.10 does not support IPv6 Address on the Gaia Management Interface
(Known Limitation PMTR-47313).
n To configure an IPv6 address on a Multi-Domain Security Management Server,
see the R82.10 Gaia Administration Guide.

R82.10 Gaia Advanced Routing Administration Guide | 16


Syntax Legend for CLI Commands

Syntax Legend for CLI Commands


Whenever possible, this guide lists commands, parameters and options in the alphabetical
order.
This guide uses this convention in the Command Line Interface (CLI) syntax:

Character Description

TAB Shows the available nested subcommands:


main command
→ nested subcommand 1
→ → nested subsubcommand 1-1
→ → nested subsubcommand 1-2
→ nested subcommand 2
Example:
cpwd_admin
config
-a <options>
-d <options>
-p
-r
del <options>
Meaning, you can run only one of these commands:
n This command:
cpwd_admin config -a <options>
n Or this command:
cpwd_admin config -d <options>
n Or this command:
cpwd_admin config -p
n Or this command:
cpwd_admin config -r
n Or this command:
cpwd_admin del <options>

Curly brackets or Enclose a list of available commands or parameters, separated by


braces the vertical bar |.
{} User can enter only one of the available commands or parameters.

R82.10 Gaia Advanced Routing Administration Guide | 17


Syntax Legend for CLI Commands

Character Description

Angle brackets Enclose a variable.


<> User must explicitly specify a supported value.

Square brackets or Enclose an optional command or parameter, which user can also
brackets enter.
[]

R82.10 Gaia Advanced Routing Administration Guide | 18


DHCP Relay

DHCP Relay
BOOTP/DHCP Relay extends Bootstrap Protocol (BOOTP) and Dynamic Host Configuration
Protocol (DHCP) operations across multiple hops in a routed network.
In standard BOOTP, all interfaces on a LAN are loaded from a single configuration server on
the LAN.
BOOTP Relay allows configuration requests to be forwarded to, and serviced from,
configuration servers outside the LAN.
BOOTP/DHCP Relay offers these advantages over standard BOOTP/DHCP:
n Redundancy - Configure an interface on the Check Point system to relay client
configuration requests to all the listed servers simultaneously.
n Load Balancing - Configure multiple interfaces on the Check Point system to relay client
configuration requests to different servers.
n Management - Centrally manage client configurations in large enterprise environments
across multiple LANs.
The Gaia implementation of BOOTP Relay is compliant with RFC 951, RFC 1542, and RFC
2131.
BOOTP Relay supports Ethernet and IEEE 802 LANs with canonical MAC byte ordering, on
clients that specify Bootp htype=1: 802.3 and FDDI.
When an interface configured for BOOTP Relay receives a boot request, it forwards the
request to all the servers in its server list.
It does this after waiting a specified length of time for a local server to answer the boot request.

If a primary IP is specified, it stamps the request with that address. Otherwise, it stamps the
request with the lowest numeric IP address specified for the interface.

R82.10 Gaia Advanced Routing Administration Guide | 19


Configuring IPv4 DHCP Relay on Security Gateways

Configuring IPv4 DHCP Relay on Security


Gateways
You can configure DHCP Relay on the Security Gateway on the Security Gateway in either
Gaia Portal, or Gaia Clish.
If the interface is enabled for DHCP relay, you can set up a number of DHCP Servers, to which
to forward BOOTP/DHCP requests.

Important:
n In a Cluster, you must configure all the Cluster Members in the same way.
n For ClusterXL members, set the value of the kernel parameter "fwx_dhcp_
relay_nat" to 0 on each cluster member. See the R82.10 Quantum Security
Gateway Guide > Chapter Working with Kernel Parameters on Security
Gateway.

Configuring IPv4 DHCP Relay in Gaia Portal


To enable IPv4 BOOTP/DHCP Relay on an Interface

1. With a web browser, connect to Gaia Portal at:

[Link] address of Gaia Management Interface>

If you changed the default port of Gaia Portal from 443, then you must also enter it
([Link] address>:<Port>).
2. From the left navigation tree, click Advanced Routing > DHCP Relay.

3. Click Add.
4. Select Enable.
5. In the Interface field, select the interface, on which you want to enable BOOTP/DHCP
Relay.
6. Optional: Enter values for one or more of these parameters:
n Primary Address
n Wait Time
n Maximum Hops

R82.10 Gaia Advanced Routing Administration Guide | 20


Configuring IPv4 DHCP Relay on Security Gateways

BOOTP/DHCP Parameters

Parameter Description

Primary The IPv4 address to use as the BOOTP/DHCP router address.


Address If you enter an IPv4 address, all BOOTP/DHCP requests
received on the interface are stamped with this IPv4 address.
This can be useful on interfaces with multiple IPv4 addresses
(aliases).
Default: First IPv4 address assigned to the interface.

Wait Time The minimum time to wait (in seconds) for a local configuration
server to answer the boot request before forwarding the request
through the interface.
This delay provides an opportunity for a local configuration
server to reply before attempting to relay to a remote server.
Set the wait time to a sufficient length to allow the local
configuration server to respond before the request is forwarded.
If no local server is present, set the time to zero (0).
Range: 1-65535
Default: 0

Maximum Configures the maximum number of hops for IPv4


Hops BOOTP/DHCP requests.
The IPv4 DHCP Relay increments the hop count of a
BOOTP/DHCP request and then compares it against the
maximum hop count. The IPv4 DHCP Relay discards the
request if the maximum hop count is exceeded.
Range: 1-16
Default: 4

R82.10 Gaia Advanced Routing Administration Guide | 21


Configuring IPv4 DHCP Relay on Security Gateways

7. In the Relays section, define the IPv4 address of each relay, to which you want to
forward BOOTP/DHCP requests. This can be an IPv4 unicast, multicast, or broadcast
address.
You can configure relay to multiple configuration servers independently on each
interface.
Configuring different servers on different interfaces provides load balancing, while
configuring multiple servers on a single interface provides redundancy.

Note - This IPv4 address cannot be an address that belongs to the local
machine.

For each relay:


a. Click Add

b. In the IPv4 address field, enter the IPv4 address of the relay.
c. Click OK.
8. Optional: In the Relay Agent Information Option (Option 82) section, configure the
applicable settings (see RFC 3046):
n Select Circuit-ID to enable the Agent Circuit ID that identifies an interface that
received DHCP requests.
By default, Gaia OS uses the name of the interface you selected earlier.
You can enter a custom string that identifies the relay interface you selected
earlier.
n Select Remote-ID to enable the Agent Remote ID that identifies the host system
that forwarded or relayed DHCP requests to a DHCP server.

By default, Gaia OS uses its hostname.


You can enter a custom string.

Notes:
n The maximum length for the Agent Circuit ID is 251 characters.
n The maximum length for the Agent Remote ID is 251 characters.
n If you configure the Agent Circuit ID and the Agent Remote ID, then the

total length of these two strings cannot exceed 249 characters.

9. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 22


Configuring IPv4 DHCP Relay on Security Gateways

To disable an IPv4 BOOTP/DHCP Relay destination on an interface

1. From the left navigation tree, click Advanced Routing > DHCP Relay.
2. Select the interface.
3. Click Edit.
4. In the Relays section:
a. Select the server.
b. Click Delete.
5. Click Save.

To disable Relay Agent Information Option (Option 82) on an interface

1. From the left navigation tree, click Advanced Routing > DHCP Relay.
2. Select the interface.
3. Click Edit.
4. In the Relay Agent Information Option (Option 82) section:
a. Clear Circuit-ID.
b. Clear Remote-ID.
5. Click Save.

To disable IPv4 BOOTP/DHCP Relay completely on an interface

1. From the left navigation tree, click Advanced Routing > DHCP Relay.

2. Select the interface.


3. Click Delete.

R82.10 Gaia Advanced Routing Administration Guide | 23


Configuring IPv4 DHCP Relay on Security Gateways

Configuring IPv4 DHCP Relay in Gaia Clish


n To see the available "set" commands for IPv4 DHCP Relay, enter in Gaia Clish:

set bootp interface[Esc][Esc]

n To see the available "show" commands for IPv4 DHCP Relay, enter in Gaia Clish:

show bootp interface[Esc][Esc]

Syntax

set bootp interface <Name of Interface>


agent-info
circuit-id {<Circuit-ID> | default | off}
remote-id {<Remote-ID> | default | off}
off
maxhopcount {<1-16> | default}
{off | on}
primary {<IPv4 Address of Interface> | default} wait-time
{<1-65535> | default} on
relay-to <Destination IPv4 Address> {off | on}

Parameters

Parameter Description

<Name of Specifies the interface, on which you want to enable IPv4 DHCP
Interface> Relay.

agent-info Specifies the Agent Circuit ID that identifies an interface that


circuit-id received DHCP requests (see RFC 3046).
{<Circuit-ID> |
default | off}
n <Circuit-ID> - Configures a custom string.
n default - Configures the default value (Gaia OS uses the
name of the interface you selected earlier).
n off - Removes the Agent Circuit ID completely.

Notes:
n The maximum length for the Agent Circuit ID is 251
characters.
n If you configure the Agent Circuit ID and the Agent
Remote ID, then the total length of these two strings
cannot exceed 249 characters.

R82.10 Gaia Advanced Routing Administration Guide | 24


Configuring IPv4 DHCP Relay on Security Gateways

Parameter Description

agent-info Specifies the Agent Remote ID that identifies the host system that
remote-id forwarded or relayed DHCP requests to a DHCP server (see RFC
{<Remote-ID> | 3046)
default | off}
n <Remote-ID> - Configures a custom string.
n default - Configures the default value (Gaia OS uses its
hostname).
n off - Removes the Agent Remote ID completely.

Notes:
n The maximum length for the Agent Remote ID is 251
characters.
n If you configure the Agent Circuit ID and the Agent
Remote ID, then the total length of these two strings
cannot exceed 249 characters.

agent-info off Disables the Relay Agent Information Option (Option 82)
completely.

maxhopcount Configures the maximum number of hops for IPv4 BOOTP/DHCP


{<1-16> | requests.
default} The IPv4 DHCP Relay increments the hop count of a
BOOTP/DHCP request and then compares it against the
maximum hop count. The IPv4 DHCP Relay discards the request
if the maximum hop count is exceeded.
Range: 1-16
Default: 4

{off | on} Disables (off) or enables (on) BOOTP/DHCP Relay on the


specified interface.

primary {<IPv4 The IPv4 address to use as the BOOTP/DHCP router address.
Address of If you enter an IPv4 address, all BOOTP/DHCP requests received
Interface> | on the interface are stamped with this IPv4 address.
default} This can be useful on interfaces with multiple IPv4 addresses
(aliases).
Default: First IPv4 address assigned to the interface.

R82.10 Gaia Advanced Routing Administration Guide | 25


Configuring IPv4 DHCP Relay on Security Gateways

Parameter Description

wait-time {<1- The minimum time to wait (in seconds) for a local configuration
65535> | server to answer the boot request before forwarding the request
default} through the interface.
This delay provides an opportunity for a local configuration server
to reply before attempting to relay to a remote server.
Set the wait time to a sufficient length to allow the local
configuration server to respond before the request is forwarded.
If no local server is present, set the time to zero (0).
Range: 1-65535
Default: 0

relay-to Specifies the IPv4 address of each relay, to which you want to
<Destination forward BOOTP/DHCP requests. This can be an IPv4 unicast,
IPv4 Address> multicast, or broadcast address.
{off | on} You can configure relay to multiple configuration servers
independently on each interface.
Configuring different servers on different interfaces provides load
balancing, while configuring multiple servers on a single interface
provides redundancy.
Note - This IPv4 address cannot be an address that belongs
to the local machine.

R82.10 Gaia Advanced Routing Administration Guide | 26


Configuring IPv4 DHCP Relay on Security Gateways

To enable IPv4 BOOTP/DHCP Relay on an Interface

1. Connect to the command line.


2. Log in to Gaia Clish.
3. Configure the interface, on which you want to enable IPv4 DHCP Relay:

set bootp interface <Name of Interface> on

4. Configure the IPv4 address of each relay, to which you want to forward IPv4
BOOTP/DHCP requests:

set bootp interface <Name of Interface> relay-to


<Destination IPv4 Address> on

5. Optional: Configure values for one or more of these parameters:


n Primary Address
n Wait Time
n Maximum Hops

set bootp interface <Name of Interface>


maxhopcount {<1-16> | default}
primary {<IPv4 Address of Interface> | default} wait-
time {<1-65535> | default} on

6. Optional: Configure the Relay Agent Information Option (Option 82) settings:

set bootp interface <Name of Interface>


agent-info
circuit-id {<Circuit-ID> | default | off}
remote-id {<Remote-ID> | default | off}

7. Save the configuration:

save config

R82.10 Gaia Advanced Routing Administration Guide | 27


Configuring IPv4 DHCP Relay on Security Gateways

To disable an IPv4 BOOTP/DHCP Relay destination on an interface

1. Connect to the command line.


2. Log in to Gaia Clish.
3. Disable the IPv4 BOOTP/DHCP Relay destination on the interface:

set bootp interface <Name of Interface> relay-to


<Destination IPv4 Address> off

4. Save the configuration:

save config

To disable Relay Agent Information Option (Option 82) on an interface

1. Connect to the command line.


2. Log in to Gaia Clish.
3. Disable the Relay Agent Information Option (Option 82) on the interface:

set bootp interface <Name of Interface> agent-info off

4. Save the configuration:

save config

To disable IPv4 BOOTP/DHCP Relay completely on an interface

1. Connect to the command line.

2. Log in to Gaia Clish.


3. Disable the IPv4 BOOTP/DHCP Relay on the interface:

set bootp interface <Name of Interface> off

4. Save the configuration:

save config

R82.10 Gaia Advanced Routing Administration Guide | 28


Configuring IPv4 DHCP Relay Security Policy on Management Servers

Configuring IPv4 DHCP Relay Security Policy


on Management Servers
Configuring IPv4 DHCP Services on Management Servers
This procedure shows how to configure the DHCP services on the Security Management
Server or the Multi-Domain Server.
1. Connect to the command line on the Security Management Server or the Multi-Domain
Server (over SSH, or console).
2. Log in to the Expert mode.

3. On Multi-Domain Server, go to the context of the applicable Domain Management


Server:

mdsenv <Name or IP Address of Domain Management Server>

4. Examine the contents of all the related [Link] files. For file locations, refer to
R82.10 Security Management Administration Guide.

egrep "no_hide_services_ports|no_fold_services_ports"
/<Path>/<To>/<Applicable>/[Link]

5. If UDP port 67 and UDP port 68 are configured in the "no_hide_services_ports" or


the "no_fold_services_ports" tables, edit the related [Link] file and remove
these ports.

vi /<Path>/<To>/<Applicable>/[Link]
Note - These table changes are only necessary if one or more VSX or
ClusterXL clusters run DHCP Relay. You can skip this step, if DHCP Relay is
only used on VRRP clusters or Standalone.

Change from:

no_hide_services_ports = { <4500,17>, <500,17>, <259,17>,


<1701,17>, ..., <68,17>, <67,17> }
no_fold_services_ports = { <4500,17>, <500,17>, <259,17>,
<1701,17>, ..., <68,17>, <67,17> }

To:

R82.10 Gaia Advanced Routing Administration Guide | 29


Configuring IPv4 DHCP Relay Security Policy on Management Servers

no_hide_services_ports = { <4500,17>, <500,17>, <259,17>,


<1701,17>, ... }
no_fold_services_ports = { <4500,17>, <500,17>, <259,17>,
<1701,17>, ... }

6. Save the changes in the file and exit the editor.


7. In SmartConsole, install the Access Control Policy on the applicable Security Gateways.

Configuring Security Policy in SmartConsole


To allow the IPv4 DHCP relay traffic, it is necessary to configure explicit Security Policy rules
with the IPv4 DHCP relay services.
Such explicit Rule Base configuration is required for these reasons:
n The IPv4 DHCP relay agents and IPv4 DHCP servers cannot automatically match
replies with requests.
n Clients do not necessarily have a source IP address when they send their initial request.
The Security Policy has to allow IPv4 DHCP broadcasts from Any source to the IPv4
DHCP Server or IPv4 DHCP Relay.
n The dhcp-request and dhcp-reply services use Check Point's Stateful Inspection Engine
to do Stateful inspection of IPv4 DHCP traffic.

Important - If you do not handle IPv4 DHCP Relay traffic with these services (for
example: a service of Any in the Security Policy or implied rules) the Security
Gateway can drop the traffic.

You configure the IPv4 DHCP services on these ports:


n IPv4 DHCP requests from an IPv4 DHCP client are sent as UDP unicasts or broadcasts
with a source port of 68 and a destination port of 67.
The source IPv4 address may be [Link] if the client does not have an IPv4 address yet.
n IPv4 DHCP replies to a client are sent as UDP unicasts or broadcasts with a source port
of 67 and a destination port of 68.
n IPv4 DHCP relay traffic between relay and server is sent as UDP unicasts with source
port of 67 and destination port of 67.
For Security Gateways R77.20 or higher, the applicable IPv4 DHCP services are the new
DHCP services: dhcp-request and dhcp-reply.

Configuring IPv4 DHCP Security Policy

1. In SmartConsole, click the main Menu ( ) > Global properties.

2. In the Global Properties window, click Firewall.

R82.10 Gaia Advanced Routing Administration Guide | 30


Configuring IPv4 DHCP Relay Security Policy on Management Servers

If the Accept outgoing packets originating from gateway implied rule is enabled, then
from the drop-down menu, select Last or Before Last.
Click OK.
3. Create a host object for the DHCP server.
In the SmartConsole main view, go to Objects > New Host.
a. Enter the object name.
b. Enter the IPv4 address of the IPv4 DHCP server.
c. Click OK.
4. Create a host object for the Global Broadcast.

In the SmartConsole main view, click Objects > New Host.


a. Enter the object name.
b. Enter the IPv4 Address of [Link].
c. Click OK.
5. Create the object of a Client Network, to which the which the IPv4 DHCP clients are
connected.
In the SmartConsole main view, go to Objects > New Network.
a. Enter the object name.
b. In the IPv4 section, enter the IPv4 Network address and IPv4 Net mask.

c. Click OK.
6. Make sure that the legacy DHCP configuration does not exist:

a. Delete or disable all security rules for IPv4 DHCP traffic that use these legacy
services:
n bootp
n dhcp-relay
n dhcp-req-localmodule
n dhcp-rep-localmodule

b. Delete or disable all manual NAT rules for legacy IPv4 DHCP configuration.
7. Configure the required Access Control Policy rules with the new IPv4 DHCP services
(dhcp-request and dhcp-reply).
Example for a Rule Base with the IPv4 DHCP Relay services

R82.10 Gaia Advanced Routing Administration Guide | 31


Configuring IPv4 DHCP Relay Security Policy on Management Servers

Source Destination Service Action Description of the rule

Any <Global Broadcast> dhcp-request Accept Source IP must be Any.


object A value of [Link] does not work.

<Security Gateway that <DHCP Server> dhcp-request Accept In some situations, the DHCP client
performs DHCP Relay> object sends some requests directly to the
object DHCP Server.
<Client Network> object

<Security Gateway that <Client Network> dhcp-reply Accept The replies can be unicast or
performs DHCP Relay> object broadcast based on the DHCP client
object <Global Broadcast> options.
object

<DHCP Server> object <Client Network> dhcp-reply Accept The replies can be unicast or
object broadcast based on the DHCP client
<Global Broadcast> options.
object In some situations, the DHCP server
sends some requests directly to the
DHCP client.

8. Install the Access Control Policy on the applicable Security Gateways.

R82.10 Gaia Advanced Routing Administration Guide | 32


Monitoring IPv4 DHCP Relay

Monitoring IPv4 DHCP Relay


Monitoring IPv4 DHCP Relay in Gaia Portal
1. From the left navigation tree, click Advanced Routing > DHCP Relay.
2. In the top right corner, click Monitoring.

Note - The page is static. To see the latest values, click Reload.

Monitoring IPv4 DHCP Relay in Gaia Clish

To see the available "show" commands for PIM, enter in Gaia Clish:

show bootp[Esc][Esc]

Troubleshooting IPv4 DHCP Relay


See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 33


IPv6 DHCP Relay

IPv6 DHCP Relay


You can configure IPv6 DHCP Relay on the Security Gateway.
For more technical information on the DHCPv6 protocol and IPv6 DHCP relay, refer to RFC
3315.

R82.10 Gaia Advanced Routing Administration Guide | 34


Configuring IPv6 DHCP Relay on Security Gateways

Configuring IPv6 DHCP Relay on Security


Gateways
You can configure IPv6 DHCP Relay on the Security Gateway in either Gaia Portal or Gaia
Clish.
You can configure each interface to send requests to a different set of DHCPv6 servers.

Best Practice: Management Servers R80.10 and higher include pre-defined DHCPv6
services. These built-in services perform stateful inspection of DHCPv6 traffic for
enhanced security. Upgrade your older management servers before you configure
DHCPv6 relay.

Important - In a Cluster, you must configure all the Cluster Members in the same way.

R82.10 Gaia Advanced Routing Administration Guide | 35


Configuring IPv6 DHCP Relay on Security Gateways

Configuring IPv6 DHCP Relay in Gaia Portal


To enable IPv6 DHCP Relay on an Interface

1. With a web browser, connect to Gaia Portal at:

[Link] address of Gaia Management Interface>

If you changed the default port of Gaia Portal from 443, then you must also enter it
([Link] address>:<Port>).
2. From the left navigation tree, click Advanced Routing > IPv6 DHCP Relay.
3. Click Add.

4. Select Enable.
5. In the Interface field, select the interface, on which you want to enable BOOTP/DHCP
Relay.
6. Optional: Select Send Interface-ID to send the Interface-ID option with DHCPv6
Relay requests.
Description

This option tells the DHCPv6 server to copy the interface ID from a relay request to
a relay reply message.
The relay agent uses this value to identify on which interface the DHCPv6 request
was originally received.

Best Practice - Enable this option in situations where the global link
address of the interface that runs the DHCPv6 Relay is not sufficient to
uniquely identify the interface.

The relay agent uses this value to identify on which interface the DHCPv6 request
was originally received.

7. Optional: In the Wait Time field, enter the wait time for this interface.
Description

If a DHCPv6 client indicates that it waited for a server response for shorter than this
wait time, the DHCPv6 Relay drops the request instead of forwarding it.
This delay provides an opportunity for a local DHCPv6 server to respond before
attempting to relay to a remote server.

Note - The actual delay is in increments of 0.01 seconds. Setting this value
to 100 configures a wait time of 1 second.

R82.10 Gaia Advanced Routing Administration Guide | 36


Configuring IPv6 DHCP Relay on Security Gateways

8. In the Relays section, define the IPv6 address of each relay, to which you want to
forward DHCPv6 requests.
You can configure a different list of DHCPv6 servers for each interface, which
receives DHCPv6 requests.
Configuring different servers for different interfaces provides load balancing.
Configuring multiple servers on a single interface provides redundancy.
Configuring different servers on different interfaces provides load balancing, while
configuring multiple servers on a single interface provides redundancy.
You can configure relay to multiple configuration servers independently on each
interface.

Note - This IPv6 address cannot be an address that belongs to the local
machine.

For each relay:


a. Click Add
b. In the Relay To field, enter the IPv6 address of the relay.
c. Click OK.
9. Click Save.

To disable IPv6 DHCP Relay destination on an interface

1. From the left navigation tree, click Advanced Routing > IPv6 DHCP Relay.
2. Select the interface.
3. Click Edit.

4. In the Relays section:


a. Select the server.
b. Click Delete.
5. Click Save.

To disable IPv6 DHCP Relay completely on an interface

1. From the left navigation tree, click Advanced Routing > IPv6 DHCP Relay.
2. Select the interface.
3. Click Delete.
4. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 37


Configuring IPv6 DHCP Relay on Security Gateways

Configuring IPv6 DHCP Relay in Gaia Clish


n To see the available "set" commands for IPv6 DHCP Relay, enter in Gaia Clish:

set ipv6 dhcp6relay[Esc][Esc]

n To see the available "show" commands for IPv6 DHCP Relay, enter in Gaia Clish:

show ipv6 dhcp6relay[Esc][Esc]

Syntax

set ipv6 dhcp6relay interface <Name of Interface>


interface-id {off | on}
{off | on}
relay-to <Destination IPv6 Address> {off | on}
wait-time {<1-65535> | default}

Parameters

Parameter Description

<Name of Specifies the interface, on which you want to enable IPv6


Interface> DHCP Relay.

interface-id {off This option tells the DHCPv6 server to copy the interface ID
| on} from a relay request to a relay reply message.
The relay agent uses this value to identify on which interface
the DHCPv6 request was originally received.
Best Practice - Enable this option in situations where the
global link address of the interface that runs the DHCPv6
Relay is not sufficient to uniquely identify the interface.
Default: off

{off | on} Disables (off) or enables (on) IPv6 DHCP Relay on the
specified interface.

R82.10 Gaia Advanced Routing Administration Guide | 38


Configuring IPv6 DHCP Relay on Security Gateways

Parameter Description

relay-to Specifies the IPv6 address of each relay, to which you want to
<Destination IPv6 forward DHCPv6 requests.
Address> {off | You can configure a different list of DHCPv6 servers for each
on} interface, which receives DHCPv6 requests.
Configuring different servers for different interfaces provides
load balancing.
Configuring multiple servers on a single interface provides
redundancy.
Configuring different servers on different interfaces provides
load balancing, while configuring multiple servers on a single
interface provides redundancy.
You can configure relay to multiple configuration servers
independently on each interface.
Note - This IPv6 address cannot be an address that
belongs to the local machine.

wait-time {<1- If a DHCPv6 client indicates that it waited for a server


65535> | default} response for shorter than this wait time, the DHCPv6 Relay
drops the request instead of forwarding it.
This delay provides an opportunity for a local DHCPv6 server
to respond before attempting to relay to a remote server.
Note - The actual delay is in increments of 0.01 seconds.
Setting this value to 100 configures a wait time of 1
second.
Range: 1-65535 (units of 1/100th of 1 second)
Default: 0

To enable IPv6 DHCP Relay on an Interface

1. Connect to the command line.


2. Log in to Gaia Clish.
3. Configure the interface, on which you want to enable BOOTP/DHCP Relay:

set ipv6 dhcp6relay interface <Name of Interface> on

4. Configure the IPv6 address of each relay, to which you want to forward DHCPv6
requests:

set bootp interface <Name of Interface> relay-to


<Destination IPv6 Address> on

5. Optional: Configure values for one or more of these parameters:

R82.10 Gaia Advanced Routing Administration Guide | 39


Configuring IPv6 DHCP Relay on Security Gateways

n Interface-ID
n Wait Time

set ipv6 dhcp6relay interface <Name of Interface>


interface-id on
wait-time {<1-65535> | default}

6. Save the configuration:

save config

To disable an IPv6 DHCP Relay destination on an interface

1. Connect to the command line.


2. Log in to Gaia Clish.
3. Disable the IPv6 DHCP Relay destination on the interface:

set ipv6 dhcp6relay interface <Name of Interface> relay-to


<Destination IPv6 Address> off

4. Save the configuration:

save config

To disable IPv6 DHCP Relay completely on an interface

1. Connect to the command line.


2. Log in to Gaia Clish.

3. Disable the IPv6 BOOTP/DHCP Relay on the interface:

set ipv6 dhcp6relay interface <Name of Interface> off

4. Save the configuration:

save config

R82.10 Gaia Advanced Routing Administration Guide | 40


Configuring IPv6 DHCP Relay Security Policy on Management Servers

Configuring IPv6 DHCP Relay Security Policy


on Management Servers
IPv6 DHCP Services on Management Servers
DHCPv6 clients and servers send and receive messages through UDP.
A special link-scoped multicast address lets DHCPv6 clients request the configuration
information, when they do not know the IPv6 address of a relay or server:

FF02::1:2

n The client sends DHCPv6 requests as UDP unicasts or multicasts with source port 546
and destination port 547.
The related security policy service is dhcpv6-request.
n DHCPv6 replies to a client are sent as UDP unicasts to the client's IPv6 link-local
address.
They are sent with source port 547 and destination port 546. The related security policy
service is dhcpv6-reply.
n The relay and server send DHCPv6 traffic between them as IPv6 UDP unicasts with
source port 547 and destination port 547.
Multiple server addresses can be specified.

Each server address must be an IPv6 unicast address.


Each server address can refer to a DHCPv6 server or one more DHCPv6 relay.

The related security policy service is dhcpv6-relay.


n Unlike IPv4 BOOTP/DHCP Relay, DHCPv6 server sends its replies to the nearest relay
to the server, as opposed to the nearest relay to the client.

Configuring Security Policy in SmartConsole

Configuring IPv6 DHCP Security Policy

1. In SmartConsole, click the main Menu ( ) > Global properties.

2. In the Global Properties window, click Firewall.


If the Accept outgoing packets originating from gateway implied rule is enabled, then
from the drop-down menu, select Last or Before Last.

R82.10 Gaia Advanced Routing Administration Guide | 41


Configuring IPv6 DHCP Relay Security Policy on Management Servers

Click OK.
3. Create a new host for the DHCP server.
In the SmartConsole main view, go to Objects > New Host.
a. Enter the server name.
b. Enter the IPv6 address of the DHCP server.
c. Click OK.
4. Create the object of a Client Network, to which the which the IPv6 DHCP clients are
connected.
In the SmartConsole main view, go to Objects > New Network.

a. Enter the object name.


b. In the IPv6 section, enter the IPv6 Network address and IPv6 Prefix.
c. Click OK.
5. Configure the required Security Policy rules with the DHCPv6 services (dhcpv6-request,
dhcpv6-reply, and dhcpv6-relay).

Note - Use:
n The DHCPv6 Relay object, which you configured for the Security

Gateway.
n The pre-defined object "All_DHCPv6_Relay_Agents_and_

Servers".
n The pre-defined object "IPv6_Link_Local_Hosts".

Example for a Rule Base with the IPv6 DHCP Relay services

Source Destination Service Notes

<IPv6 Link <All DHCPv6 Relay dhcpv6- Allows requests from DHCPv6 clients to a DHCPv6 relay (on a
Local Hosts> Agents and Servers> request Gaia Security Gateway), which is directly connected to the
object object client network.

<DHCPv6 <IPv6 Link Local dhcpv6-reply Allows replies from a DHCPv6 relay to local DHCPv6 clients.
Relay> object Hosts> object
<IPv6 Link
Local Hosts>
object

<DHCPv6 <DHCPv6 Server> dhcpv6-relay Allows traffic between DHCPv6 relays and DHCPv6 servers.
Relay> object object

R82.10 Gaia Advanced Routing Administration Guide | 42


Configuring IPv6 DHCP Relay Security Policy on Management Servers

Source Destination Service Notes

<DHCPv6 <DHCPv6 Relay> dhcpv6-reply With the implied rules in their default settings (Before Last),
Server> object object replies from the DHCPv6 Server to the DHCPv6 relay are
automatically accepted when the reply matches a request from
the relay to the server.
However, to make sure that such replies are accepted, we
recommend to make an explicit rule to allow traffic from the
DHCPv6 Server to the DHCPv6 Relay.

<Client <DHCPv6 Server> dhcpv6- When DHCPv6 relay is used, the DHCPv6 client can still send
Network> object request requests directly to the DHCPv6 server.
object

<DHCPv6 <Client Network> dhcpv6-reply Accepts replies from DHCPv6 servers to DHCPv6 clients.
Server> object object When DHCPv6 relay is used, the DHCPv6 client can still
receive replies directly from a remotely located DHCPv6
server through UDP unicasts.

6. Install the Access Control Policy on the applicable Security Gateways.

R82.10 Gaia Advanced Routing Administration Guide | 43


Monitoring IPv6 DHCP Relay

Monitoring IPv6 DHCP Relay


Monitoring IPv6 DHCP Relay in Gaia Portal
1. From the left navigation tree, click Advanced Routing > IPv6 DHCP Relay.
2. In the top right corner, click Monitoring.

Note - The page is static. To see the latest values, click Reload.

Monitoring IPv6 DHCP Relay in Gaia Clish

To see the available "show" commands for PIM, enter in Gaia Clish:

show ipv6 dhcp6relay[Esc][Esc]

Troubleshooting IPv6 DHCP Relay


See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 44


BGP

BGP
Border Gateway Protocol (BGP) is an inter-AS protocol, meaning that it can be deployed within
and between autonomous systems (AS). An autonomous system is a set of routers under a
single technical administration. An AS uses an Interior Gateway Protocol (IGP) and common
metrics to route packets within an AS; it uses an exterior routing protocol to route packets to
other ASs.

Notes:
n This implementation supports BGP version 4, with Multiprotocol
Extensions.
n Routing Event Trigger does not support VRRP Cluster.

BGP sends update messages that consist of network number-AS path pairs. The AS path
contains the string of ASs through which the specified network can be reached. An AS path
has some structure in order to represent the results of aggregating dissimilar routes. These
update messages are sent over TCP transport mechanism to ensure reliable delivery. BGP
contrasts with IGP, which build their own reliability on top of a datagram service.
As a path-vector routing protocol, BGP limits the distribution of router reachability information
to its peer or neighbor routers.
You can run BGP over a route-based VPN by enabling BGP on a virtual tunnel interface (VTI).

BGP 4-Byte AS

BGP 4-Byte AS lets you configure 32-bit AS numbers. This feature is enabled by default and it
is not possible to turn it off.
Configuring AS number

set as {off | <1-4294967295> | <0.1-65535.65535>}


save config

Example:

MyGW> set as 1.14464

Viewing BGP 4-Byte AS

show as

Example:

Autonomous System Number 1.14464 (80000)

R82.10 Gaia Advanced Routing Administration Guide | 45


Configuring BGP in Gaia Portal

Configuring BGP in Gaia Portal


This section gives per-field help for the fields in the Advanced Routing > BGP section of the
Gaia Portal.\

Note - Not all fields are shown in all cases.

Important - In a Cluster, you must configure all the Cluster Members in the same way.

1. From the left navigation tree, click Advanced Routing > BGP.
2. Configure BGP Global Settings, including the Router ID.

See "Configuring BGP Global Settings in Gaia Portal" on page 47 .


3. Optional: Configure Peer Groups.
See:
n "Configuring BGP AS Peer Group Settings in Gaia Portal" on page 54
n "Configuring BGP Remote Peers in Gaia Portal" on page 56
4. Optional: Configure Miscellaneous Settings.
See "Configuring BGP Miscellaneous Settings in Gaia Portal" on page 50.

R82.10 Gaia Advanced Routing Administration Guide | 46


Configuring BGP Global Settings in Gaia Portal

Configuring BGP Global Settings in Gaia Portal


1. From the left navigation tree, click Advanced Routing > BGP.
2. In the BGP Global Settings section, click Change Global Settings.
3. Configure the Router ID.
4. Configure the Autonomous System settings.
5. Click Save
Description of fields in the "Router ID and Cluster ID" section

Parameter Description

Router ID The Router ID uniquely identifies the router in the autonomous system.
The BGP protocol uses the Router ID.
Best Practice - Set the Router ID rather than rely on the default
setting. This prevents changes in the Router ID if the interface
used for the router ID goes down.
On a Security Gateway, use an address on a loopback interface
that is not the loopback address [Link] (configure an
additional Loopback interface and assign an IP address to it from
the 128.0.0.x / 24 subnet - see the R82.10 Gaia
Administration Guide).
Important:
n Do not use the IP address [Link] as the Router ID.
n In a Cluster, you must configure the Router ID and you must
configure its value to one of the Cluster Virtual IP
addresses.
In a Cluster, you must configure all the Cluster Members in
the same way.

Range: Dotted-quad.([0-255].[0-255].[0-255].[0-255]).
Default: The interface address of one of the local interfaces.

R82.10 Gaia Advanced Routing Administration Guide | 47


Configuring BGP Global Settings in Gaia Portal

Parameter Description

Cluster ID for The cluster ID used for route reflection.


Route The default cluster ID is the router ID.
Reflectors You must override this default value if the cluster contains more than
one route reflector.
Typically, a single router acts as the reflector for a set, or cluster, of
clients. However, for redundancy two or more routers can also be
configured as reflectors for the same cluster. In this case, you must
select a cluster ID to identify all reflectors serving the cluster.
Gratuitous use of multiple redundant reflectors is not advised, for this
situation can cause an increase in the memory required to store routes
on the redundant reflectors peers.
Range: Dotted-quad ([0-255].[0-255].[0-255].[0-255])
Default: The IP address from the Router ID field

Local The local autonomous system number of the router.


Autonomous
System
Number

Description of fields in the "Autonomous System" section

Parameter Description

Unconfigured

Local The local autonomous system number of the router.


Autonomous This setting is mutually exclusive from the Confederation and
System Number Routing Domain Identifier.
The router can be configured with either the autonomous system
number or the member of confederation, not both.
Warning - When you change the autonomous system number,
all current peer sessions are reset and all BGP routes are
deleted.
Range: 1-65535
Default: No default

Confederation The identifier for the entire confederation system.


This identifier is used as the AS in external BGP sessions.
To the outside world, the confederation ID is the AS number of the
single, large AS.
For this reason, the confederation ID must be a globally unique,
normally assigned AS number.
Range: 1-65535
Default: No default

R82.10 Gaia Advanced Routing Administration Guide | 48


Configuring BGP Global Settings in Gaia Portal

Parameter Description

Number of loops For the confederation: The number of times the local autonomous
permitted in AS_ system can appear in an AS path for routes learned through BGP.
PATH If the number of times the local autonomous system appears in an
AS path is more than the number in this field, the corresponding
routes are discarded or rejected.
Range: 1-10
Default: 1

Routing Domain The Routing Domain Identifier (RDI) of this router.


Identifier This value is required only if BGP confederations are in use.
The RDI does not have to be globally unique since it is never used
outside the domain of the confederation system. However, the
configured RDI must be unique within the confederation.
The routing-domain identifier and autonomous system number are
mutually exclusive values. Meaning, the router can be configured
with either the autonomous system number or the member of
confederation, not both.
If confederations are in use, the RDI is used wherever the
autonomous system would be used to communicate with peers
within the confederation, including group-type confederation peers
and the various internal-type peers.
For correct operation of the router in confederations you must
configure both the routing-domain identifier and the confederation.
Range: 1-65535
Default: No default

Number of loops For the routing domain identifier: The number of times the local
permitted in AS_ autonomous system can appear in an AS path for routes learned
PATH through BGP.
If the number of times the local autonomous system appears in an
AS path is more than the number in this field, the corresponding
routes are discarded or rejected.
Range: 1-10
Default: 1

R82.10 Gaia Advanced Routing Administration Guide | 49


Configuring BGP Miscellaneous Settings in Gaia Portal

Configuring BGP Miscellaneous Settings in Gaia Portal


1. From the left navigation tree, click Advanced Routing > BGP.
2. In the Miscellaneous Settings section, configure the applicable settings.
3. Click Apply.

Parameter Description

Default MED Defines the metric (MED) used when advertising routes through
BGP.
If you do not specify a value, no metric is propagated.
A metric specified on the neighbor configuration or in the
redistribution configuration might override the metric you configure.
Range: 0-65535
Default: None

Default Gateway: A default route is generated when any BGP peer is up.
This route has a higher rank than the default configured in the static
routing page.
If a specific BGP peer should not be considered for generating the
default route, you should explicitly suppress the option in the peer-
specific configuration.
Range: Dotted-quad ([0-255].[0-255].[0-255].[0-255])
Default: None

Enable IGP Select this option to make internal and configured BGP peers check
Synchronization for a matching route from IGP protocols before installing a given
route.
Default: Unselected

Enable Enables communities-based policy options.


communities Default: Unselected

Enable ECMP Enables Equal-Cost Multi-Path (ECMP) routing strategy.


ECMP is a load-balancing routing strategy.
The BGP RFC does not support ECMP routes because BGP clearly
sets the route selection criteria.
To overcome this issue and install ECMP route through a BGP user,
enable the ECMP option.
Note - BGP ECMP is not supported for routes that are received
by a mix of iBGP and eBGP.
Default: Unselected

R82.10 Gaia Advanced Routing Administration Guide | 50


Configuring BGP Miscellaneous Settings in Gaia Portal

Parameter Description

Graceful Restart Specifies the time (in seconds) that BGP peers of this router should
Time keep the routes advertised to them while this router restarts.
If the BGP session is not re-established within this time, the peers will
delete the routes.
If this router re-establishes the session(s) with its peer(s) before this
timer expires, the peers will schedule the stale-path-timer to re-
validate the routes advertised by this router.
See sk100499.
Range: 1-4095
Default: 360

Graceful Restart Specifies the time (in seconds) that this router will wait for the End-of-
Selection Deferral RIB notification from each of its BGP peers after a restart.
Time After a restart or cluster failover, the cluster master has to re-validate
the routes it had previously received from each of the BGP peers.
The old routes will be kept till either all the peers have sent the End-
of-RIB or this timer expires.
Any routes not re-validated are deleted.
See sk100499.
Range: 60-4095
Default: 360

Enable Weighted Select this option and see the next section Weighted Route
Route Dampening Dampening Settings.
Default: Unselected

Ping interval Specifies the interval between pings sent to all BGP peers with ping
enabled.
Range: 1-60
Default: 2

Ping Count Specifies the number of failed pings to an individual BGP peer with
ping enabled before BGP will drop that peer.
This value is common across all BGP peers.
Range: 1-10
Default: 3

R82.10 Gaia Advanced Routing Administration Guide | 51


Configuring BGP Miscellaneous Settings in Gaia Portal

Weighted Route Dampening Settings

Parameter Description

Enable Weighted route dampening minimizes the propagation of flapping


Weighted routes across an internetwork.
Route A route is considered to be flapping when it is repeatedly transitioning
Dampening from available to unavailable, or the other way around.
Only routes learned through BGP are subjected to weighted route
dampening.
Note - BGP route dampening is supported only for External BGP
(eBGP).
When this option is selected, the other Route Dampening fields show.

Reuse-below The value of the instability metric at which a suppressed route


metric becomes unsuppressed if it is reachable but currently suppressed.
The value assigned to the reuse-below metric must be less than the
suppress-above value.
Range: 1-32
Default: 2

Suppress- The value of the instability metric at which a route is suppressed; a


above metric route is not installed in the FIB or announced even if it is reachable
during the period that it is suppressed.
Range: 2-32
Default: 3

Max-flap The upper limit of the instability.


metric The value must be higher than one plus the suppress-above value.
The metric assigned to the suppress-above, reuse-below, and max-
flap metric values is a floating point number, in units of flaps.
Each time a route becomes unreachable, one is added to the current
instability metric.
Range: 3-64
Default: 16

Reachable A value that determines the length of time it takes for the instability
decay time metric value to reach one half of its current value when the route is
reachable.
This half-life value determines the rate at which the metric value is
decayed.
A smaller half-life value makes a suppressed route reusable sooner
than a greater value.
Range: 1-900
Default: 300

R82.10 Gaia Advanced Routing Administration Guide | 52


Configuring BGP Miscellaneous Settings in Gaia Portal

Parameter Description

Unreachable The rate at which the instability metric is decayed when a route is
decay time unreachable.
This value must be equal to or greater than the reach-decay value.
Range: 1-2700
Default: 900

Keep history The period over which the route flapping history is maintained for a
time given route.
The size of the configuration arrays described below is directly
affected by this value.
Range: 2-5400
Default: 1800

R82.10 Gaia Advanced Routing Administration Guide | 53


Configuring BGP AS Peer Group Settings in Gaia Portal

Configuring BGP AS Peer Group Settings in Gaia Portal


1. From the left navigation tree, click Advanced Routing > BGP.
2. In the Peer Groups section, configure the applicable settings.
3. Click Add.
4. Configure the applicable settings.
5. Click Save.

Parameter Description

Peer AS The autonomous system number of the external peer group.


Number Enter an integer from 1-65535.

Peer Group Shows the peer group type.


Type

Description Optional: A free-text description of the peer group.

Local The address used on the local end of the TCP connection with the peer.
Address For external peers that do not have multihop enabled, the local address
must be on an interface that is shared with the peer or with the peer's
gateway, when the gateway parameter is used.
A session with an external peer opens only when an interface with a local
address through which you can reach the peer or gateway address directly
operates.
For other types of peers, a peer session opens when an interface with the
specified local address operates.
In both external and other types of peers, incoming connections are
recognized as matching a configured peer only if they are addressed to the
configured local address.
Note - If you run BGP in a cluster, you must not configure the local
address.
Default: None

Out Delay The length of time in seconds that a route must be present in the routing
database before it is redistributed to BGP.
This value applies to all neighbors configured in this group.
The default value is zero, which means that this feature is disabled.
This feature dampens route fluctuations.
Range: 0-65535
Default: 0

R82.10 Gaia Advanced Routing Administration Guide | 54


Configuring BGP AS Peer Group Settings in Gaia Portal

Parameter Description

Peers Configure BGP peers.


Each peer inherits as defaults all parameters configured on a group.
To change the values of a peer's parameters, select the peer and click
Edit.
See "Configuring BGP Remote Peers in Gaia Portal" on page 56.

R82.10 Gaia Advanced Routing Administration Guide | 55


Configuring BGP Remote Peers in Gaia Portal

Configuring BGP Remote Peers in Gaia Portal


1. From the left navigation tree, click Advanced Routing > BGP.
2. In the Peer Groups section, configure the applicable settings.
3. Click Add.
4. Configure the applicable settings for this Peer Group.
5. In the Peers section, click Add Peer and select either Add IPv4 Peer or Add IPv6 Peer.
6. Configure the applicable settings for this Peer and click Save.
7. Click Save.
Table: BGP Peer parameters in Gaia Portal
Parameter Description

Peer IP address of the BGP remote peer.

Comment Optional: A free-text description of the remote peer.

Ping Enable or disable ping for this peer.

IP Reachability Configure Bidirectional Forwarding Detection (BFD) on each Security


Detection Gateway and cluster member that sends or receives BFD packets.
Select one of these options:
n Singlehop BFD - For a peer that is one hop away.
The peer must be on a directly connected network.
Make sure the Firewall policy allows UDP port 3784 in both
directions.
n Multihop BFD - For a peer that is one or more hops away.
Make sure the Firewall policy allows UDP port 4784 in both
directions.
n Off
Make sure that the BFD configuration is the same on both BFD peers
(both configured as multihop or singlehop).
Make sure the SmartConsole topology is correct (issues with incorrect
Firewall topology can cause anti-spoofing to interfere with BFD traffic).

R82.10 Gaia Advanced Routing Administration Guide | 56


Configuring BGP Remote Peers in Gaia Portal

Table: BGP Peer parameters in Gaia Portal (continued)


Parameter Description

Check Control Interprets the control plane independent flag (the C bit) received from
Plane Failure the remote BFD peer.
When these two conditions are met at the same time, the gateway
keeps stale routes and does not purge them, for graceful restart
purposes:
a. The C bit received from the peer is zero.
b. BGP graceful restart is enabled.
When the option is cleared, stale routes are purged when the peer goes
down.
Default: Cleared

Multiprotocol n IPv4 Unicast Only - Specifies if IPv4 unicast routes can be sent
Capabilities to and received from this peer. Default: Selected.
n IPv6 Unicast Only - Specifies if IPv6 unicast routes can be sent
to and received from this peer. Default: Cleared.
n Both IPv4 and IPv6 - Specifies if both IPv4 and IPv6 unicast
routes can be sent to and received from this peer. Default:
Cleared.

Local Address The IP address used on the local end of the TCP connection with the
peer.
For external peers that do not have multihop enabled, the local address
must be on an interface that is shared with the peer or with the peer's
gateway when the gateway parameter is used.
A session with an external peer is opened only when an interface with a
local address through which the peer or gateway address is directly
reachable is operating.
For other types of peers, a peer session is maintained when any
interface with the specified local address is operating.
In either case, incoming connections are recognized as matching a
configured peer only if they are addressed to the configured local
address.
Default: None
Important:
n Do not use Local Address with VRRP or Cluster mode.
n Local Address should match an interface.

R82.10 Gaia Advanced Routing Administration Guide | 57


Configuring BGP Remote Peers in Gaia Portal

Table: BGP Peer parameters in Gaia Portal (continued)


Parameter Description

Peer Local AS Lets you configure the connection to a remote peer with a Peer Local
ASN, on a per-peer basis.
The Peer Local ASN replaces the Local ASN in the BGP session.
Only eBGP peers are supported.
It is not necessary to configure the Peer Local ASN locally
n Enable Peer Local AS
Enables this feature.
n Prepend Peer Local AS on inbound updates from peer
The router adds the configured peer local ASN to the AS path of
the routes received from the peer.
Routes installed from that peer will contain the peer local ASN as
the first entry in the AS Path.
Default: Selected
n Prepend systemwide Local AS on outbound updates to peer
The router adds the local ASN to the AS Path of the routes
advertised to an eBGP peer.
When enabled, the local ASN is the second ASN in the AS Path
of updates sent to eBGP peers. The peer local ASN is always the
first ASN in the AS Path if the sub feature is enabled or not.
Default: Selected
n Allow peering with the Local AS
Enables the connection to the local ASN or the peer local ASN.
There can be only one active connection. If you do not enable this
option, it is only possible to connect to the Peer Local ASN.
The router first tries to connect to the local ASN. If the connection
is created with the local ASN, the BGP runs as if the peer local
ASN feature is not configured. If the connection with the local
ASN fails, the router tries to connect with the peer local ASN.
Important - Do not use this feature with an AS that already
has peer local AS with Dual-Peering enabled.
Default: Cleared

R82.10 Gaia Advanced Routing Administration Guide | 58


Configuring BGP Remote Peers in Gaia Portal

Table: BGP Peer parameters in Gaia Portal (continued)


Parameter Description

MED n Accept MED from External Peer


MED should be accepted from this external neighbor.
MEDs are always accepted from routing-type and confederation
neighbors.
If this parameter is not used with an external neighbor, the MED is
stripped before the update is added to the routing table.
If this parameter is added or deleted and other routing settings
are reconfigured, the affected peering sessions are automatically
restarted.
Default: Cleared
n MED Sent Out
The primary metric used on all routes sent to the specified peer.
This metric overrides the default metric on any route specified by
the redistribute policy.
Range: 0-4294967294
Default: 4294967294

Next Hop and n EGP Multihop


Time to Live Multihop is used to set up eBGP peering connections with peers
that are not directly connected.
You can also use this option, which relies on an IGP to find the
route to the peer, to set up peers to perform eBGP load
balancing.
You can refine the multihop session by configuring the TTL, that
is, the number of hops to the eBGP peer.
The TTL has a default value of 64.
Default: Cleared
n Time to Live
You can use the TTL (time to live parameter) to limit the number
of hops over which the eBGP multihop session is established.
You can configure the TTL only if multihop is enabled.
Range: 1-255
Default: 64

Aggregator Select No Aggregator ID to force this router to specify the router ID in


the aggregator attribute as zero, rather than the actual router ID.
This option prevents different routers in an AS from creating aggregate
routes with different AS paths.
Default: Cleared

R82.10 Gaia Advanced Routing Administration Guide | 59


Configuring BGP Remote Peers in Gaia Portal

Table: BGP Peer parameters in Gaia Portal (continued)


Parameter Description

ASPATH n ASPATH prepend count


The number of times this router adds to the AS path on eBGP
external or CBGP confederation sessions.
Use this setting to bias the degree of preference some
downstream routers have for the routes originated by this router.
Some implementations prefer to select routes with shorter AS
paths.
This parameter has no effect when used with iBGP peers.
Range: 1-25
Default: 1
n AllowAS In Count
This feature lets the router at the receiving end override the peer's
AS number with the router's AS number in the inbound AS path.
This is an inbound property whereas as-override is an outbound
property.
Range: 0-10
Default: 0
n AS Override
Overrides the peer's AS number with the router's AS number in
the outbound AS path.
Default: Cleared

Private AS Remove Private AS remove private AS numbers from the outgoing


updates to this peer.
These conditions apply when this feature is enabled:
n If the AS path includes both public and private AS numbers,
private AS numbers will not be removed.
n If the AS path contains the AS number of the destination peer,
private AS numbers will not be removed.
n If the AS path contains only confederations and private AS
numbers, private AS numbers will be removed.
Default: Cleared

R82.10 Gaia Advanced Routing Administration Guide | 60


Configuring BGP Remote Peers in Gaia Portal

Table: BGP Peer parameters in Gaia Portal (continued)


Parameter Description

Timers n Keep Alive Timer


An alternative way to specify a Hold Time value, in seconds, to
use when negotiating the connection with this peer.
The keepalive interval equals one-third the value of the holdtime.
The keepalive interval is often used instead of the holdtime value,
but you can specify both values, provided the value for the
holdtime is three times the keepalive interval.
The value must be 0, that is, no keepalives are sent, or at least 2.
Range: 0, 2-21845
Default: 60
n Hold Time
The BGP holdtime value, in seconds, to use when negotiating a
connection with this peer.
According to the specification, if the BGP speaker does not
receive a keepalive update or notification message from its peer
within the period specified by the holdtime value in the BGP Open
message, the BGP connection is closed.
The value must be either 0, that is, no keepalives are sent, or at
least 6.
Range: 0, 6-65535
Default: 180

Needed when Select Ignore First AS Hop to force this router to ignore the first AS
Peering with number in the AS_PATH for routes learned from the corresponding
Route Server peer.
Important - Select this option only if you are peering with a route
server in so-called transparent mode, that is, when the route server
is configured to redistribute routes from multiple ASs without
prepending its own AS number.
Default: Cleared

Keep Alive Select Keep Alive Always to force this router always to send
keepalives even when an update can substitute.
This setting allows interoperability with routers that do not completely
adhere to the protocol specifications on this point.
Default: Cleared

R82.10 Gaia Advanced Routing Administration Guide | 61


Configuring BGP Remote Peers in Gaia Portal

Table: BGP Peer parameters in Gaia Portal (continued)


Parameter Description

Routes Accept Routes Received From the Peer controls if routes received
from peer routes are accepted if there is an inbound BGP route policy.
If an inbound policy to accept the route does not exist, you can select
All or None:
n All - Specifies to accept and install routes with an invalid
preference. Depending on the local BGP inbound policy the
routes could become active or inactive.
n None - Specifies to delete routes learned from a peer when no
explicit local BGP inbound policy exists. This option is used to
save memory overhead when many routes are rejected because
there is no local policy. These routes can be relearned only by
restarting the BGP session.
Default: All

Allows Accept Select Passive to force this router to wait for the peer to issue an open.
TCP Sessions By default all explicitly configured peers are active and periodically
from Your Peer send open messages until the peer responds.
Modifying this option resets the peer connection.
Default: Cleared

Authentication The type of authentication scheme to use between given peers.


In general peers must agree on the authentication configuration to form
peer adjacencies.
This feature guarantees that routing information is accepted only from
trusted peers.
If you selected MD5, the Password field appears. When you enter a
password, MD5 authentication is used with the given peer.
Options: None, or MD5
Default: None

Limit BGP Controls the network traffic when there are many BGP peers.
Updates Send to Throttle Count determines the number of BGP updates sent at a time.
a Peer Range: 0-65535
Default: No default

Default Select Suppress Default Originate to NOT generate a default route


Originate when the peer receives a valid update from its peer.
Default: Cleared

R82.10 Gaia Advanced Routing Administration Guide | 62


Configuring BGP Remote Peers in Gaia Portal

Table: BGP Peer parameters in Gaia Portal (continued)


Parameter Description

Route Refresh Route refresh is used to either re-learn routes from the BGP peer or to
refresh the routing table of the peer without tearing down the BGP
session.
Both peers must support the BGP route refresh capability and should
have advertised this at the time peering was established.
Re-learning of routes previously sent by the peer is accomplished by
sending a BGP route refresh message.
The peer responds to the message with the current routing table.
Similarly, if a peer sends a route refresh request the current routing
table is re-sent.
You can also trigger a route update without having to wait for a route
refresh request from the peer.
Both peers must support the same address and subsequent address
families.
For example a request for IPv6 unicast routes from a peer that did not
advertise the capability during session establishment will be ignored.
Note - Clicking a refresh button sends a trigger to the routing
daemon. It does not change the configuration of the router.

Graceful Restart n Helper


Routes received from peer are preserved if the peer goes down
till either the session is re-established ("Open" message is
received from the peer after it comes back up) or the graceful
restart timer expires.
Default: Cleared
n Stalepath Time
The maximum time for which routes previously received from a
restarting router are kept unless they are re-validated.
The timer is started after the peer sends indication that it is up
again.
Range: 60 - 65535
Default: 360

Logging n Log bgp peer transitions


Select to force this router to log a message whenever a BGP peer
enters or leaves the ESTABLISHED state.
Default: Cleared
n Log warnings
Select to force this router to log a message whenever a warning
scenario is encountered in the codepath.
Default: Cleared

R82.10 Gaia Advanced Routing Administration Guide | 63


Configuring BGP Remote Peers in Gaia Portal

Table: BGP Peer parameters in Gaia Portal (continued)


Parameter Description

Trace Options The tracing options for BGP. The BGP implementation inherits the
default values for global trace options.
You can override these values on a group or neighbor basis.
Log messages are saved in the /var/log/[Link] file.
See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 64


Restarting BGP Peers in Gaia Portal

Restarting BGP Peers in Gaia Portal


This lets you restart BGP peering without restarting the Gaia RouteD daemon.

To restart BGP peering with all peers in all groups:


1. From the left navigation tree, click Advanced Routing > BGP.
2. In the Peer Groups section, click Restart All.

To restart BGP peering with all peers in the specified group:


1. From the left navigation tree, click Advanced Routing > BGP.
2. In the Peer Groups section, select the peer group.

3. Click Restart.

To restart BGP peering with the specified peer:


1. From the left navigation tree, click Advanced Routing > BGP.
2. In the Peer Groups section, select the peer group.
3. Click Edit.
4. In the Peers section, select the peer.
5. Click Restart.

Important:
n Restarting any part of a BGP protocol causes neighbor adjacencies to be torn
down and brought back up.
n The protocol's Graceful Restart mechanism does not take effect.
n Side effects of restarting a BGP instance include:
l Loss of BGP routes

l Traffic outage

l Network topology reconvergence

n In a ClusterXL or VRRP Cluster, restart of a BGP instance does not trigger a


failover.

R82.10 Gaia Advanced Routing Administration Guide | 65


Monitoring BGP in Gaia Portal

Monitoring BGP in Gaia Portal

Monitoring BGP
1. From the left navigation tree, click Advanced Routing > BGP.
2. In the top right corner, click Monitoring.
3. In the BGP Monitor section, click on the Information category.

Note - The page is static. To see the latest values, click Reload.

Troubleshooting BGP

See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 66


Configuring BGP in Gaia Clish

Configuring BGP in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

n To see the available "set" commands for BGP, enter in Gaia Clish:

set bgp[Esc][Esc]

n To see the available "show" commands for BGP, enter in Gaia Clish:

show bgp[Esc][Esc]

n To see the available "restart" commands for BGP, enter in Gaia Clish:

restart bgp[Esc][Esc]

R82.10 Gaia Advanced Routing Administration Guide | 67


Configuring External BGP in Gaia Clish

Configuring External BGP in Gaia Clish


Use these commands to configure external sessions of the protocol (between routers in
different autonomous systems).

Syntax

set bgp external remote-as <Number of Autonomous System>


{off | on}
aspath-prepend-count <1-25 | default>
description "Your Text"
local-address <IP Address> {off | on}
outdelay <0-65535>
outdelay off

Parameters

Parameter Description

<Number of The autonomous system number of the external peer group.


Autonomous Enter an integer from 1 to 65535.
System>

{off | on} Enables or disables the BGP autonomous system.

aspath- The number of times this router adds to the autonomous system path
prepend- on external BGP sessions.
count <1-25> Use this option to bias the degree of preference some downstream
| default> routers have for the routes originated by this router.
Some implementations prefer to select paths with shorter autonomous
system paths. Default is 1.

description Optional: You can enter a brief text description of the group.
"Your Text"

R82.10 Gaia Advanced Routing Administration Guide | 68


Configuring External BGP in Gaia Clish

Parameter Description

local- The address used on the local end of the TCP connection with the peer.
address <IP For external peers that do not have multihop enabled, the local address
Address> must be on an interface that is shared with the peer or with the peer's
{off | on} gateway when the gateway parameter is used.
A session with an external peer is opened only when an interface with a
local address, through which the peer or gateway address is directly
reachable is operating.
For other types of peers, a peer session is maintained when any
interface with the specified local address is operating.
In either case, incoming connections are recognized as matching a
configured peer only if they are addressed to the configured local
address.
Default: off
Note - If running BGP in a cluster you must not configure the local
address.

outdelay <0- The amount of time in seconds that a route must be present in the
65535> routing database before it is redistributed to BGP. The configured value
applies to all peers configured in this group. This feature dampens
route fluctuation. The value zero (0) disables this feature.
Default: 0

outdelay off Disables outdelay.

R82.10 Gaia Advanced Routing Administration Guide | 69


Configuring Internal BGP in Gaia Clish

Configuring Internal BGP in Gaia Clish


Use these commands to configure internal BGP sessions (between routers within the same
autonomous system).

Syntax

set bgp internal


{off | on}
description "Your Text"
export-routemap <Name of Route Map>
off
preference <1-65535>
any-pass-routemap <Name of Route Map>
on
family {inet | inet6 | inet-and-inet6} on
family {inet | inet6 | inet-and-inet6}
on
any-pass-routemap <Name of Route Map> on
no-pass-routemap <Name of Route Map> on
no-pass-routemap <Name of Route Map>
on
family {inet | inet6 | inet-and-inet6} on
import-routemap <Name of Route Map>
off
preference <1-65535>
family {inet | inet6 | inet-and-inet6} on
interface {all | <Name of Interface>} {off | on}
local-address <IP Address> {off | on}
med {<0-4294967295> | default }
nexthop-self {off | on}
outdelay {<0-65535> | off}
protocol {all | bgp_internal_protocol} {off | on}
route-refresh {off | on}

R82.10 Gaia Advanced Routing Administration Guide | 70


Configuring Internal BGP in Gaia Clish

set bgp internal peer <IP Address>


accept-routes {all | none}
allowas-in-count {<0-10> | default}
authtype {none | md5 secret <Secret>}
capability {default | ipv4-unicast {off | on} | ipv6-unicast
{off | on}}
comment "<Your Text>"
graceful-restart {off | on}
graceful-restart-helper-stalepath-time {<60-65535> |
default}
holdtime {<6-65535> | default}
ignore-first-ashop {off | on}
ip-reachability-detection {check-control-plane-failure |
multihop | off | on}
keepalive {<2-21845> | default}
local-address <IP Address> {off | on}
log-state-transitions {off | on}
log-warnings {off | on}
no-aggregator-id {off | on}
passive-tcp {off | on}
peer_type {none | no-client-reflector | reflector-client}
{off | on}
ping {off | on}
route-refresh {off | on}
send-keepalives {off | on}
send-route-refresh
request {all | ipv4 | ipv6} unicast}
route-update {all | ipv4 | ipv6} unicast}
suppress-default-originate {off | on}
throttle-count {<0-65535> | off}
trace bgp_traceoption {off | on}
weight {<0-65535> | off}

Parameters

Parameter Description

{off | on} Enable or disable an internal BGP group.

description "Your Optional: A brief text description of the group.


Text" Maximum: 100 characters.

R82.10 Gaia Advanced Routing Administration Guide | 71


Configuring Internal BGP in Gaia Clish

Parameter Description

export-routemap Configures the export policy for the given BGP peer group or
<Name of Route Map> peer.
<parameters>} See "Configuring Route Maps in Gaia Clish" on page 606.
If route maps are configured for both a peer and its peer
group, the Security Gateway ignores the peer group route
maps for that peer.
n off
Disables the Route Map policy.
n preference <1-65535>
Configures the Route Map preference that determines
the order in which this Route Map is applied in the
export policy for the given BGP peer group.
The lower the preference value, the higher the
preference (priority) of a Route Map.
l any-pass-routemap <Name of Route

Map>
Makes the export Route Map dependent on any
route matching the specified Route Map.
l family {inet | inet6 | inet-and-

inet6}
Restricts the Route Map to match the specified
address family.
l no-pass-routemap <Name of Route Map>

Makes the export Route Map dependent on no


route matching the specified Route Map.

import-routemap Configures the import policy for the given BGP peer group or
<Name of Route Map> peer.
{off | preference See "Configuring Route Maps in Gaia Clish" on page 606.
<parameters>} If route maps are configured for both a peer and its peer
group, the Security Gateway ignores the peer group route
maps for that peer.
n off
Disables the Route Map policy.
n preference <1-65535> [ family {inet |
inet6 | inet-and-inet6} ] on
Configures the Route Map preference that determines
the order in which this Route Map is applied in the
import policy for the given BGP peer group.
The lower the preference value, the higher the
preference (priority) of a Route Map.

R82.10 Gaia Advanced Routing Administration Guide | 72


Configuring Internal BGP in Gaia Clish

Parameter Description

interface {all | Enable or disable the specified internal peer group on all
<Name of interfaces or a specific interface.
Interface>} {off |
on}

local-address <IP The address used on the local end of the TCP connection
Address> {off | on} with the peer.
For external peers that do not have multihop enabled, the
local address must be on an interface that is shared with the
peer or with the peer's gateway when the gateway parameter
is used.
A session with an external peer is opened only when an
interface with a local address through which the peer or
gateway address is directly reachable operates.
For other types of peers, a peer session is maintained when
any interface with the specified local address operates.
In both cases, incoming connections are recognized as
matching a configured peer only if they are addressed to the
configured local address.
Default: off
Note - If you run BGP in a cluster, you must not configure
the local address.

med {<0-4294967295> Defines the Multi-Exit Discriminator (MED) metric used when
| default} advertising routes to all peers in this group.
If no value is specified, then no metric is propagated.
Any metric configured in redistribution policy for this peer
group will override the value configured here.
Default: No MED is advertised

R82.10 Gaia Advanced Routing Administration Guide | 73


Configuring Internal BGP in Gaia Clish

Parameter Description

nexthop-self {off | This router sends one of its own IP addresses as the BGP
on} next hop.
Default: off
Important - If in the Check Point Gaia OS, you change
the state of the BGP "nexthop-self" setting (from
"off" to "on", or from "on" to "off") in an active BGP
deployment, then it is necessary to force a new update to
BGP peers that are already established.
n If the BGP "route-refresh" is enabled on the
BGP peers, then run this Gaia Clish command:
set bgp internal peer <IP Address>
send-route-refresh route-update all
unicast
n If the BGP "route-refresh" is disabled on the
BGP peers, then it is necessary to restart the BGP
session.

outdelay {<0-65535> Configures or disables the amount of time in seconds that a


| off} route must be present in the routing database before it is
redistributed to BGP.
The configured value applies to all peers configured in this
group.
This feature dampens route fluctuation.
Default: 0 (means that this feature is disabled)

protocol {all | Enable or disable all internal routing protocols on the


<BGP Internal specified internal peer group or specific internal protocols.
Protocol>} {off | You can enter the following specific internal protocols:
on} direct, rip, static, ospf, and ospfase.

route-refresh {off Re-learns routes previously sent by the BGP peer or


| on} refreshes the routing table of the peer.
The peer responds to the message with the current routing
table.
Similarly, if a peer sends a route refresh request the current
routing table is re-sent.
A user can also trigger a route update without having to wait
for a route refresh request from the peer.

R82.10 Gaia Advanced Routing Administration Guide | 74


Configuring Internal BGP in Gaia Clish

Parameter Description

peer <IP Address> An inbound BGP policy route if one is not already configured.
accept-routes {all
n all
| none}
Specifies accept routes and installing them with an
invalid preference.
Depending on the local inbound route policy, these
routes are then made active or inactive.
n none
Specifies to delete routes learned from a peer.
This option saves memory overhead when many routes
are rejected because no inbound policy exists.

peer <IP Address> Specifies the number of times the Local AS can occur in an
allowas-in-count AS path received from this peer.
{<0-10> | default} A value of 0 means that the Local AS cannot be in the
received AS path.
If the Peer Local AS feature is enabled, then this value
represents the total cumulative occurances of the Local AS
and Peer Local AS that can occur in an AS path.
Default: 0

peer <IP Address> Configures the authentication scheme between peers.


authtype {none | Using an authentication scheme guarantees that routing
md5 secret information is accepted only from trusted peers.
<Secret>}
n none
Does not use an authentication scheme between peers.
Using an authentication scheme guarantees that routing
information is accepted only from trusted peers.
n md5 secret <Secret>
Uses MD5 authentication between peers.
In general, peers must agree on the authentication
configuration to and from peer adjacencies.

peer <IP Address> Configure the IP capabilities supported for this session.
capability {default
n default
| ipv4-unicast {off
| on} | ipv6- Configures the default behavior:
unicast {off | on}} "ipv4-unicast on" and "ipv6-unicast off"
n ipv4-unicast {off | on}
Specifies that IPv4 unicast routes be exchanged with
this peer.
n ipv6-unicast {off | on}
Specifies that IPv6 unicast routes be exchanged with
this peer.

R82.10 Gaia Advanced Routing Administration Guide | 75


Configuring Internal BGP in Gaia Clish

Parameter Description

peer <IP Address> Optional: A brief text description of the peer.


comment "Your Text" Maximum: 100 characters.

peer <IP Address> Whether the Check Point system should maintain the
graceful-restart forwarding state advertised by peer routers even when they
{off | on} restart to minimize the negative effects caused by peer
routers restarting.
Default: off

peer <IP Address> The maximal amount of time that routes previously received
graceful-restart- from a restarting router are kept so that they can be validated
helper -stalepath- again.
time {<60-65535> | The timer is started after the peer sends an indication that it
default} has recovered.
Default: 360

peer <IP Address> The BGP holdtime interval, in seconds, when negotiating a
holdtime {<6-65535> connection with the specified peer.
| default} If the BGP speaker does not receive a keepalive update or
notification message from its peer within the period specified
in the holdtime field of the BGP open message, the BGP
connection is closed.
Default: 180

peer <IP Address> Ignore the first autonomous system number in the
ignore-first-ashop autonomous system path for routes learned from the
{off | on} corresponding peer.
Note - Set this option only if you are peering with a route
server in transparent mode, that is, when the route server
is configured to redistribute routes from multiple other
autonomous systems without prepending its own
autonomous system number.

R82.10 Gaia Advanced Routing Administration Guide | 76


Configuring Internal BGP in Gaia Clish

Parameter Description

peer <IP Address> Configure Bidirectional Forwarding Detection (BFD) on each


ip-reachability- Security Gateway and cluster member that sends or receives
detection {off | on BFD packets.
| multihop | check-
n off
control-plane-
failure} The default state.
Stale routes are purged when the peer goes down.
n on
Sets the peer to singlehop BFD. Singlehop BFD is for a
peer that is one hop away. The peer must be on a
directly connected network. Make sure the Firewall
policy allows UDP port 3784 in both directions.
n multihop
For a peer is one or more hops away. Make sure the
Firewall policy allows UDP port 4784 in both directions.
The configuration on both BFD peers must be the same
(both configured as multihop or singlehop).
n check-control-plane-failure
Interprets the control plane independent flag (the C bit)
received from the remote BFD peer.
When these two conditions are met at the same time,
the gateway keeps stale routes and does not purge
them, for graceful restart purposes:
a. The C-bit received from the peer is zero.
b. BGP graceful restart is enabled.

Make sure the SmartConsole topology is correct (issues with


incorrect Firewall topology can cause anti-spoofing to
interfere with BFD traffic.

peer <IP Address> The keepalive option is an alternative way to specify a


keepalive {<2- holdtime value in seconds when negotiating a connection with
21845> | default} the specified peer.
You can use the keepalive interval instead of the holdtime
interval.
You can also use both interval, but the holdtime value must
be 3 times the keepalive interval value.
Default: 60

R82.10 Gaia Advanced Routing Administration Guide | 77


Configuring Internal BGP in Gaia Clish

Parameter Description

peer <IP Address> Configures the address to be used on the local end of the
local-address <IP TCP connection.
Address> {off | on} The local address must be a valid address configured on a
local interface.
Remote eBGP peers may need to enable BGP multihop to
reach the configured local address if the local address is not
on a shared interface.
For eBGP peers that do not have multihop enabled, the local
address must be on an interface that is shared with the peer
or the peer's gateway when the gateway parameter is used.
A session with an external peer is opened only when an
interface with a local address through which the peer or the
gateway is directly reachable is operating.
For other types of peers, a session is maintained when any
interface with the address is operating.
In all cases, incoming connections are accepted only when
they are addressed to the configured value.
This option is ignored when using VRRP.
When using ClusterXL, the physical IP address should be
used, not the Cluster Virtual IP address.

peer <IP Address> The router generates a log message whenever a peer enters
log-state- or leave the established state.
transitions {off | Default: off
on}

peer <IP Address> The router generates a log message whenever a warning
log-warnings {off | scenario is encountered in the codepath.
on} Default: off

peer <IP Address> The router's aggregate attribute as zero (rather than the
no-aggregator-id router ID value).
{off | on} This option prevents different routers in an AS from creating
aggregate routes with different AS paths.
Default: off

peer <IP Address> The router waits for the specified peer to issue an open
passive-tcp {off | message.
on} No TCP connections are initiated by the router.
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 78


Configuring Internal BGP in Gaia Clish

Parameter Description

peer <IP Address> Specifies if this is a Route Reflector client.


peer_type {none |
n none
reflector-client |
no-client- Peer is not a Route Reflector.
reflector} {off | Enter this option, if you do not want to specify route
on} reflection.
n no-client-reflector
Peer is a 'non-client' Route Reflector.
Enter this option to specify that a reflection client's
routes are reflected only to internal BGP peers in other
groups.
Clients in the group are assumed to be direct iBGP
peers of each other.
n reflector-client
Peer is a Route Reflector. Enter this option to specify
that the local router acts as a route reflector for the
group of peers named.
That is, the local router is the route reflection server,
and the named peers are route reflection clients.
Normally, the routing daemon readvertises, or reflects,
routes it receives from one of its clients to all other iBGP
peers, including the other peers in that client's group.

peer <IP Address> Enables (on) or disables (off) the ping for this peer.
ping {off | on} If ping is enabled for this peer and this established BGP peer
stops responding to pings, then after a configured number of
missed pings (configured with the "set bgp ping count
<Number>" command), the BGP peer will be forced from an
established state to reconnect manually.
Peers with this feature enabled must be able to receive and
respond to echo requests, or it will not function properly.
If ping is disabled for this peer, it will continue to handle BGP
connections according to protocol without any assistance
from
pings to verify connectivity.

peer <IP Address> This router always sends keepalive messages even when an
send-keepalives update message is sufficient.
{off | on} This option allows interoperability with routers that do not
strictly adhere to protocol specifications regarding update.

R82.10 Gaia Advanced Routing Administration Guide | 79


Configuring Internal BGP in Gaia Clish

Parameter Description

peer <IP Address> The router dynamically request BGP route updates from
send-route-refresh peers or respond to requests for BGP route updates.
[request | route-
update {all | ipv4
| ipv6} [unicast]

peer <IP Address> Specifies whther to eliminate (on) or not (off) this peer from
suppress-default- consideration when generating the BGP default route.
originate {off | The BGP default route is configured with the command ''set
on} bgp default-route-gateway".

peer <IP Address> The number of BGP updates to send at one time.
throttle-count {<0- The throttle count option limits the number of BGP updates
65535> | off} when there are many BGP peers.
The value "off" disables the throttle count option.

peer <IP Address> Tracing options for the BGP implementation.


trace bgp_ Log messages are saved in the /var/log/[Link].*
traceoption {off | files.
on} See "Trace Options" on page 672.

peer <IP Address> The weight associated with the specified peer.
weight {<0-65535> | BGP implicitly stores any rejected routes by not mentioning
off} them in a route filter.
BGP explicitly mentions them within the routing table by using
a restrict keyword with a negative weight.
A negative weight prevents a route from becoming active,
which prevents it from being installed in the forwarding table
or exported to other protocols.
This eliminates the need to break and reestablish a session
upon reconfiguration if import route policy is changed.
The value "off" disables the weight associated with the
specified peer.

R82.10 Gaia Advanced Routing Administration Guide | 80


Configuring BGP Remote Peers in Gaia Clish

Configuring BGP Remote Peers in Gaia Clish


Gaia supports IPv4 and IPv6 addresses for BGP peers.
Use these commands to configure BGP peers.

R82.10 Gaia Advanced Routing Administration Guide | 81


Configuring BGP Remote Peers in Gaia Clish

Syntax

set bgp external remote-as <Number of Autonomous System> peer <IP


Address>
{off | on}
accept-med {off | on}
accept-routes {all | none}
allowas-in-count {<0-10> | default}
as-override {off | on}
authtype {none | md5 secret <Secret>}
capability {default | ipv4-unicast | ipv6-unicast} {off |
on}
graceful-restart {off | on}
graceful-restart-helper-stalepath-time <Seconds>
holdtime {<6-65535> | default}
ignore-first-ashop {off | on}
ip-reachability-detection
check-control-plane-failure {off | on}
multihop {off | on}
{off | on}
keepalive {<2-21845> | default}
log-state-transitions {off | on}
log-warnings {off | on}
med-out {<0-4294967294> | default}
multihop {off | on}
no-aggregator-id {off | on}
outgoing-interface <Name of Interface> {off | on}
passive-tcp {off | on}
peer-local-as
dual peering {off | on}
inbound-peer-local {off | on}
outbound-local {off | on}
peer-local-as as {{<1-4294967295> | <0.1-65535.65535>} on |
off}
remove-private-as {off | on}
route-refresh {off | on}
send-keepalives {off | on}
send-route-refresh {request | route-update} {ipv4 | ipv6 |
all} [unicast]
suppress-default-originate {off | on}
throttle-count {<0-65535> | off}
trace bgp_traceoption {off | on}
ttl {<1-255> | default}

R82.10 Gaia Advanced Routing Administration Guide | 82


Configuring BGP Remote Peers in Gaia Clish

Parameters

Parameter Description

IP Address {off | on} A specified peer IP address for the group.

med-out {<0- The Multi-Exit Discriminator (MED) metric used as the


4294967294> | default} primary metric on all routes sent to the specified peer
address.
This metric overrides the default metric on a metric
specified by the redistribute policy.
External peers use MED values to know which of the
available entry points into an autonomous system is
preferred.
A lower MED value is preferred over a higher MED value.
Range: 0-4294967294
Default: 4294967294

outgoing-interface Applies only to IPv6 peer with local address FE80:


<Name of Interface> All peer interfaces have a local address and a global
{off | on} address.
All the peer interfaces can have the same local address,
which starts with FE80:.
To use the local address, you must enter the outgoing
interface for the local address.

accept-med {off | on} Accept MED from the specified peer address.
If you do not set this option, the MED is stripped from the
advertisement before the update is added to the routing
table.
Default: off

multihop {off | on} Enable multihop connections with external BGP (eBGP)
peers that are not directly connected.
By default, external BGP peers are expected to be directly
connected.
You can configure the multihop session in the Time to Live
(TTL) parameter, that is, the number of hops to the eBGP
peer.
This option can also be used to set up peers for eBGP load
balancing.
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 83


Configuring BGP Remote Peers in Gaia Clish

Parameter Description

peer-local-as as {{<1- Configures the connection to a remote peer with a Peer


4294967295> | <0.1- Local ASN, on a per-peer basis.
65535.65535>} on | The Peer Local ASN replaces the Local ASN in the BGP
off} session.
Range: 1 - 4294967295, or 0.1 - 65535.65535
Default: none

peer-local-as Configures a peer-specific Local AS number different to


{inbound-peer-local | the system-wide Local AS number.
outbound-local | dual
peering} {off | on}
n "inbound-peer-local" - Prepend Peer Local AS
on inbound updates from peer. Default: on.
n outbound-local" - Prepend Local AS on
outbound updates to peer. Default: on.
n "dual-peering" - Allow peering from Local AS and
Peer Local AS. Default: off.

as-override {off | on} As a rule, to prevent loops in BGP, routers examine the AS
number in the AS Path.
If a router sees its own AS number in the AS Path of the
BGP packet, it drops the packet.
This feature lets the router at the sending end override the
peer's AS number with the router's AS number in the
outbound AS path.
This helps multiple sites in the same AS accept the routes.
If the Peer Local AS feature is enabled, the router uses the
configured Peer Local AS to override the remote peer's AS
number.
Default: off

allow-as-in-count {0- This feature lets the router at the receiving end override
10 | default} the peer's AS number with the router's AS number in the
inbound AS path.
This is an inbound property whereas as-override is an
outbound property.
Range: 0-10
Default: 0

R82.10 Gaia Advanced Routing Administration Guide | 84


Configuring BGP Remote Peers in Gaia Clish

Parameter Description

ttl {<1-255> | Use the TTL (Time to Live) parameter to limit the number
default} of hops over which the External BGP (eBGP) multihop
session is created.
You can configure the TTL only if eBGP multihop is
enabled.
When multihop is disabled the default TTL is 1.
Range: 1-255
Default: 64

no-aggregator-id {off The router's aggregate attribute as zero (rather than the
| on} router ID value).
This option prevents the creation of aggregate routes with
different AS paths by different routers in an AS.
Default: off

holdtime {<6-65535> | The BGP holdtime interval, in seconds, during the


default} negotiation of a connection with the specified peer.
If the BGP speaker does not receive a keepalive update or
notification message from its peer within the period
specified in the holdtime field of the BGP open message,
the BGP connection is closed.
Range: 6-65535
Default: 180

keepalive {<2-21945> | The keepalive option is an alternative way to enter a


default} holdtime value in seconds during the negotiation of a
connection with the specified peer.
You can use the keepalive interval instead of the holdtime
interval.
You can also use both intervals, but the holdtime value
must be 3 times the keepalive interval value.
Range: 2-21945
Default: 60

ignore-first-ashop Ignore the first AS number in the AS path for routes


{off | on} learned from the corresponding peer.
Set this option only if you peer with a route server in
transparent mode.
In transparent mode, the route server redistributes routes
from multiple other autonomous systems and does not
prepend its own ASN.
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 85


Configuring BGP Remote Peers in Gaia Clish

Parameter Description

send-keepalives {off | The router always sends keepalive messages even when
on} an update message is sufficient.
This option lets the router interoperate with other routers
that do not strictly follow protocol specifications regarding
updates.
Default: none

send-route-refresh The router dynamically requests BGP route updates from


{request | route- peers or responds to requests for BGP route updates.
update}{ipv4 | ipv6 | This setting is not supported for iBGP.
all} unicast Default: none

route-refresh {off | Re-learns routes previously sent by the BGP peer or


on} refreshes the routing table of the peer.
The peer responds to the message with the current routing
table.
Similarly, if a peer sends a route refresh request the
current routing table is re-sent.
A user can also trigger a route update and not wait for a
route refresh request from the peer.
Default: off

accept-routes {all | An inbound BGP policy route if one is not already


none} configured.
n "all" - Accepts routes and installs them with an
invalid preference.
Depending on the local inbound route policy, these
routes are then made active or inactive.
n "none" - Deletes routes learned from a peer.
This option saves memory overhead when many
routes are rejected because there is no inbound
policy.
Default: all

passive-tcp {off | on} The router waits for the specified peer to issue an open
message.
The router does not initiate TCP connections.
Default: off

remove-private-as {off Remove private AS numbers from BGP update messages


| on} to external peers.
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 86


Configuring BGP Remote Peers in Gaia Clish

Parameter Description

authtype {none | md5 Configure authentication policy for this peer.


secret <Secret>}
n "none" - Does not use an authentication scheme
between peers.
If you use an authentication scheme, routing
information is accepted only from trusted peers.
n "md5" - Uses MD5 authentication between peers.
In general, peers must agree on the authentication
configuration to and from peer adjacencies.
If you use an authentication scheme, routing
information is accepted only from trusted peers.

Default: none

throttle-count {<0- The number of BGP updates to send at one time.


65535> | off} This option limits the number of BGP updates when there
are many BGP peers.
Value "off" disables the throttle count option.
Range: 0-65535
Default: none

suppress-default- Do NOT generate a default route when the peer receives a


originate {off | on} valid update from its peer.
Default: none

log-state-transitions The router generates a log message when a peer enters or


{off | on} leaves the established state.
Default: off

log-warnings {off | The router generates a log message when there is a


on} warning scenario in the codepath.
Default: off

trace bgp_traceoption Tracing options for the BGP implementation.


{off | on} Log messages are saved in the
/var/log/[Link].* files.
See "Trace Options" on page 672.
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 87


Configuring BGP Remote Peers in Gaia Clish

Parameter Description

capability {default | On each peer, configure the type of routes (Multiprotocol


ipv4-unicast | ipv6- capability) to interchange between peers.
unicast} {off | on} Select one of these:
n IPv4 Unicast Only. Default: on.
n IPv6 Unicast Only. Default: off.
n Both IPv4 and IPv6. Default: off.
To create peering, the routers must share a capability.

graceful-restart {off Sets the Check Point system to maintain the forwarding
| on} state advertised by peer routers even when they restart.
This minimizes the negative effects caused by the restart
of peer routers.
See sk100499.
Default: off

graceful-restart- The maximum number of seconds that routes previously


helper-stalepath-time received from a restarting router are kept so that they can
<Seconds> be validated again.
The timer starts after the peer sends an indication that it
recovered.
See sk100499.
Range: 60-65535
Default: 360

R82.10 Gaia Advanced Routing Administration Guide | 88


Configuring BGP Remote Peers in Gaia Clish

Parameter Description

ip-reachability- Configure Bidirectional Forwarding Detection (BFD) on


detection {off | on | each Security Gateway and cluster member that sends or
multihop | check- receives BFD packets.
control-plane-failure}
n "off" - Stale routes are purged when the peer goes
down. This is the default state.
n "on" - Sets the peer to singlehop BFD. Singlehop
BFD is for a peer that is one hop away.
The peer must be on a directly connected network.
Make sure the Firewall policy allows UDP port 3784
in both directions.
n "multihop" - For a peer is one or more hops away.
Make sure the Firewall policy allows UDP port 4784
in both directions.
The configuration on both BFD peers must be the
same (both configured as multihop or singlehop.
n "check-control-plane-failure" - Interprets
the control plane independent flag (the C bit)
received from the remote BFD peer.
When these two conditions are met at the same time,
the gateway keeps stale routes and does not purge
them, for graceful restart purposes:
a. The C-bit received from the peer is zero.
b. BGP graceful restart is enabled.

Default: off
Make sure the SmartConsole topology is correct (issues
with incorrect Firewall topology can cause Anti-Spoofing to
interfere with BFD traffic.

R82.10 Gaia Advanced Routing Administration Guide | 89


Configuring BGP Confederation in Gaia Clish

Configuring BGP Confederation in Gaia Clish


In This Section:

You can configure a BGP confederation in conjunction with external BGP.

Configuring BGP Confederations

Syntax

set bgp
confederation identifier <Number of Autonomous System>
confederation identifier off
confederation aspath-loops-permitted <1-10>
confederation aspath-loops-permitted default
routing-domain identifier <Number of Autonomous System>
routing-domain identifier off
routing-domain aspath-loops-permitted <1-10>
routing-domain aspath-loops-permitted default
synchronization {off | on}

Parameters

Parameter Description

confederation Specifies the identifier for the entire confederation. This identifier
identifier is used as the autonomous system number in external BGP
<Number of sessions. Outside the confederation, the confederation id is the
Autonomous autonomous system number of a single, large autonomous
System> system. Thus the confederation id must be a globally unique,
typically assigned autonomous system number.

confederation Disables the confederation identifier.


identifier off

confederation Specifies the number of times the local autonomous system can
aspath-loops appear in an autonomous system path for routes learned through
permitted <1-10> BGP. If this number is higher than the number of times the local
autonomous system appears in an autonomous system path, the
corresponding routes are discarded or rejected.

R82.10 Gaia Advanced Routing Administration Guide | 90


Configuring BGP Confederation in Gaia Clish

Parameter Description

confederation Specifies a value of 1.


aspath loops-
permitted
default

routing-domain Specifies the routing domain identifier (RDI) for this router. You
identifier must specify the RDI if you are using BGP confederations. The
<Number of RDI does not need to be globally unique since it is used only
Autonomous within the domain of the confederation.
System>

routing-domain Disables the routing-domain identifier.


identifier off

routing-domain Specifies the number of times the local autonomous system can
aspath-loops- appear in an autonomous system path for routes learned through
permitted <1-10> BGP. If this number is higher than the number of times the local
autonomous system appears in an autonomous system path, the
corresponding routes are discarded or rejected.

routing-domain Specifies a value of 1.


aspath-loops-
permitted
default

synchronization Enables IGP synchronization. Set this option On to cause internal


{off | on} and confederation BGP peers to check for a matching route from
IGP protocol before installing a BGP learned route.

R82.10 Gaia Advanced Routing Administration Guide | 91


Configuring BGP Confederation in Gaia Clish

Configuring BGP Confederation Peers

Note - The IP address of a peer can be an IPv4 or an IPv6 address.

R82.10 Gaia Advanced Routing Administration Guide | 92


Configuring BGP Confederation in Gaia Clish

Syntax

set bgp confederation member-as <ID of Autonomous System>


{off | on}
description {off | "<Your Text>"}
interface <Name of Interface> {off | on}
local-address <IP Address> [{off | on}]
med {default | <Value>}
nexthop-self [{off | on}]
outdelay {off | <Delay>}
peer <IP Address>
[{off | on}]
accept-routes {all | none}
authtype {none | md5 secret <Password>}
capability {ipv4-unicast | ipv6-unicast} {off | on}
graceful-restart {off | on}
graceful-restart-stalepath-time {default | <Time>}
holdtime {default | <Time>}
ignore-first-ashop {off | on}
keepalive {default | <Time>}
local-address <Local IP Address> [{off | on}]
log-state-transitions {off | on}
log-warnings {off | on}
no-aggregator-id {off | on}
outgoing-interface <Name of Interface> {off | on}
passive-tcp {off | on}
peer-type
[none] [{off | on}]
[reflector-client {off | on}]
[no-client-reflector {off | on}]
ping {off | on}
route-refresh {off | on}
send-keepalives {off | on}
send-route-refresh
request {all | ipv4 | ipv6} unicast
route-update {all | ipv4 | ipv6} unicast
throttle-count {off | <Number>}
trace {all | keepalive | open | packets | update |
general | normal | policy | route | state | task | timer} {off |
on}
weight <Weight>
comment "<Your Text>"
protocol {all | bgp | direct | rip | static | ospf |
ospfase}

R82.10 Gaia Advanced Routing Administration Guide | 93


Configuring BGP Confederation in Gaia Clish

Parameters

Parameter Description

{off | on} Creates (on) or removes (off) a


peer group with AS ID.

description {off | "<Your Text>"] Optional: Sets the peer group


description to <Your Text>, or
turns off the description (off).

interface <Name of Interface> {off | Sets an interface (<Name of


on} Interface>: eth1, eth2, and so on)
as the peer group interface, and
turns it on or off.

local-address <IP Address> [{off | on}] Sets a peer group with an IP


address on the local gateway.

med {default | <Value>} Sets the peer group local Multi-Exit


Discriminator (MED).
The default is 0.

R82.10 Gaia Advanced Routing Administration Guide | 94


Configuring BGP Confederation in Gaia Clish

Parameter Description

nexthop-self {off | on} Sets (on) or removes (off) the


local gateway as the default exit
gateway for the peer group.
Important - If in the Check
Point Gaia OS, you change
the state of the BGP
"nexthop-self" setting
(from "off" to "on", or from
"on" to "off") in an active
BGP deployment, then it is
necessary to force a new
update to BGP peers that are
already established.
n If the BGP "route-
refresh" is enabled on
the BGP peers, then run
this Gaia Clish
command:
set bgp internal
peer <IP Address>
send-route-refresh
route-update all
unicast
n If the BGP "route-
refresh" is disabled on
the BGP peers, then it is
necessary to restart the
BGP session.

outdelay {off | <Delay>} Sets or removes (off) the out-


delay value (in seconds).
Set this value to enforce rate
limiting.

peer <IP Address> [{off | on}] Creates a peer group with the
specified gateway (<IP
Address>).

protocol {all | bgp | direct | rip | Sets an internal peer group


static | ospf | ospfase} protocol.

R82.10 Gaia Advanced Routing Administration Guide | 95


Configuring BGP Confederation in Gaia Clish

Parameter Description

peer <IP Address> accept-routes {all | Accepts routes from peers only if
none} there is an inbound BGP route
policy.
In the absence of a configured
import policy for this peer, specify
"all" or "none" here.
n all - Accepts and installs
routes with an invalid
preference. This is the
default.
Depending on the local BGP
inbound policy, the routes
can become active or
inactive.
n none - Deletes routes from a
peer when no explicit local
BGP inbound policy exists.
Use this option to save
memory overhead when
many routes are rejected
because there is no local
policy.
These routes can be re-
learned only if you restart the
BGP session.

peer <IP Address> authtype {none | md5 Sets peer authentication between
secret <Password>} the local gateway and the specified
peer gateway (<IP Address>).
You can set it to MD5 and specify
the password (<Password>), or
you can turn it off (none).

peer <IP Address> capability {ipv4- Configures peer multiprotocol


unicast | ipv6-unicast} [{off | on}] capabilities (ipv4-unicast or
ipv6-unicast) with the
specified peer (<IP Address>).
Turn these on or off, if
necessary.

peer <IP Address> graceful-restart {off Turns graceful restart on and off
| on} between the local gateway and the
specified peer (<IP Address>).

R82.10 Gaia Advanced Routing Administration Guide | 96


Configuring BGP Confederation in Gaia Clish

Parameter Description

peer <IP Address> graceful-restart- Sets graceful restart stalepath time


stalepath-time {default | <Time>} (in seconds) with the specified
peer (<IP Address>).

peer <IP Address> holdtime {default | Sets the maximum amount of time
<Time>} (in seconds) that can elapse
between messages from the
specified peer (<IP Address>).

peer <IP Address> ignore-first-ashop Sets the router to ignore the first
{off | on} AS number in the AS_PATH for
routes learned from the specified
peer.
Use this option for a route server
peer in so-called transparent
mode.
The route server is configured to
redistribute routes from multiple
ASs and does not prepend its own
AS number.

peer <IP Address> keepalive {default | Sets the keepalive timer (in
<Time>} seconds) for the specified peer
(<IP Address>).

peer <IP Address> local-address <Local Sets a local IP address (<Local


IP Address {off | on} IP Address) for the specified
peer (<IP Address>).

peer <IP Address> log-state-transitions Turns logging of peer state


{off | on} transitions on or off for the
specified peer (<IP Address>).

peer <IP Address> log-warnings {off | Turns logging of warnings on or


on} off for the specified peer (<IP
Address>).

peer <IP Address> no-aggregator-id {off Sets the specified peer (<IP
| on} Address>) to not aggregate AS
routes (on).
If set to off, the peer will create
aggregate routes.

R82.10 Gaia Advanced Routing Administration Guide | 97


Configuring BGP Confederation in Gaia Clish

Parameter Description

peer <IP Address> outgoing-interface Sets a specific outgoing interface


<Name of Interface> {off | on} (<Name of Interface>) to the
specified peer (<IP Address>).

peer <IP Address> passive-tcp {off | Sets peer passive behavior. If on,
on} the gateway does not initialize
connections to the specified
remote peer (<IP Address>).
The default is off.

peer <IP Address> peer-type {none | Sets the local gateway's peer type
reflector-client | no-client-reflector} in the relation to the specified peer
[{off | on}] (<IP Address>).

peer <IP Address> ping {off | on} Sets ping capability between the
local gateway and the specified
peer (<IP Address>).
The default is off.

peer <IP Address> route-refresh {off | Sets route refresh capability


on} between the local gateway and the
specified peer (<IP Address>).
The default is off.

peer <IP Address> send-keepalives {off Sets the gateway to always send
| on} keepalive messages to the
specified peer (<IP Address>).
The default is off.

peer <IP Address> send-route-refresh Sets the local gateway to request


request {all | ipv4 | ipv6} unicast BGP route updates from the
specified peer (<IP Address>).

peer <IP Address> send-route-refresh Sets the local gateway to respond


route-update {all | ipv4 | ipv6} to requests for BGP route updates
unicast from the specified peer (<IP
Address>).

peer <IP Address> throttle-count {off | Sets the maximum number of BGP
<Number>} updates that can be sent at one
time to the specified peer (<IP
Address>).
The range for the <Number> is 0-
65535. The default is off.

R82.10 Gaia Advanced Routing Administration Guide | 98


Configuring BGP Confederation in Gaia Clish

Parameter Description

peer <IP Address> trace [{keepalive | Sets the types of packets to trace
open | packets | update | all | general from the specified peer (<IP
| normal | policy | route | state | Address>).
task | timer}] {off | on}

peer <IP Address> weight <Weight> Sets the weight for the specified
peer (<IP Address>).
The value range for the <Weight>
is 0-65535.

peer <IP Address> comment "<Your Text>" Sets a comment associated with
the specified peer (<IP
Address>).

R82.10 Gaia Advanced Routing Administration Guide | 99


Configuring BGP Route Reflection in Gaia Clish

Configuring BGP Route Reflection in Gaia Clish


You can configure route reflection as an alternative to BGP confederations.
Route reflection supports both internal and external BGP routing groups.

Syntax

set bgp
internal peer <IP Address> peer-type
none
no-client-reflector
reflector-client
cluster-id {<IP Address> | off}
default-med {<0-65535> | off}
default-route-gateway {<IP Address> | off}

Parameters

Parameter Description

internal peer <IP The peer router <IP Address> is not a reflector client of
Address> the local router. This is the default.
peer-type none

internal peer <IP An advanced option.


Address>
peer-type no-client-
reflector

internal peer <IP The peer router <IP Address> is a reflector client of the
Address> local router.
peer-type reflector-
client

cluster-id <IP The cluster ID used for route reflection.


Address> The cluster ID default is that of the router id.
Override the default if the cluster has more than one route
reflector

cluster-id off Disable the cluster ID.

default-med <0-65535> The Multi-Exit Discriminator (MED) metric used to advertise


routes through BGP.

default-med off Disable the specified MED metric.

R82.10 Gaia Advanced Routing Administration Guide | 100


Configuring BGP Route Reflection in Gaia Clish

Parameter Description

default-route-gateway Installs the BGP default route in the kernel and then sends
<IP Address> that route to BGP peers.
This route has a higher rank than any configured default
static route for this router.
Notes:
n If you do not want a BGP peer considered for
generating the default route, use this command
(see "Configuring BGP Remote Peers in Gaia
Clish" on page 81):
set bgp external remote-as <Number
of Autonomous System> peer <IP
Address> suppress-default-originate
on
n If you want to originate a default route via BGP
without installing it in the kernel, you can use
NAT Pools to do so (see"NAT Pools" on
page 726). You can configure a default static
route ([Link]/0) using the NAT Pool feature and
advertise the route via BGP to your desired peers
using one of these methods:
l Route Maps

See:
o "Configuring Route Maps in Gaia

Clish" on page 606


l Route Redistribution

See:
o "Configuring Route Redistribution in

Gaia Portal" on page 534


o "Configuring IPv4 Route

Redistribution in Gaia Clish" on


page 552

default-route-gateway Disables the configured default BGP route.


off

R82.10 Gaia Advanced Routing Administration Guide | 101


Configuring BGP Route Dampening in Gaia Clish

Configuring BGP Route Dampening in Gaia Clish


BGP route dampening maintains a history of flapping routes and prevents advertising these
routes.
A route is considered to be flapping when it is repeatedly transitioning from available to
unavailable, or the other way around.

Note - BGP route dampening is supported only for External BGP (eBGP).

Syntax

set bgp dampening


{off | on}
suppress-above {<2-32> | default}
reuse-below {<1-32> | default}
max-flat {<3-64> | default}
reachable-decay {<1-900> | default}
unreachable-decay [<1-2700> | default}
keep-history {<2-5400> | default}

Parameters

Parameter Description

{off | on} Specifies whether to enable or disable BGP route dampening.

suppress- Specifies the value of the instability metric at which route suppression
above <2-32> takes place.
A route is not installed in the forwarding table or announced even if it
reachable during the period that it is suppressed.

suppress- Specifies an instability metric value for suppressing routes of 3.


above default

reuse-below Specifies the value of the instability metric at which a suppressed


metric <1-32> route becomes unsuppressed if it is reachable but currently
suppressed.
The value assigned to the reuse-below metric must be lower than the
suppress-above value.

reuse-below Specifies an instability metric value for announcing previously


metric suppressed routes of 2.
default

R82.10 Gaia Advanced Routing Administration Guide | 102


Configuring BGP Route Dampening in Gaia Clish

Parameter Description

max-flap <3- Specifies the upper limit of the instability metric.


64> The value must be greater than the suppress-above value plus 1.
Each time a route becomes unreachable, 1 is added to the current
instability metric.

max-flat Specifies the upper limit of the instability metric as 16.


default

reachable- Specifies the time for the instability metric to reach half of its value
decay <1-900> when the route is reachable.
The smaller the value the sooner a suppressed route becomes
reusable.

reachable- Specifies a value of 300.


decay default

unreachable- Specifies the time for the instability metric to reach half its value when
decay <1- the route is NOT reachable.
2700> The value must be equal to or higher than the reachable-decay value.

unreachable- Specifies a value of 900.


decay default

keep-history Specifies the period for which route flapping history is maintained for a
<2-5400> given route.

keep-history Specifies a value of 1800.


default

R82.10 Gaia Advanced Routing Administration Guide | 103


Configuring BGP Communities in Gaia Clish

Configuring BGP Communities in Gaia Clish


A BGP community is a group of destinations that share the same property.
However, a community is not restricted to one network or autonomous system.
Use communities to simplify the BGP inbound and route redistribution policies.
Use the BGP communities command(s) together with inbound policy and route redistribution.

Syntax

set bgp communities {off | on}

Parameters

Parameter Description

on Enable BGP policy options based on communities.

off Disable BGP policy options based on communities.

R82.10 Gaia Advanced Routing Administration Guide | 104


Restarting BGP Peers in Gaia Clish

Restarting BGP Peers in Gaia Clish


You can restart BGP peering without restarting the Gaia RouteD daemon.

Syntax

restart bgp
all
as <Number of Autonomous System>
peer <IP Address of Peer>

Parameters

Parameter Description

all Restarts BGP peering with all peers in all groups

as <Number of Autonomous Restarts BGP peering with all peers in the


System> specified group

peer <IP Address of Peer> Restarts BGP peering with the specified peer
Important:
n Restarting any part of a BGP protocol causes neighbor adjacencies to be torn
down and brought back up.
n The protocol's Graceful Restart mechanism does not take effect.
n Side effects of restarting a BGP instance include:
l Loss of BGP routes

l Traffic outage

l Network topology reconvergence

n In a ClusterXL or VRRP Cluster, restart of a BGP instance does not trigger a


failover.

R82.10 Gaia Advanced Routing Administration Guide | 105


Monitoring BGP in Gaia Clish

Monitoring BGP in Gaia Clish

Monitoring BGP
To see all available "show" commands for BGP, enter in Gaia Clish:

show bgp[Esc][Esc]

Troubleshooting BGP
See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 106


Support for IPv6 BGP (BGP-4 Multiprotocol Extensions)

Support for IPv6 BGP (BGP-4 Multiprotocol


Extensions)
Gaia implements BGP-4 with support for multiprotocol extensions and the exchange of IPv6
address prefixes, as described in RFCs 2545, 2858, and 3392.
You must use an IPv4 address for the router ID (BGP identifier). After the BGP session is up,
prefixes can be advertised and withdrawn by sending normal "UPDATE" messages that include
either or both of the new multiprotocol attributes "MP_REACH_NLRI" (used to advertise
reachability of routes) and "MP_UNREACH_NLRI" (used to withdraw routes).
The new attributes are backward compatible. If two routers have a BGP session and only one
supports the multiprotocol attributes, they can still exchange unicast IPv4 routes even though
they cannot exchange IPv6 routes.

Notes:
n ClusterXL (in Gateway and VSX mode) supports BGP IPv6 Link Local
peers.
n ClusterXL (in Gateway and VSX mode) supports BGP IPv6 Global Link
peers.

Configuring IPv6 BGP (BGP-4 Multiprotocol Extensions)


On each peer, configure the type of routes (Multiprotocol capability) to exchange between
peers.

Select one of these:


n IPv4 Unicast Only (this is the default)
n IPv6 Unicast Only
n Both IPv4 and IPv6
To establish BGP peering, the BGP routers must share a capability.
If your system is exchanging IPv4 routes over IPv6 (or IPv6 routes over IPv4), use the Gaia
Clish "routemap" commands to set nexthop to match the family of the routes being
exchanged. If they do not match, the routes cannot be active.

Note - To configure routing policies for BGP-4 Multiprotocol Extensions, use the Gaia
Clish "routemap" commands. Do not use the route redistribution and inbound filters
in Gaia Portal.

R82.10 Gaia Advanced Routing Administration Guide | 107


BGP Sessions (Internal and External)

BGP Sessions (Internal and External)


Introduction
BGP supports these session types between neighbors:
n Internal (iBGP) - Runs between routers in the same autonomous system.
n External (eBGP) - Runs between routers in different autonomous systems.
When you send routes to an external peer, the local AS number is prepended to the AS path.
Routes received from an internal neighbor have the same AS path that the route had when it
was received from an external peer.

BGP sessions might include a single metric (Multi-Exit Discriminator or MED) in the path
attributes. Smaller values are preferred. These values are used to break ties between routes
with equal preference from the same neighbor AS.
Internal BGP sessions carry at least one metric in the path attributes that BGP calls the local
preference. The size of the metric is identical to the MED. Use of these metrics depends on the
type of internal protocol processing.
For BGP implementation, external peers are directly attached to a shared subnet and
advertise next hops that are host addresses on the subnet. If you enable the multihop option in
the BGP peer template during configuration, this constraint is relaxed.
Internal groups determine the immediate next hops for routes. The next hop received with a
route from a peer is used as a forwarding address and to look up an immediate next hop in IGP
routes. Internal groups support distant peers, but need to know the IGP whose routes they are
using to determine immediate next hops.
Where possible, for internal BGP group types, a single outgoing message is built for all group
peers based on the common policy. A copy of the message is sent to every peer in the group,
with appropriate adjustments to the next hop field to each peer. This minimizes the
computational load needed to run large numbers of peers in these types of groups.

R82.10 Gaia Advanced Routing Administration Guide | 108


BGP Sessions (Internal and External)

Preventing Private AS Numbers from Propagating


An ISP can assign private AS numbers (64512 to 65535) to a customer in order to conserve
globally unique AS numbers. When an ISP does so, a BGP update from a customer network to
the ISP has the private AS number in its AS_PATH attribute. When the ISP propagates its
network information to other ISPs, the private AS number would normally be included. To
avoid this, you can configure Gaia to remove the private AS number from BGP update
messages to external peers.
To configure Gaia to remove private AS numbers from BGP updates, enable the Remove
Private AS option on the configuration page for an external peer.
If you enable this option, private AS numbers are removed from BGP updates according to the
following rules:
n If the AS_PATH includes both public and private AS numbers, the private AS numbers
are not removed.
n If the AS_PATH contains the AS number of the destination peer, private AS numbers are
not removed.
n If the AS_PATH includes confederations and all the AS numbers in the AS_PATH are
private, all the private AS numbers are removed.

BGP Route Refresh


Gaia supports the ability to dynamically request BGP route updates from peers and to respond
to requests for BGP route updates. For example, if you change the inbound routing policy, you
can request that a peer readvertise its previously advertised routes so that the routes can be
checked against the new policy. This feature is often referred to as a soft reset because it
provides the ability to refresh routes received from a peer without tearing down the established
session.

These options work only with peers that support the same capabilities.
Gaia systems can also peer with systems that do not support these options.
n To configure BGP route updates in Gaia Clish:

set bgp external remote-as <AS Number> peer <IP Address> send-
route-refresh
set bgp internal peer <IP Address> send-route-refresh
save config

n To configure BGP route updates Gaia Portal:


1. From the left navigation tree, click Advanced Routing > BGP.
2. In the Peer Groups section, select the applicable group and click Edit.

R82.10 Gaia Advanced Routing Administration Guide | 109


BGP Sessions (Internal and External)

3. In the Peers section, select the applicable peer and click Edit.
4. Click Shows Advanced Settings.
5. In the Route Refresh section, select the Route Refresh.
6. Click Save to close the Edit Peer window.
7. Click Save to close the Edit Peer Group window.

R82.10 Gaia Advanced Routing Administration Guide | 110


BGP Path Attributes

BGP Path Attributes


A path attribute is a list of AS numbers that a route has traversed to reach a destination. BGP
uses path attributes to provide more information about each route and to help prevent routing
loops in an arbitrary topology. You can also use path attributes to determine administrative
preferences.
BGP collapses routes with similar path attributes into a single update for advertisement.
Routes that are received in a single update are readvertised in a single update. The churn
caused by the loss of a neighbor is minimized, and the initial advertisement sent during peer
establishment is maximally compressed.
BGP does not read information that the kernel forms message by message. Instead, it fills the
input buffer. BGP processes all complete messages in the buffer before reading again. BGP
also performs multiple reads to clear all incoming data queued on the socket.

Note - This feature might cause a busy peer connection to block other protocols for
prolonged intervals.

Path attributes

Attribute Description

AS_PATH Identifies the autonomous systems through which routing information


carried in an UPDATE message passed. Components of this list can be
AS_SETs or AS_SEQUENCES.

NEXT_HOP Defines the IP address of the border router that should be used as the
next hop to the destinations listed in the UPDATE message.

MULTI_ Discriminates among multiple exit or entry points to the same neighboring
EXIT_DISC autonomous system. Used only on external links.

LOCAL_PREF Determines which external route should be taken and is included in all
iBGP UPDATE messages. The assigned BGP speaker sends this
message to BGP speakers within its own autonomous system but not to
neighboring autonomous systems. Higher values of a LOCAL_PREF are
preferred.

ATOMIC_ Specifies to a BGP speaker that a less specific route was chosen over a
AGGREGATE more specific route. The BGP speaker attaches the ATOMIC_AGGREGATE
attribute to the route when it reproduces it to other BGP speakers. The
BGP speaker that receives this route cannot remove the ATOMIC_
AGGREGATE attribute or make any Network Layer Reachability Information
(NLRI) of the route more specific. This attribute is used only for debugging
purposes.

R82.10 Gaia Advanced Routing Administration Guide | 111


BGP Path Attributes

All unreachable messages are collected into a single message and are sent before reachable
routes during a flash update. For these unreachable announcements, the next hop is set to the
local address on the connection, no metric is sent, and the path origin is set to incomplete. On
external connections, the AS path in unreachable announcements is set to the local AS. On
internal connections, the AS path length is set to zero.
Routing information shared between peers in BGP has two formats: announcements and
withdrawals. A route announcement indicates that a router either learned of a new network
attachment or made a policy decision to prefer another route to a network destination. Route
withdrawals are sent when a router makes a new local decision that a network is no longer
reachable.

R82.10 Gaia Advanced Routing Administration Guide | 112


BGP Multi-Exit Discriminator

BGP Multi-Exit Discriminator


Multi-exit Discriminator (MED) values are used to help external neighbors decide which of the
available entry points into an AS are preferred.
A lower MED value is preferred over a higher MED value and breaks the tie between two or
more preferred paths.

Note - A BGP session does not accept MEDs from an external peer unless the Accept
MED field is set for an external peer.

R82.10 Gaia Advanced Routing Administration Guide | 113


BGP Interactions with IGP

BGP Interactions with IGP


All transit ASs must be able to carry traffic that originates from locations outside of that AS, is
destined to locations outside of that AS, or both. This requires a certain degree of interaction
and coordination between BGP and the Interior Gateway Protocol (IGP) that the particular AS
uses. In general, traffic that originates outside of a given AS passes through both interior
gateway (that support the IGP only) and border gateway (that support both the IGP and BGP).
All interior gateway receive information about external routes from one or more of the border
gateway of the AS that uses the IGP.
Depending on the mechanism used to propagate BGP information within a given AS, take
special care to ensure consistency between BGP and the IGP, since changes in state are
likely to propagate at different rates across the AS. A time window might occur between the
moment when some border gateway "A" receives new BGP routing information (which was
originated from another border gateway "B" within the same AS) and the moment the IGP
within this AS can route transit traffic to the border gateway "B". During that time window,
either incorrect routing or black holes can occur.
To minimize such routing problems, border gateway "A" should not advertise to any of its
external peers a route to some set of exterior destinations associated with a given address
prefix using border gateway "B" until all the interior gateway within the AS are ready to route
traffic destined to these destinations by using the correct exit border gateway "B". Interior
routing should converge on the proper exit gateway before advertising routes that use the exit
gateway to external peers.
If all routers in an AS are BGP speakers, no interaction is necessary between BGP and an
IGP. In such cases, all routers in the AS already have full knowledge of all BGP routes. The
IGP is then only used for routing within the AS, and no BGP routes are imported into the IGP.
The user can perform a recursive lookup in the routing table. The first lookup uses a BGP route
to establish the exit router, while the second lookup determines the IGP path to the exit router.

R82.10 Gaia Advanced Routing Administration Guide | 114


BGP Inbound Route Filters

BGP Inbound Route Filters


BGP routes can be filtered, or redistributed by AS number or AS path regular expression, or
both.
BGP stores rejected routes in the routing table with a negative preference. A negative
preference prevents a route from becoming active and prevents it from being installed in the
forwarding table or being redistributed to other protocols. This behavior eliminates the need to
break and re-establish a session upon reconfiguration if importation policy is changed.
When you import from BGP you can add or modify the local preference, rank and nexthop. The
local preference parameter assigns a BGP local preference to the imported route. The local
preference is a 32-bit unsigned value, with greater values preferred. This is the preferred way
to bias a routing subsystem preference for BGP routes.

R82.10 Gaia Advanced Routing Administration Guide | 115


Redistributing Routes to BGP

Redistributing Routes to BGP


Redistributing to BGP is controlled by an AS.
The same policy is applied to all Firewalls in the AS. BGP metrics are 16-bit, unsigned
quantities; that is, they range from 0 to 65535 inclusive, with zero being the most attractive.
While BGP version 4 supports 32-bit unsigned quantities, routed does not.

Notes:
n To define a redistribution policy in Gaia Portal, go to Advanced Routing >
Route Redistribution.
n To define a redistribution policy in Gaia Clish, use the "set routemap"
commands. See sk100501.

R82.10 Gaia Advanced Routing Administration Guide | 116


BGP Communities

BGP Communities
BGP communities allow you to group a set of IP addresses and apply routing decisions based
on the identity of the group or community.
To implement this feature, map a set of communities to certain BGP local preference values.
Then you can apply a uniform BGP configuration to the community as a whole as opposed to
each router within the community. The routers in the community can capture routes that match
their community values.
Use community attributes to configure your BGP speaker to set, append, or modify the
community of a route that controls which routing information is accepted, preferred, or
distributed to other neighbors. The following table displays some special community attributes
that a BGP speaker can apply.

Community
Description
attribute

NO_EXPORT Not advertised outside a BGP confederation boundary.


(0xFFFFFF01) A Standalone autonomous system that is not part of a confederation
should be considered a confederation itself.

NO_ADVERTISE Not advertised to other BGP peers.


(0xFFFFFF02)

NO_EXPORT_ Not advertised to external BGP peers.


SUBCONFED This includes peers in other members' autonomous systems inside a
(0xFFFFFF03) BGP confederation.

For more about communities, see RFC 1997 and RFC 1998.

R82.10 Gaia Advanced Routing Administration Guide | 117


BGP Route Reflection

BGP Route Reflection


By default, all BGP peers in an Autonomous System (AS) are in a full mesh.
However, if an AS has many BGP peers, the BGP configuration and hardware deployment is
not easy.
To simplify configuration and deployment and avoid having to connect the peers in a full mesh,
it is possible to configure:
n One BGP peer as a route reflector.
n All or some of the other BGP peers as clients of the route reflector.
The route reflector and its clients are known as a route reflection cluster.

The route reflector sends the routes received from its peers to its clients.
In the example network below:
n AS1 has five Check Point routers with enabled BGP.
n One of the routers is a route reflector for two clients.

Item Description Item Description

1 Non-clients 5 AS1

2 iBGP 6 eBGP

3 Route Reflector in cluster 7 AS676

4 Clients in cluster

R82.10 Gaia Advanced Routing Administration Guide | 118


BGP Route Reflection

It is possible to define more than one route reflector in the AS to avoid having a single point of
failure.

Best Practice - We recommend that you not use multiple redundant reflectors
unnecessarily because it increases the memory required to keep routes on the peers
of redundant reflectors.

To learn more about route reflection, see RFC 2796.

R82.10 Gaia Advanced Routing Administration Guide | 119


BGP Confederations

BGP Confederations
An alternative to route reflection is BGP confederations. As with route reflectors, you can
partition BGP speakers into clusters where each cluster is typically a topologically close set of
routers. With confederations, this is accomplished by subdividing the autonomous system into
multiple, smaller ASs that communicate among themselves. The internal topology is hidden
from the outside world, which perceives the confederation to be one large AS.
Each distinct sub-AS within a confederation is referred to as a routing domain (RD). Routing
domains are identified by using a Routing Domain Identifier (RDI). The RDI has the same
syntax as an AS number, but as it is not visible outside of the confederation, it does not need to
be globally unique, although it does need to be unique within the confederation. Many
confederations find it convenient to select their RDIs from the reserved AS space (ASs 64512
through 65535 (see RFC 1930). RDIs are used as the ASs in BGP sessions between peers
within the confederation.
The confederation as a whole, is referred to by a confederation identifier. This identifier is used
as the AS in external BGP sessions. As far as the outside world is concerned, the
confederation ID is the AS number of the single, large AS. For this reason, the confederation
ID must be a globally unique, normally assigned AS number.

Note - Do not nest confederations.

For further details, refer to the confederations specification document RFC 1965.

R82.10 Gaia Advanced Routing Administration Guide | 120


External BGP (eBGP) Multihop Support

External BGP (eBGP) Multihop Support


Connections between BGP speakers of different ASs are referred to as External BGP (eBGP)
connections. BGP enforces the rule that peer routers for eBGP connections need to be on a
directly attached network. If the peer routers are multiple hops away from each other or if
multiple links are between them, you can override this restriction by enabling the eBGP
multihop feature. TCP connections between eBGP peers are tied to the addresses of the
outgoing interfaces. Therefore, a single interface failure severs the session even if a viable
path exists between the peers.
eBGP multihop support can provide redundancy so that an eBGP peer session persists even
in the event of an interface failure. Using an address assigned to the loopback interface for the
eBGP peering session ensures that the TCP connection stays up even if one of the links
between them is down, provided the peer loopback address is reachable. In addition, you can
use eBGP multihop support to balance the traffic among all links.
Use the TTL (Time to Live) parameter to limit the number of hops over which the External BGP
(eBGP) multihop session is established.
You can configure the TTL only if eBGP multihop is enabled.
The default TTL is 64. When multihop is disabled the default TTL is 1.
When traffic comes from a router that is not directly connected and multihop is enabled, BGP
uses that router as the next hop, irrespective of the advertised routes that it gets.

Important - Enabling multihop BGP connections is dangerous because BGP


speakers might establish a BGP connection through a third-party AS. This can violate
policy considerations and introduce forwarding loops.

R82.10 Gaia Advanced Routing Administration Guide | 121


BGP Route Dampening

BGP Route Dampening


Route dampening decreases the propagation of flapping routes. A flapping route is a route that
repeatedly becomes available and then unavailable. Without route dampening, autonomous
systems continually send advertisement and withdrawal messages each time the flapping
route becomes available or unavailable. As the Internet grew, the number of announcements
per second grew as well and caused performance problems within the routers.
Route dampening enables routers to keep a history of the flapping routes and prevent them
from consuming significant network bandwidth. The routers measure how often a given route
becomes available and then unavailable. When a route reaches a set threshold, that route is
no longer considered valid, and is no longer propagated for a given period of time, usually
about 30 minutes. If a route continues to flap even after it reaches the threshold, the time out
period for that route grows in proportion to each additional flap. Once the route reaches the
threshold, the route is dampened or suppressed. Suppressed routes are added back into the
routing table once the penalty value decreases and falls below the reuse threshold.
Route dampening can cause connectivity to look lost to the outside world but maintained on
your own network because route dampening only applies to BGP routes. Because of high load
on the backbone network routers, most NSPs (MCI, Sprint, UUNet etc.) have set up route
suppression.

Note - BGP route dampening is supported only for eBGP. It is not supported for iBGP.

R82.10 Gaia Advanced Routing Administration Guide | 122


TCP MD5 Authentication for BGP

TCP MD5 Authentication for BGP


The Internet is vulnerable to attack through its routing protocols and BGP is no exception.
External sources can disrupt communications between BGP peers by breaking their TCP
connection with spoofed RST packets.
Internal sources, such as BGP speakers, can inject bogus routing information from any other
legitimate BGP speaker.
Bogus information from either external or internal sources can affect routing behavior over a
wide area in the Internet.
The TCP MD5 option allows BGP to protect itself against the introduction of spoofed TCP
segments into the connection stream.
To spoof a connection using MD5 signed sessions, the attacker not only has to guess TCP
sequence numbers, but also the password included in the MD5 digest.

BGP Behavior During ClusterXL Failover


Overview
When Border Gateway Protocol (BGP) is configured on a Check Point cluster, the Cluster
Members establish the BGP session using the Cluster Virtual IP (VIP) addresses on the
cluster interfaces. The Cluster Members learn, import, and synchronize BGP routes.

During a cluster failover in the ClusterXL High Availability mode, the BGP session drops when
a Standby Cluster Member takes over the Cluster VIP addresses. As described in RFC 4271,
this triggers the deletion of all BGP routes learned from a BGP peer, from both the Active and
Standby Cluster Members. The new Active Cluster Member re-learns the BGP routes after it
re-establishes the BGP sessions.
A service interruption occurs because BGP negotiations usually take 10-60 seconds to
complete.

Required Configuration
To prevent BGP interruption during a cluster failover, you must:
1. Enable the BGP Graceful Restart in the BGP configuration on each Cluster Member.
2. Enable the BGP Graceful Restart in the BGP configuration on the BGP peers.
Graceful Restart is a mechanism which keeps deleted BGP routes in the routing table as
kernel routes until a timer expires (default is 360 seconds).
For more information about Graceful Restart, see:

R82.10 Gaia Advanced Routing Administration Guide | 123


TCP MD5 Authentication for BGP

n "Configuring BGP Miscellaneous Settings in Gaia Portal" on page 50


n "Configuring BGP Remote Peers in Gaia Clish" on page 81
To enable BGP Graceful Restart, enter these Gaia Clish commands on each Check Point
Cluster Member:
1. set bgp external remote-as <AS Number> peer <IP Address>
graceful-restart on
2. save config

Important:
n You must create a matching configuration on the BGP peers of the Check Point
cluster.
Test this configuration properly to make sure it works properly.
n The Graceful Restart process is initiated for all BGP peers during a cluster
failover and concludes upon receiving an End-of-Routing Information Base
(RIB) from each BGP peer.
n To ensure proper configuration of Graceful Restart, it is essential to enable it for
all BGP peers and to confirm that the Graceful Restart Helper is configured on
all remote BGP peers.
n Incomplete configuration, where the Graceful Restart Helper is set up on some
but not all BGP peers, results in the Graceful Restart process not functioning as
intended, potentially leading to BGP service outages.

Additional Configuration
You can use Continuous Built-In Test (cBIT) detection with the BGP Graceful Restart. See
RFC-5882 > section-3.1.

If you use Bidirectional Forwarding Detection (BFD), then you must enable the BGP control
plane detection failure. See "IP Reachability Detection" on page 243.
For Graceful Restart to work with BFD without an outage, the Graceful Restart Helper must
have the "cBit" detection and the cBit value must be set to 0 (depends on the control plane) by
the cluster.

To configure the BGP peers to use Bidirectional Forwarding Detection (BFD) with cBIT
detection:
In this configuration, the Standby Cluster Member keeps learned routes in its routing table.
This way, there is no traffic interruption when the BGP session is re-established.
Run these Gaia Clish commands on each Cluster Member:

R82.10 Gaia Advanced Routing Administration Guide | 124


TCP MD5 Authentication for BGP

1. set bgp external remote-as <AS Number> peer <IP Address> ip-
reachability-detection onset bgp external remote-as <AS
Number> peer <IP Address> ip-reachability-detection on
2. set bgp external remote-as <AS Number> peer <IP Address> ip-
reachability-detection check-control-plane-failure on
3. save config

Important - You must create a matching configuration on the BGP peers of the Check
Point cluster. Check Point strongly recommendd to fully test this configuration to
make sure it works properly. Some BGP peer routers can support BFD but not include
cBIT detection in BGP. Refer to the relevant vendor's documentation.

R82.10 Gaia Advanced Routing Administration Guide | 125


IGMP

IGMP
Introduction
Internet Group Management Protocol (IGMP) allows hosts on multiaccess networks to inform
locally attached routers of their group membership information. Hosts share their group
membership information by multicasting IGMP host membership reports. Multicast routers
listen for these host membership reports, and then exchange this information with other
multicast routers.
The group membership reporting protocol includes two types of messages: host membership
query and host membership report. IGMP messages are encapsulated in IP datagrams, with
an IP protocol number of 2. Protocol operation requires that a designated querier router be
elected on each subnet and that it periodically multicast a host membership query to the all-
hosts group.
Hosts respond to a query by generating host membership reports for each multicast group to
which they belong. These reports are sent to the group being reported, which allows other
active members on the subnet to cancel their reports. This behavior limits the number of
reports generated to one for each active group on the subnet. This exchange allows the
multicast routers to maintain a database of all active host groups on each of their attached
subnets. A group is declared inactive (expired) when no report is received for several query
intervals.
The IGMPv2 protocol adds a leave group message and uses an unused field in the IGMPv1
host membership query message to specify a maximum response time. The leave group
message allows a host to report when its membership in a multicast group terminates. Then,
the IGMP querier router can send a group-directed query with a very small maximum response
time to probe for any remaining active group members. This accelerated leave extension can
reduce the time required to expire a group and prune the multicast distribution tree from
minutes, down to several seconds
The unicast traceroute program allows the tracing of a path from one device to another, using
mechanisms that already exist in IP. Unfortunately, you cannot apply such mechanisms to IP
multicast packets. The key mechanism for unicast traceroute is the ICMP TTL exceeded
message that is specifically precluded as a response to multicast packets. The traceroute
facility implemented within routed conforms to the traceroute facility for IP multicast draft
specification.
Gaia supports IGMPv1, IGMPv2 (runs by default), and IGMPv3.

R82.10 Gaia Advanced Routing Administration Guide | 126


IGMP

IGMPv3
Gaia provides IGMP version 3 source filtering to support source-specific multicast (SSM),
which enables the Gaia system to request traffic from specific sources via PIM join/prune
messages without requiring the presence of a rendezvous point (RP). This enables the Gaia
system to forward traffic from only those sources from which receivers requested traffic.
IGMPv3 supports applications that explicitly signal sources, from which they want to receive
traffic.
With IGMP version 3, receivers (hosts) identify their membership to a multicast group in the
following two modes:
n Include mode: Receivers announce membership to a group and provide a list of IP
addresses (the include list) from which they want to receive traffic.
n Exclude mode: Receivers announce membership to a host group and provide a list of IP
addresses (the exclude list) from which they do not want to receive traffic. To receive
traffic from all sources, a host sends an empty exclude list.
The multicast group address range 232/8 ([Link] to [Link]) is reserved for use
by SSM protocols and applications. The DRs of senders do not send register packets to any
RPs in the SSM group range.
When SSM is enabled, all other multicast groups are treated as in normal sparse-mode.

Configuring Local and Static IGMP Groups


You can facilitate multicast routing by creating IGMP local and static groups. You create these
groups on a per-interface basis, and for each group you specify an address for a multicast
group. Gaia then acts as a receiver for that multicast group and builds a routing tree to the
source regardless of whether there are any hosts on the downstream LAN that want to receive
traffic for that group. When hosts later join the multicast group, they start receiving traffic
sooner because the routing tree is already built.
This feature is useful in any situation in which multicast receivers might not be permanently
attached to the downstream LAN. For example, if you have laptop users who regularly detach
from the LAN and reattach when they return to work and who also want to receive multicast
traffic from a known source when their laptop is connected to the LAN, you can create a local
or static group using the multicast address of the known source. Gaia then maintains the
reverse path forwarding tree without waiting for requests from the laptops.
The differences between local and static groups are:

R82.10 Gaia Advanced Routing Administration Guide | 127


IGMP

n When you create a local group:


l IGMP sends a membership report out of the appropriate interface.
l If the system is running a parent multicast routing protocol, IGMP informs the
parent protocol about the simulated local receiver.
n When you create a static group:
l IGMP does not send a membership report for the group. You might want to use
static groups if you do not want other devices to receive IGMP membership reports
from your Gaia system.
l If the system is running a parent multicast routing protocol, IGMP informs the
parent protocol about the simulated local receiver.

R82.10 Gaia Advanced Routing Administration Guide | 128


Configuring IGMP in Gaia Portal

Configuring IGMP in Gaia Portal


Important:
n In a Cluster, you must configure all the Cluster Members in the same way.
n IGMP functions only in conjunction with a multicast routing protocol to calculate
a multicast distribution tree. For more information, see "PIM" on page 155.

IGMP is enabled by default.


1. Configure a multicast routing protocol, such as PIM.
IGMP functions only in conjunction with a multicast routing protocol to calculate a
multicast distribution tree.

IGMP supports IP multicast groups on a network.


For more information, see "PIM" on page 155.
2. From the left navigation tree, click Advanced Routing > IGMP.
3. For each interface, on which you enabled a multicast routing protocol:
a. Select the interface and click Edit.
b. Configure the IGMP interface parameters.
All parameters are optional.

R82.10 Gaia Advanced Routing Administration Guide | 129


Configuring IGMP in Gaia Portal

IGMP interface parameters

Parameter Description

Version The version of the IGMP protocol.


Notes:
n IGMP version 2 is compatible with IGMP version

1.
n IGMP version 3 is compatible with versions 2 and

1.
n You must select the IGMP version 3 and click

Save before you configure allowed Source-


Specific Multicast (SSM) sources for a Static
IGMP Group.
Best Practice - Use IGMP version 1 only on networks
that include multicast routers that do not support IGMP
versions 2 or 3.
IGMP version 3 is used to support source-specific multicast
(SSM). IGMPversion 3 membership reports are used to
request or block multicast traffic from specific sources.
For example, when a host requests traffic for a multicast
group from a specific source, SSM sends PIM join/prune
messages towards the source.
The multicast group address [Link]/8 is reserved for use
with SSM.
Range: 1-3
Default: 2

Loss Allows tuning for the expected packet loss on a subnet.


Robustness If the subnet is expected to be highly lossy, then the "loss
robustness" value may be increased.
IGMP protocol operation is robust to (loss robustness - 1)
packet loss.
Range: 1-255
Default: 2

Query Interval The interval (in seconds) between IGMP general queries
sent by the querier router.
This parameter can be used to tune the IGMP messaging
overhead and has a secondary effect on the timeout of idle
IP multicast groups.
Range: 1-3600
Default: 125

R82.10 Gaia Advanced Routing Administration Guide | 130


Configuring IGMP in Gaia Portal

Parameter Description

Query The maximum response time (in seconds) inserted into the
Response periodic IGMP general queries.
Interval The query response interval may be used to tune the
burstiness of IGMP messages.
A greater value spreads the host IGMP reports over a
greater interval, reducing burstiness.
This value must always be less than the query interval.
Range: 1-25
Default: 10

Last Member The maximum response time (in seconds) inserted into
Query Interval IGMP group-specific queries.
The last member query interval may be used to tune the
"leave latency".
A smaller value results in a reduction in the time to detect
the loss of the last member of a multicast group.
This value must always be less than the query interval.
Range: 1-25
Default: 1

Router Alert Allows the "disable insertion of IP router alert" option in all
IGMP messages sent on the interface.
This can be useful in interoperating with broken IP
implementations that may discard the packet due to the use
of this option.
Options: Enabled, or Disabled
Default: Enabled

c. Optional: Add a Multicast Group.


n In the Static Groups section, add a static Multicast group and click OK.
n In the Local Groups section, add a local network Multicast Group and click
OK.
Multicast Group parameters

Parameter Description

Multicast The multicast address of the group.


Address

R82.10 Gaia Advanced Routing Administration Guide | 131


Configuring IGMP in Gaia Portal

Parameter Description

Group Count This field appears if in the Group Type field you selected
Static Group.
Specifies the number of adjacent groups to subscribe to.
Range: 1-512
Default: 1

Add SSM Adds an allowed Source-Specific Multicast (SSM) Source.


Source The IGMP group accepts traffic only from this IGMP source.
i. In the Source Address field, enter the multicast source
IPv4 address
ii. In the Source Count field, enter the number of adjacent
sources from 1 to 512
iii. In the Source increment field, enter the increment (this
field appears if in the Source Count field you enter a
value other than the default 1)
Important - The IPv4 address of the multicast group
must be from the SSM multicast range 232.X.X.X

Group Type n Static Group


Provides a mechanism to simulate the presence of local
receivers on an interface.
When a static group is configured on an interface that is
also running a parent multicast protocol (such as PIM)
IGMP informs the parent of the presence of a local
receiver.
In contrast to regular IGMP, no membership reports are
sent on the corresponding interface.
n Local Group

Provides a mechanism to simulate the presence of local


receivers for specific groups.
When a multicast group is added to an interface, IGMP
sends a membership report on the interface.
Important - If the same multicast group is configured as
both a local and a static group, local group takes
precedence, that is, membership reports are sent out on
the interface.

d. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 132


Configuring IGMP in Gaia Clish

Configuring IGMP in Gaia Clish


Important:
n In a Cluster, you must configure all the Cluster Members in the same way.
n IGMP functions only in conjunction with a multicast routing protocol to calculate
a multicast distribution tree. For more information, see "PIM" on page 155.
n To see the available "set" commands for IGMP, enter in Gaia Clish:

set igmp[Esc][Esc]

n To see the available "show" commands for IGMP, enter in Gaia Clish:

show igmp[Esc][Esc]

Syntax

set igmp interface <Name of Interface>


default
last-member-query-interval {<1-25> | default}
local-group <Multicast Group IP Address> {off | on}
loss-robustness {<1-255> | default}
query-interval {<1-3600> | default}
query-response-interval {<1-25> | default}
router-alert {off | on}
static-group <Multicast Group IP Address>
group-count <1-512> group-increment {<Set of 4 Octets>
| default} {off | on}
source <SSM Source IP Address> {off | on}
[source-count <1-512> source-increment {<Set of
4 Octets> | default} {off | on}]
source-all-off
{off | on}
version {1 | 2 | 3}

Parameters

Parameter Description

interface <Name of The interface, on which IGMP should be configured.


Interface>

default Reset IGMP settings to defaults for the specified interface.

R82.10 Gaia Advanced Routing Administration Guide | 133


Configuring IGMP in Gaia Clish

Parameter Description

last-member-query- This parameter applies only to IGMP versions 2 and


interval {<1-25> | newer.
default} When an IGMP router receives a "Leave Group" message,
the router issues a membership query to determine if any
hosts remain that still desire multicast data for the given
group.
The query message is repeated a number of times, at an
interval which is determined by this parameter (in
seconds).
If no responses are received, then multicast routing for this
group stops.
This parameter defines the maximum response time
inserted into IGMP group-specific queries.
A smaller value results in a reduction in the time to detect
the loss of the last member of a multicast group.
Important - This value must be less than the
configured Query Interval.
Default: 1

local-group <Multicast A multicast group address.


Group IP Address> {off A local group provides a mechanism to simulate the
| on} presence of local receivers for specific groups.
When a multicast group is added to an interface, IGMP
sends a membership report on the interface.

loss-robustness {<1- Expected packet loss on a subnet.


255> | default} If you expect the subnet to be highly lossy, then you can
increase the "loss robustness" value.
IGMP protocol operation is robust to ("value of loss
robustness" - 1) packet loss.
Default: 2

query-interval {<1- The interval (in seconds) between IGMP general queries
3600> | default} which the querier router sends.
You can use this parameter to tune the IGMP messaging
overhead and has a secondary effect on the timeout of idle
IP multicast groups.
Default: 125

R82.10 Gaia Advanced Routing Administration Guide | 134


Configuring IGMP in Gaia Clish

Parameter Description

query-response- The maximum response time (in seconds) inserted into the
interval }<1-25> | periodic IGMP general queries.
default{ You can use the query response interval to tune the
burstiness of IGMP messages; a greater value spreads the
host IGMP reports over a greater interval, which reduces
burstiness.
Important - This value must always be less than the
configured Query Interval.
Default: 10

router-alert {off | Lets you disable the insertion of IP router alert in all IGMP
on} messages sent on the interface. This can be useful with
broken IP implementations that may discard the packet
because of the use of this option.
Default: off

static-group address A multicast group address.


{off | on} A static group provides a mechanism to simulate the
presence of local receivers on an interface.
When a static group is configured on an interface that also
runs a parent multicast protocol (such as PIM), IGMP
informs the parent of the presence of a local receiver.
In contrast to regular IGMP, no membership reports are
sent on the corresponding interface.
Important - If the same multicast group is configured
as both a local and a static group, local group takes
precedence, that is, membership reports are sent out
on the interface.

group-count <1-512> Number of adjacent groups, to which this interface


subscribes.

R82.10 Gaia Advanced Routing Administration Guide | 135


Configuring IGMP in Gaia Clish

Parameter Description

group-increment {<Set Controls the increment between groups.


of 4 Octets> | Static group configuration provides a mechanism to
default} simulate the presence of local receivers on the interface.
When a static group is configured on an interface, the
parent protocol (e.g. PIM) is notified of the presence of a
local receiver.
Local groups and static groups are similar in behavior.
The difference is that IGMP membership reports are not
sent for static groups.
If the same multicast group is configured as both a local
and a static group, the local group takes precedence.
In other words, membership reports are sent out the
interface for that group when it is configured as a local
group, regardless of static group configuration.

source <SSM Source IP Specifies an allowed Source-Specific Multicast (SSM)


Address> {off | on} Source.
The IGMP group accepts traffic only from this IGMP
source.
Important - The IPv4 address of the multicast group
must be from the SSM multicast range 232.X.X.X

source-count <1-512> Specifies:


source-increment {<Set
of 4 Octets> |
n The number of the adjacent IGMP sources.
default} {off | on}
n The increment between the adjacent IGMP sources.

source-all-off Disables all source-specific behavior for this IGMP group.


The IGMP group accepts traffic from all IGMP sources.

version {1 | 2 | 3} IGMP version 2 is compatible with IGMP version 1.


IGMP version 3 is compatible with versions 2 and 1.
Best Practice - Use IGMP version 1 only on networks
that include multicast routers that do not support
IGMP versions 2 or 3

R82.10 Gaia Advanced Routing Administration Guide | 136


Monitoring IGMP

Monitoring IGMP
Monitoring IGMP in Gaia Portal
1. From the left navigation tree, click Advanced Routing > IGMP.
2. In the top right corner, click Monitoring.
3. In the IGMP Monitor section, click on the Information category.

Note - The page is static. To see the latest values, click Refresh.

Monitoring IGMP in Gaia Clish


To see the available "show" commands for IGMP, enter in Gaia Clish:

show igmp[Esc][Esc]

Troubleshooting IGMP
See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 137


Multicast Listener Discovery (MLD)

Multicast Listener Discovery (MLD)


Multicast Listener Discovery (MLD) allows each IPv6 router to discover the presence of
multicast listeners on its directly attached links, and to discover specifically which multicast
addresses are of interest to those neighboring nodes.
MLD in IPv6 is similar to IGMP in IPv4.
MLD is needed to support IPv6 PIM and IPv6 multicast.
The role of MLD is to find out for which groups the routee is listening on each directly
connected network.
In MLD, one router on each network is elected as the querier and sends MLD query packets, to
which listeners respond. These responses tell all routers on the network what multicast groups
may have listeners on the network. An MLD router implementation passes the information it
gets to some multicast routing protocol such as IPv6 PIM.
For more infromation, see RFC 3810.

Configuring MLD in Gaia Portal


Multicast Listener Discovery (MLD) allows each IPv6 router to discover the presence of
multicast listeners on its directly attached links, and to discover specifically which multicast
addresses are of interest to those neighboring nodes.
MLD in IPv6 is similar to IGMP in IPv4.

Important:
n In a Cluster, you must configure all the Cluster Members in the same way.
n MLD functions only in conjunction with a multicast routing protocol to calculate a
multicast distribution tree.
Configure "IPv6 PIM" on page 185.

1. From the left navigation tree, click Advanced Routing > MLD.
2. In the MLD Interfaces section, select the applicable interface and click Edit.
3. In the top section, configure the applicable values:

R82.10 Gaia Advanced Routing Administration Guide | 138


Multicast Listener Discovery (MLD)

Parameter Description

Version Configures the MLD protocol version.


Range: v1, or v2
Default: v1
Note - If you selected the value v2, then:
a. Click Save at the bottom.
b. Click Edit again.
c. Configure other applicable MLD parameters.

Loss Configures the loss robustness - the expected number of packet


Robustness losses on a link.
If the link is expected to be lossy, you can increase this value.
MLD is robust to this level of packet losses: "Loss Robustness - 1".
Range: 2-7 packets
Default: 2 packets

Startup Query Configures the number of MLD queries sent out on startup, sent with
Count the intervals as configured in the parameter "startup-query-
interval".
Range: 1-255
Default: The value of the parameter "Loss Robustness"

Last Listener Configures the last listener query count.


Query Count This is the number of Multicast-Address-Specific Queries sent
before the router assumes there are no remaining listeners for an
address on a link.
Range: 1-255
Default: The value of the parameter "Loss Robustness"

Query Interval Configures the interface MLD query interval.


This is the interval between General Queries sent by the Querier.
Larger values cause MLD Queries to be sent less often.
Range: 1-360 seconds
Default: 125 seconds

Query Configures the maximum delay for hosts to respond to an MLD


Response membership query.
Interval Range: 1-25 seconds
Default: 10 seconds

R82.10 Gaia Advanced Routing Administration Guide | 139


Multicast Listener Discovery (MLD)

Parameter Description

Last Listener Configures the last listener query interval.


Query Interval This nterval controls:
n The Maximum Response Delay inserted into Multicast-

Address-Specific Queries sent in response to the "Done"


messages.
n The time between Multicast-Address-Specific Query

messages.
You can change this value to fine-tune the "leave latency" of the link.
A reduced value results in reduced time to detect the departure of
the last listener for an address.
Range: 1-25 seconds
Default: 1 second

Startup Query Configures the interval between General Queries sent by a Querier
Interval upon startup.
Range: 1-31744 seconds
Default: The value of the parmeter "Query Interval" divided by 4
(and rounded up)

4. In the Static Groups section, configure the applicable static multicast groups.
These settings configure the local membership for a multicast group.
Static group configuration provides a mechanism to simulate the presence of local
receivers on the interface.

When a static group is configured on an interface, the parent protocol (for example, PIM)
is notified of the presence of a local receiver.

a. Click Add.
b. In the Multicast Address field, enter the IPv6 address of the static multicast group.
c. Optional: In the Group Count field, enter the number of adjacent static multicast
groups, for which to enable the static membership at the same time.
Range: 1-512
Default: 1
d. Optional: In the Group Increment field, enter the IPv6 increment address between
adjacent static multicast groups.
Range: None
Default: ::1

R82.10 Gaia Advanced Routing Administration Guide | 140


Multicast Listener Discovery (MLD)

e. Optional: Click Add SSM Source to configure the sources, from which to receive
traffic for this group.

Notes:
n This parameter is supported only for the MLD version 2.

To make this button available, you must save the current settings
while the field Version contains the value v2.
n Source-specific joins will only forward traffic that arrives from

specific sources, and was sent to the specified multicast group.

i. In the Source Address field, enter the applicable multicast IPv6 address.
Default: None
ii. Optional: In the Source Count field, enter the number of adjacent static
multicast sources, for which to enable the local membership at the same
time.
Range: 1-512
Default: 1
iii. Optional: In the Source Increment field, enter the applicable unicast IPv6
address to increment between adjacent static multicast sources.
This field appears if in the Source Count field, you configured the value of 2
or greater.
Default: ::1
f. Click OK.

5. In the Local Groups section, configure the applicable local multicast groups.
These settings configure the interface to be a receiver of multicast data for the given
address.
Local group configuration provides a mechanism to simulate the presence of local
receivers on the interface.
When a local group is added, MLD sends a membership report for the group on the
interface.
a. Click Add.
b. In the Multicast Address field, enter the IPv6 address of the local multicast group.
c. Click OK.
6. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 141


Multicast Listener Discovery (MLD)

Configuring MLD in Gaia Clish


Important:
n In a Cluster, you must configure all the Cluster Members in the same way.
n MLD functions only in conjunction with a multicast routing protocol to calculate a
multicast distribution tree.
Configure "IPv6 PIM" on page 185.
n To see the available "set" commands for MLD, enter in Gaia Clish:

set ipv6 mld[Esc][Esc]

n To see the available "show" commands for MLD, enter in Gaia Clish:

show ipv6 mld[Esc][Esc]

See "Monitoring and Troubleshooting MLD" on page 147.

Workflow:
1. If necessary to use the MLD version 2, then configure it on the required interface.
2. Configure other applicable MLD settings.

R82.10 Gaia Advanced Routing Administration Guide | 142


Multicast Listener Discovery (MLD)

Syntax for configuring MLD

set ipv6 mld interface <Name of Interface>


default
last-listener-query-count {<1-255> | default}
last-listener-query-interval {<1-25> | default}
local-group <IPv6 Multicast Address> {on | off}
loss-robustness {<2-7> | default}
query-interval {<1-3600> | default}
query-response-interval {<1-25> | default}
startup-query-count {<1-255> | default}
startup-query-interval {<1-31744> | default}
static-group <IPv6 Multicast Address>
group-count <1-512> group-increment <IPv6 Unicast
Address> {on | off}
{on | off}
source <IPv6 Address>
{on | off}
source-count <1-512> source-increment <IPv6
Unicast Address> {on | off}
source-all-off
version {1 | 2}

Parameters for configuring MLD

Parameter Description

<Name of Interface> Specifies the interface that listens for MLD protocol
messages.

default Resets the MLD settings to default values.

last-listener-query- Configures the last listener query count.


count {<1-255> | This is the number of Multicast-Address-Specific Queries
default} sent before the router assumes there are no remaining
listeners for an address on a link.
Range: 1-255
Default: The value of the parameter "loss-
robustness"

R82.10 Gaia Advanced Routing Administration Guide | 143


Multicast Listener Discovery (MLD)

Parameter Description

last-listener-query- Configures the last listener query interval.


interval {<1-25> | This nterval controls:
default}
n The Maximum Response Delay inserted into
Multicast-Address-Specific Queries sent in
response to the "Done" messages.
n The time between Multicast-Address-Specific
Query messages.
You can change this value to fine-tune the "leave
latency" of the link.
A reduced value results in reduced time to detect the
departure of the last listener for an address.
Range: 1-25 seconds
Default: 1 second

local-group <IPv6 Configures the interface to be a receiver of multicast data


Multicast Address> {on for the given address.
| off} Local group configuration provides a mechanism to
simulate the presence of local receivers on the interface.
When a local group is added, MLD sends a membership
report for the group on the interface.

loss-robustness {<2-7> Configures the loss robustness - the expected number of


| default} packet losses on a link.
If the link is expected to be lossy, you can increase this
value.
MLD is robust to this level of packet losses: "loss-
robustness value" - 1.
Range: 2-7 packets
Default: 2 packets

query-interval {<1- Configures the interface MLD query interval.


3600> | default} This is the interval between General Queries sent by the
Querier.
Larger values cause MLD Queries to be sent less often.
Range: 1-360 seconds
Default: 125 seconds

query-response-interval Configures the maximum delay for hosts to respond to an


{<1-25> | default} MLD membership query.
Range: 1-25 seconds
Default: 10 seconds

R82.10 Gaia Advanced Routing Administration Guide | 144


Multicast Listener Discovery (MLD)

Parameter Description

startup-query-count Configures the number of MLD queries sent out on


{<1-255> | default} startup, sent with the intervals as configured in the
parameter "startup-query-interval".
Range: 1-255
Default: The value of the parameter "loss-
robustness"

startup-query-interval Configures the interval between General Queries sent by


{<1-31744> | default} a Querier upon startup.
Range: 1-31744 seconds
Default: The value of the parmeter "query-interval"
divided by 4 (and rounded up)

static-group <IPv6 Configures the local membership for a multicast group.


Multicast Address> {on Static group configuration provides a mechanism to
| off} simulate the presence of local receivers on the interface.
When a static group is configured on an interface, the
parent protocol (for example, PIM) is notified of the
presence of a local receiver.

group-count <1-512> n group-count


group-increment <IPv6 Enables static membership for a set of N adjacent
Unicast Address> {on | groups at the same time.
off} Range: 1-512
Default: 1
n group-increment
Controls the increment between groups.
Range: None
Default: ::1

source <IPv6 Multicast Configures the multicast sources from which to receive
Address> {on | off} traffic for this group.
Notes:
n This parameter is supported only for the MLD
version 2.
To configure this parameter, you must first
enable the MLD version 2 on the specific
interface.
n Source-specific joins will only forward traffic
that arrives from specific sources, and was
sent to the specified multicast group.

R82.10 Gaia Advanced Routing Administration Guide | 145


Multicast Listener Discovery (MLD)

Parameter Description

source-count <1-512> n source-count


source-increment <IPv6 Enables static membership for a set of N adjacent
Unicast Address> {on | sources at the same time.
off} Range: 1-512
Default: 1
n source-increment
Controls the increment between sources.
Range: None
Default: ::1

source-all-off Disables all source-specific configuration for the


specified multicast group and returns to default
behaviour of forwarding all traffic for this multicast group
onto this interface.

version {1 | 2} Configures the MLD protocol version.


Range: 1, or 2
Default: 1

R82.10 Gaia Advanced Routing Administration Guide | 146


Monitoring and Troubleshooting MLD

Monitoring and Troubleshooting MLD


Monitoring MLD in Gaia Portal
1. From the left navigation tree, click Advanced Routing > MLD.
2. In the top right corner, click Monitoring.
3. In the MLD Monitor section, click the Information category.

Note - The page is static. To see the latest values, click Reload.

Monitoring MLD in Gaia Clish

Syntax for monitoring MLD

show ipv6 mld


groups
interface <Name of Interface>
[local]
[static]
[local]
[static]
if-stat <Name of Interface>
if-stats
interface <Name of Interface>
interfaces
stats
[error]
[receive]
[transmit]
summary

Parameters for monitoring MLD

Parameter Description

<Name of Interface> Specifies the interface that listens for MLD


protocol messages.

groups Shows all MLD groups for all interfaces.

R82.10 Gaia Advanced Routing Administration Guide | 147


Monitoring and Troubleshooting MLD

Parameter Description

groups interface <Name of Shows all MLD groups for the specified interface.
Interface>

local Shows only locally joined multicast groups.

static Shows only statically configured multicast


groups.

if-stat <Name of Interface> Shows the MLD packet statistics for the specified
interface.

if-stats Shows the MLD packet statistics for all interfaces.

interface <Name of Shows the MLD state information for the specified
Interface> interface.

interfaces Shows the MLD state information for all


interfaces.

stats Shows the MLD packet statistics -


Receive Summary, Transmit Summary, and Error
Summary.
n error - Only errors
n receive - Only received packets
n transmit - Only transmitted packets

summary Shows the MLD state summary.

Troubleshooting MLD
See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 148


IP Broadcast Helper

IP Broadcast Helper
UDP broadcasts stop at the edge of the local network. This can be a problem under some
circumstances.
For example, if a server is relocated to a different network, but it needs to receive UDP
broadcasts from clients, which are not being relocated.
IP Broadcast Helper can solve this problem by forwarding UDP broadcasts to a list of
destination IPv4 addresses.
IP Broadcast Helper is a form of static addressing that uses directed broadcasts to forward
local and all-nets broadcasts to desired destinations within the internetwork.

Note - For more information, see RFC 1542 > Section 4.

R82.10 Gaia Advanced Routing Administration Guide | 149


Configuring IP Broadcast Helper in Gaia Portal

Configuring IP Broadcast Helper in Gaia Portal


Important - In a Cluster, you must configure all the Cluster Members in the same way.

1. From the left navigation tree, click Advanced Routing > IP Broadcast Helper.
2. In the IP Broadcast Helper section, the Forward Non-local Packets option controls
whether packets are forwarded that are not locally originated by a source directly on the
receiving interface.
n Select this option to forward packets, even if the source is not directly on the
receiving interface. Click Apply.
n Clear this option (this is the default) to require that packets are generated by a
source that is directly on the receiving interface to be eligible for relay. Click Apply.
3. In the Configure Relays section, configure the interface, on which the IP helper service
runs.
a. Click Add.
b. In the Interface field, select the applicable interface.
c. In the UDP Port field, enter the number of the UDP port in the client UDP packets
that should be forwarded by the interface to the relay destination.

Important - You cannot use ports 67 and 68 that are reserved for DHCP
Relay.

Range: 1-65535
d. In the Relay field, enter the IPv4 unicast address (x.x.x.x) or IPv4 broadcast
address ([Link]), to which the interface forwards the client UDP
packets.
You can configure more than one relay IPv4 address.

Important:
n The IPv4 address specified must not be an address belonging to the

local machine.
n Packets are not forwarded to any destination IP address that uses

the same interface as the incoming UDP broadcast.

e. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 150


Configuring IP Broadcast Helper in Gaia Clish

Configuring IP Broadcast Helper in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

n To see the available "set" commands for IP Broadcast Helper, enter in Gaia Clish:

set iphelper[Esc][Esc]

n To see the available "show" commands for IP Broadcast Helper, enter in Gaia Clish:

show iphelper[Esc][Esc]

Syntax

set iphelper
forward-nonlocal {off | on}
interface <Name of Interface>
off
udp-port <1-65535>
off
relay-to <IP Address> {off | on}

R82.10 Gaia Advanced Routing Administration Guide | 151


Configuring IP Broadcast Helper in Gaia Clish

Parameters

Parameter Description

forward-nonlocal Controls whether packets are forwarded that are not locally
{off | on} originated by a source directly on the receiving interface.
n Enable (on) this option to forward packets, even if the
source is not directly on the receiving interface.
n Disable (off) this option (this is the default) to require
that packets are generated by a source that is directly on
the receiving interface to be eligible for relay.

<Name of Specifies the interface, on which the IP helper service runs.


Interface>

interface <Name Disables the IP Broadcast Helper on the specified interface.


of Interface> off

udp-port <1- Specifies the number of the UDP port in the client UDP
65535> packets that should be forwarded by the interface to the relay
destination
Important - You cannot use ports 67 and 68 that are
reserved for DHCP Relay.

udp-port <1- Disables the UDP port configured on this interface.


65535> off

relay-to Specifies the IPv4 unicast address (x.x.x.x) or IPv4 broadcast


<Destination IPv4 address ([Link]), to which the interface forwards
Address> {off | the client UDP packets.
on} You can configure more than one relay IPv4 address.
Important:
n The IPv4 address specified must not be an address
belonging to the local machine.
n Packets are not forwarded to any destination IP
address that uses the same interface as the
incoming UDP broadcast.

R82.10 Gaia Advanced Routing Administration Guide | 152


Configuring IP Broadcast Helper in Gaia Clish

Procedure

1. Connect to the command line.


2. Log in to Gaia Clish.
3. Configure the Forward Non-local Packets option.
n Enable this option to forward packets, even if the source is not directly on the
receiving interface.

set iphelper forward-nonlocal on

n Disable this option (this is the default) to require that packets are generated by a
source that is directly on the receiving interface to be eligible for relay.

set iphelper forward-nonlocal off

4. Configure the interface, the UDP port in client packets, and the destination IPv4
address:

set iphelper interface <Name of Interface> udp-port <1-


65535> relay-to <Destination IPv4 Address> on

5. Save the configuration:

save config

R82.10 Gaia Advanced Routing Administration Guide | 153


Monitoring IP Broadcast Helper

Monitoring IP Broadcast Helper


Monitoring IP Broadcast Helper in Gaia Portal
1. From the left navigation tree, click Advanced Routing > IP Broadcast Helper.
2. In the top right corner, click Monitoring.

Note - The page is static. To see the latest values, click Reload.

Monitoring IP Broadcast Helper in Gaia Clish

To see the available "show" commands for IP Broadcast Helper, enter in Gaia Clish:

show iphelper[Esc][Esc]

Troubleshooting IP Broadcast Helper


See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 154


PIM

PIM
In This Section:

Introduction 155
IPv4 PIM Dense Mode (DM) 156
IPv4 PIM Sparse Mode (SM) 156
IPv4 PIM Source-Specific Multicast (SSM) Mode 157

Introduction
IPv4 Protocol-Independent Multicast (PIM) can forward IPv4 multicast packets with a unicast
protocol.
IPv4 PIM efficiently routes IPv4 multicast traffic for groups that span wide area (and inter-
domain) networks.
It works with all existing unicast routing protocols.
IPv4 PIM supports these modes:
n Dense Mode (PIM DM)
n Sparse Mode (PIM SM)
n Source-Specific Multicast Mode(PIM SSM)

Notes:
n You can enable only one mode of IPv4 PIM at a time.
n Due to a Gaia OS limitation, a maximum of 31 PIM interfaces can be
configured.
If more interface are configured, IPv4 PIM runs only on the first 31
interfaces.
n You must configure an Access Control rule that accepts IPv4 PIM traffic.

R82.10 Gaia Advanced Routing Administration Guide | 155


PIM

IPv4 PIM Dense Mode (DM)


This mode is most useful when:
n Senders and receivers are in close proximity to one another.
n There are few senders and many receivers.
n The volume of multicast traffic is high.
n The stream of multicast traffic is constant.
PIM Dense Mode State Refresh

The IPv4 PIM Dense Mode State Refresh option can be used in conjunction with dense
mode to eliminate the periodic flood-and-prune of multicast data with no active receivers. All
PIM routers must have State Refresh enabled to take advantage of this feature.
The IPv4 PIM Dense Mode builds multicast distribution trees that operate on a flood and
prune principle. Multicast packets from a source are flooded throughout a PIM dense mode
network. PIM routers that receive multicast packets and have no directly connected
multicast group members or PIM neighbors send a prune message back up the source-
based distribution tree toward the source of the packets. As a result, subsequent multicast
packets are not flooded to pruned branches of the distribution tree. However, the pruned
state in PIM dense mode times out approximately every three minutes and the entire PIM
dense mode network is reflooded with multicast packets and prune messages. This
reflooding of unwanted traffic throughout the PIM dense mode network consumes network
bandwidth unnecessarily.

Use the IPv4 PIM Dense Mode State Refresh feature to keep the pruned state in PIM dense
mode from timing out by periodically forwarding a control message down the distribution
tree. The control message refreshes the prune state on the outgoing interfaces of each
router in the tree. This saves network bandwidth by greatly reducing the reflooding of
unwanted multicast traffic to pruned branches of the PIM dense mode network.

Note - You must enable state refresh on all the IPv4 PIM routers in the distribution
tree to take advantage of this feature.

IPv4 PIM Sparse Mode (SM)


This mode is most useful when:
n There are few IPv4 receivers in a group.
n IPv4 senders and receivers are separated by WAN links.
n The type of IPv4 traffic is intermittent.

R82.10 Gaia Advanced Routing Administration Guide | 156


PIM

IPv4 PIM Source-Specific Multicast (SSM)


Mode
This mode is most useful when:
n Most of IPv4 multicast traffic is from well-known sources.
n It is desirable to avoid the overhead of shared tree and rendezvous point processing
associated with sparse mode.
IPv4 PIM SSM is a version of IPv4 PIM Sparse Mode. It is used in conjunction with IGMP v3 to
request or block multicast traffic from specific sources. For example, when a host requests
traffic for a multicast group from a specific source, SSM sends PIM join/prune messages
towards the source.
The multicast group range [Link]/8 is reserved for SSM. When SSM is enabled, Sparse
Mode accepts only IGMP v3 reports for groups that fall within this range. Sparse Mode ignores
IGMP v1 and IGMP v2 reports in this range.
In addition, only shortest-path-tree (SPT) join/prune messages for these groups are accepted
from neighboring routers. All other multicast groups are processed as in native Sparse Mode.
SSM does not need a Rendezvous Point (RP). The presence of an RP for any of the SSM
groups does not have any influence on the processing of join/prune messages.

R82.10 Gaia Advanced Routing Administration Guide | 157


Configuring IPv4 PIM in Gaia Portal

Configuring IPv4 PIM in Gaia Portal


In This Section:

Configuring IPv4 PIM Modes 158


Configuring IPv4 PIM on Interfaces 161
Configuring IPv4 PIM Advanced Options 164
Configuring IPv4 PIM Bootstrap and Rendezvous Point Settings 167

Warning - Multicast Forwarding Cache (MFC) static entries and IPv4 PIM are
mutually exclusive features and must not be enabled at the same time ("Multicast
Forwarding Cache (MFC)" on page 730).

Important - In a Cluster, you must configure all the Cluster Members in the same way.

Configuring IPv4 PIM Modes


To configure IPv4 PIM Sparse Mode (SM)

1. From the left navigation tree, click Advanced Routing > PIM.
2. In the PIM Global Settings section:
a. Select Sparse Mode (SM).

b. Click Apply.
3. In the PIM Interfaces section, add the applicable interfaces.

See the "Configuring IPv4 PIM on Interfaces" on page 161 section below.
4. Optional: In the Advanced Options section, configure the applicable settings.
See the "Configuring IPv4 PIM Advanced Options" on page 164 section below.
5. Optional: In the Bootstrap and Rendezvous Point Settings section, configure the
applicable settings.
See the "Configuring IPv4 PIM Bootstrap and Rendezvous Point Settings" on
page 167 section below.
6. Configure the Static Multicast Routes.
See "Static Multicast Routes" on page 213.

R82.10 Gaia Advanced Routing Administration Guide | 158


Configuring IPv4 PIM in Gaia Portal

To configure IPv4 PIM Dense Mode (DM)

1. From the left navigation tree, click Advanced Routing > PIM.
2. In the PIM Global Settings section:
a. Select Dense Mode (DM).
b. Select the State Refresh to use state refresh messages to delay timing out
prune state of multicast traffic that has no active receivers. This helps suppress
the flood-and-prune cycle inherent to Dense Mode.
c. Click Apply.
3. In the PIM Interfaces section, add the applicable interfaces.
a. Click Add.

b. In the Interface field, select the interface, on which you want to run PIM.
c. Optional: To configure this interface to use the IPv4 VRRP Virtual IP address,
select Use Virtual address.
d. Optional: in the DR Priority (Designated Router priority) field, enter a new
priority between 0 and 4294967295.
e. Click Save.
4. Optional: In the Advanced Options section, configure the applicable settings.
See the "Configuring IPv4 PIM Advanced Options" on page 164 section below.

5. Configure the Static Multicast Routes.


See "Static Multicast Routes" on page 213.

R82.10 Gaia Advanced Routing Administration Guide | 159


Configuring IPv4 PIM in Gaia Portal

To configure IPv4 PIM Source-Specific Multicast (SSM)

1. From the left navigation tree, click Advanced Routing > PIM.
2. In the PIM Global Settings section:
a. Select Source-Specific Multicast (SSM).
b. Click Apply.
3. In the PIM Interfaces section, add the applicable interfaces.
See the "Configuring IPv4 PIM on Interfaces" on the next page section below.
4. Optional: In the Advanced Options section, configure the applicable settings.
See the "Configuring IPv4 PIM Advanced Options" on page 164 section below.

5. Optional: In the Bootstrap and Rendezvous Point Settings section, configure the
applicable settings.
See the "Configuring IPv4 PIM Bootstrap and Rendezvous Point Settings" on
page 167 section below.
6. Configure the Static Multicast Routes.
See "Static Multicast Routes" on page 213.

R82.10 Gaia Advanced Routing Administration Guide | 160


Configuring IPv4 PIM in Gaia Portal

Configuring IPv4 PIM on Interfaces


To configure IPv4 PIM on an interface

1. From the left navigation tree, click Advanced Routing > PIM.
2. Select the IPv4 PIM Mode.
See "Configuring IPv4 PIM Modes" on page 158.
3. In the PIM Interfaces section, click Add.
Alternatively, select the configured interface and click Edit.
4. Configure the applicable settings.

Parameter Description

Interface Specifies the interface, on which to enable PIM.

Use Virtual Select this option to use the IPv4 VRRP Virtual IP address on this
Address interface:
n PIM runs on this interface only after the router becomes a

VRRP Master after a failover.


n Creates the neighbor relationship with the Virtual IP, if the

router is a VRRP Master. The VRRP Master in the VRRP pair


sends Hello messages that include the Virtual IP as the
source address and processes PIM control messages from
routers that neighbor the VRRP pair.
Note - You cannot configure this option when ClusterXL is
enabled.
Range: Enabled, or Cleared
Default: Cleared

R82.10 Gaia Advanced Routing Administration Guide | 161


Configuring IPv4 PIM in Gaia Portal

Parameter Description

DR Priority The Designated Router priority advertised in the PIM Hello


messages that are sent on the interface.
This is used for DR selection on a LAN.
The router with the highest priority is selected as the designated
router.
To break a tie, the DR is selected on the basis of the highest IPv4
address.
If even one router does not advertise a DR priority configured, the
DR election is based on the IPv4 address.
Note - To make sure that an IPv4 PIM neighbor supports DR
Priority:
a. Run this command in Gaia Clish on the Security
Gateway:
show pim neighbor <IPv4 Address of
Neighbor>
b. For neighbors that advertise a DR selection priority
value, this message appears in the summary:
DRPriorityCapable Yes
Range: 0-4294967295
Default: 1

5. Click Save.

To disable IPv4 PIM on an interface

1. From the left navigation tree, click Advanced Routing > PIM.

2. In the PIM Interfaces section, select the interface.


3. Click Delete.
There is no prompt to confirm.

To disable IPv4 PIM on all interfaces

1. From the left navigation tree, click Advanced Routing > PIM.
2. In the PIM Interfaces section, click Delete All.
3. Click OK to confirm.

R82.10 Gaia Advanced Routing Administration Guide | 162


Configuring IPv4 PIM in Gaia Portal

To restart IPv4 PIM on all interfaces

1. From the left navigation tree, click Advanced Routing > PIM.
2. In the PIM Interfaces section, click Restart All.
3. Click OK to confirm.

R82.10 Gaia Advanced Routing Administration Guide | 163


Configuring IPv4 PIM in Gaia Portal

Configuring IPv4 PIM Advanced Options


Warning - The default settings are based on the IPv4 PIM RFCs. Changing these
settings may lead to unexpected network behavior.

These settings are optional.


1. From the left navigation tree, click Advanced Routing > PIM.
2. In the Advanced Options section, click Edit Settings.
3. Configure the applicable settings.
Description of General Timers

Parameter Description

Hello Interval between PIM Hello messages that are sent on a multicast-
Interval capable interface.
Hello messages are addressed to the All-PIM-Routers multicast
group ([Link]), so that PIM routers may discover neighbors on
a multi-access network.
Range: 1-21845 seconds
Default: 30 seconds

Data Interval The life-time of a new PIM forwarding entry.


Subsequently, the life of the entry is extended in different ways
based on the location of this router in the network.
For example, in some cases the receipt of PIM control messages
(periodic join/prune messages) extends the life of the entry and in
others the presence of local senders of multicast traffic prevents
the deletion of the entry.
Range: 11-3600 seconds
Default: 210 seconds

Assert If an assert battle on an upstream interface results in the selection


Interval of a PIM neighbor other than the unicast reverse-path-forwarding
(RPF) neighbor towards the source of the data traffic (for which the
assert battle was generated) as the designated forwarder on that
interface, then the winner is used as the upstream neighbor for all
subsequent join/prune messages.
This change is timed-out after expiry of the assert interval.
Range: 1-3600 seconds
Default: 180 seconds

R82.10 Gaia Advanced Routing Administration Guide | 164


Configuring IPv4 PIM in Gaia Portal

Parameter Description

Join Prune Interval between sending Join/Prune messages.


Interval Range: 1-3600 seconds
Default: 60 seconds

Join Prune The maximum interval from the time when the unicast Reverse
Delay Path Forwarding (RPF) neighbor (towards a source or the RP)
Interval changes, and a triggered Join/Prune message is sent.
Range: 1-3600 seconds
Default: 5 seconds

Description of Assert Ranks

Parameter Description

Direct Compares the cost of protocols to find which router will forward
OSPF multicast data packets on a multi-access LAN.
Kernel These values are used in assert messages sent out on a LAN
Static when a router detects data packets on an interface other than the
RIP incoming interface towards the source of the data.
BGP These values must be the same for all routers on a multi-access
LAN that run the same protocol.
Therefore, the default values were specially configured to match
those of other implementations.
n Range: 0-255
n Defaults:
l BGP: 170

l Direct: 0

l Kernel: 40

l OSPF: 10

l OSPF ASE: 150

l RIP: 100

l Static: 60

Description of State Refresh Parameters

Parameter Description

State For Dense Mode, the interval at which state refresh messages are
Refresh sent for multicast traffic originated by directly-connected sources.
Interval Range: 1-255 seconds
Default: 60 seconds

R82.10 Gaia Advanced Routing Administration Guide | 165


Configuring IPv4 PIM in Gaia Portal

Parameter Description

State For Dense Mode, the time-to-live (TTL) placed in the state refresh
Refresh TTL messages originated for multicast traffic from directly-connected
sources.
You can use this value to limit the forwarding of state refresh
messages in the network.
In the absence of user configuration, it is derived from the multicast
data.
Range: 1-255
Default: None

Description of Sparse Mode Timers

Parameter Description

Register The mean interval between receipt of a register-stop and the


Suppression time when registers can be sent again.
Interval A lower value means more frequent register bursts at the
rendezvous point.
A higher value means a longer join latency for new receivers.
Range: 60-3600 seconds
Default: 60

CRP Advertise The interval between which candidate-rendezvous point routers


Interval send candidate-rendezvous point advertisements to the elected
bootstrap router.
Range: 1-3600 seconds
Default: 60 seconds

4. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 166


Configuring IPv4 PIM in Gaia Portal

Configuring IPv4 PIM Bootstrap and Rendezvous Point


Settings
These settings are optional.
To configure this router as an IPv4 Bootstrap router or an IPv4 Rendezvous Point

1. From the left navigation tree, click Advanced Routing > PIM.
2. In the PIM Global Settings section, in the PIM Protocol field, select one these:
n Sparse Mode (SM)
n Source Specific Multicast (SSM)
3. In the Bootstrap and Rendezvous Point Settings section, click Edit Settings.

4. To enable the router as an IPv4 Bootstrap Router:


a. Select Enable Bootstrap Router.
Description

If enabled, this router is a candidate bootstrap router (C-BSR). All candidate


Rendezvous Points (C-RPs) send C-RP-Advertisements to the selected
bootstrap router (BSR).
The BSR then disseminates this information in bootstrap messages across
the PIM domain.
To prevent a single point of failure, configure more than one router in a
domain as a candidate BSR.
Default: Cleared

R82.10 Gaia Advanced Routing Administration Guide | 167


Configuring IPv4 PIM in Gaia Portal

b. Optional: Enter the Local Address of the bootstrap router.


Description

Address used for the C-BSR state machine and the bootstrap messages.
The higher the IPv4 address, the higher the priority.

Best Practice - Configure this local IPv4 address in these cases:


n You enabled IPv4 PIM on two or more interfaces.
n An IPv4 PIM interface has two or more IPv4 addresses.

Important:
n On a single Security Gateway, this address can be that of the

IPv4 PIM interfaces or an address configured on the loopback


interface.
If an address from the loopback interface is used, do not select
an address in the [Link]/8 address range.
If you do not configure this IPv4 address explicitly, then Gaia
OS uses the global IPv4 address.
n On a ClusterXL Cluster Member or VRRP Cluster Member, this

address can only be the Cluster Virtual IP address configured


on this IPv4 PIM interface.
If you do not configure this IPv4 address explicitly, then Gaia
OS uses the global IPv4 Virtual IP address.

Range: IPv4 address of an IPv4 PIM interface, or or of a loopback address


(not in the [Link]/8 address range).

Default: The IPv4 address of one of the interfaces on which IPv4 PIM is
enabled. The default does not apply on Cluster Members.

c. Optional: Enter the Priority.


Description

The priority advertised in C-BSR messages.


The candidate bootstrap router with the highest priority value is selected as
the bootstrap router for the domain.
The higher the value, the higher the priority.
Range: 0-255
Default: 64

5. To enable the router as an IPv4 Candidate Rendezvous Point:

R82.10 Gaia Advanced Routing Administration Guide | 168


Configuring IPv4 PIM in Gaia Portal

a. Select Enable Candidate RP to configure Gaia as a candidate rendezvous


point router.
b. Optional: Enter the Local Address of the Candidate Rendezvous Point router.
Description

Address used for the C-RP state machine and in the C-RP-Advertisements
sent to the elected bootstrap router.
The higher the IPv4 address, the higher the priority.

Best Practice - Configure this local IPv4 address in these cases:


n You enabled IPv4 PIM on two or more interfaces.
n An IPv4 PIM interface has two or more IPv4 addresses.

Important:
n On a single Security Gateway, this address can be that of the

IPv4 PIM interfaces or an address configured on the loopback


interface.
If an address from the loopback interface is used, do not select
an address in the [Link]/8 address range.
If you do not configure this IPv4 address explicitly, then Gaia
OS uses the global IPv4 address.
n On a ClusterXL Cluster Member or VRRP Cluster Member, this

address can only be the Cluster Virtual IP address configured


on this IPv4 PIM interface.
If you do not configure this IPv4 address explicitly, then Gaia
OS uses the global IPv4 Virtual IP address.

Range: IPv4 address of an IPv4 PIM interface, or or of a loopback address


(not in the [Link]/8 address range).

Default: The IPv4 address of one of the interfaces on which IPv4 PIM is
enabled. The default does not apply on Cluster Members.

c. Optional: Enter the Priority.


Description

The priority of this C-RP.


All PIM routers select the same RP for a multicast group address from the list
of C-RPs received in the bootstrap messages from the elected BSR.
The lower the value, the higher the priority.
Range: 0-255
Default: 192

R82.10 Gaia Advanced Routing Administration Guide | 169


Configuring IPv4 PIM in Gaia Portal

d. Optional: Click Add to configure a Multicast Group and Subnet mask for which
this router is designated as the candidate rendezvous point.
Description

n Multicast Group
The multicast IPv4 address of the group(s), for which this rendezvous
point is responsible.
Range: Dotted-quad ([224-239].[0-255].[0-255].[0-255])
Default: [Link]/4
n Subnet mask
The IPv4 mask length.

Range: 1-32
Default: None

6. To enable the router as an IPv4 Static Rendezvous Point:


a. Select Enable Static RP.
b. Optional: Click Add to enter the Static Rendezvous Point IP address.
Description

If an associated multicast group and prefix is not configured, the Static


Rendezvous Point (RP) is considered to be responsible for all multicast
groups ([Link]/4).
This needs to be consistent with the RP information at other routers in a
multicast domain irrespective of the RP-dissemination mechanism (bootstrap
or autoRP) used.

Note - The static RP overrides the RP information received from


other RP-dissemination mechanisms, such as bootstrap routers.

Range: Any IPv4 address


Default: None

R82.10 Gaia Advanced Routing Administration Guide | 170


Configuring IPv4 PIM in Gaia Portal

c. Optional: Click Add to configure a Multicast Group and Subnet mask for which
this router is designated as the static rendezvous point.
Description

n Multicast Group
The multicast IPv4 address of the group(s), for which this rendezvous
point is responsible.
Range: Dotted-quad ([224-239].[0-255].[0-255].[0-255])
Default: [Link]/4
n Subnet mask
The IPv4 mask length.

Range: 1-32
Default: None

7. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 171


Configuring IPv4 PIM in Gaia Clish

Configuring IPv4 PIM in Gaia Clish


Warning - Multicast Forwarding Cache (MFC) static entries and IPv4 PIM are
mutually exclusive features and must not be enabled at the same time ("Multicast
Forwarding Cache (MFC)" on page 730).

Important - In a Cluster, you must configure all the Cluster Members in the same way.

n To see the available "set" commands for IPv4 PIM, enter in Gaia Clish:

set pim[Esc][Esc]

n To see the available "show" commands for IPv4 PIM, enter in Gaia Clish:

show pim[Esc][Esc]

See "Monitoring and Troubleshooting IPv4 PIM" on page 182.


n To see the available "restart" commands for IPv4 PIM, enter in Gaia Clish:

restart pim[Esc][Esc]

R82.10 Gaia Advanced Routing Administration Guide | 172


Configuring IPv4 PIM in Gaia Clish

Syntax for configuring IPv4 PIM

set pim
assert-interval {<1-3600> | default}
assert-rank protocol <Protocol> rank {<0-255> | default}
bootstrap-candidate
local-address <IPv4 address>
{off | on}
priority {<0-255> | default}
candidate-rp
advertise-interval {<1-3600> | default}
local-address {IPv4 address>
multicast-group <IPv4 address>/<Subnet mask> {off |
on}
{off | on}
priority {<0-255> | default}
data-interval {<11-3600> | default}
hello-interval {<1-21845> | default}
interface <Name of Interface>
dr-priority {<0-4294967295> | default}
{off | on}
virtual-address {off | on}
interface-all-off
jp-delay-interval {<1-3600> | default}
jp-interval {<1-3600> | default}
mode {dense | sparse | ssm}
register-suppress-interval {<60-3600> | default}
state-refresh {off | on}
state-refresh-interval {<1-255> | default}
state-refresh-ttl {<1-255> | default}
static-rp
{off | on}
rp-address <IPv4 address>
multicast-group <IPv4 address>/<Subnet mask>
{off | on}
{off | on}

Parameters for configuring IPv4 PIM

The mandatory parameters are marked Mandatory. All other parameters are optional.

R82.10 Gaia Advanced Routing Administration Guide | 173


Configuring IPv4 PIM in Gaia Clish

Parameter Description

assert-interval Configures the assert interval.


{<1-3600> | If an assert battle on an upstream interface results in the selection
default} of an IPv4 PIM neighbor other than the unicast reverse-path-
forwarding (RPF) neighbor towards the source of the data traffic
(for which the assert battle was generated) as the designated
forwarder on that interface, then the winner is used as the
upstream neighbor for all subsequent join/prune messages.
This change is timed-out after expiry of the assert interval.
Range: 1-3600 seconds
Default: 180 seconds

assert-rank Configures the protocol, for which to configure the assert rank:
protocol
<Protocol>
n bgp - Routes learned via the IPv4 BGP protocol
n direct - Routes directly connected to an IPv4 network
interface
n kernel - Kernel routes for IPv4
n ospf - Routes learned via the IPv4 OSPF v2 protocol
n ospfase - External routes learned via the IPv4 OSPF v2
ASE protocol
n rip - Routes learned via the IPv4 RIP protocol
n static - Static IPv4 routes

rank {<0-255> | Configures the IPv4 protocol rank to compare the cost of
default} protocols to find which router will forward multicast data packets
on a multi-access LAN.
These values are used in assert messages sent out on a LAN
when a router detects data packets on an interface other than the
incoming interface towards the source of the data.
These values must be the same for all routers on a multi-access
LAN that run the same protocol.
Therefore, the default values were specially configured to match
those of other implementations.
n Range: 0-255
n Defaults:
l BGP: 170

l Direct: 0

l Kernel: 40

l OSPF: 10

l OSPF ASE: 150

l RIP: 100

l Static: 60

R82.10 Gaia Advanced Routing Administration Guide | 174


Configuring IPv4 PIM in Gaia Clish

Parameter Description

bootstrap- Configures the IPv4 Bootstrap Candidate Local Address used for
candidate the C-BSR state machine and the bootstrap messages.
local-address Best Practice - Configure this local IPv4 address in these
<IPv4 address> cases:
n You enabled IPv4 PIM on two or more interfaces.
n An IPv4 PIM interface has two or more IPv4 addresses.

Important:
n On a single Security Gateway, this address can be that
of the IPv4 PIM interfaces or an address configured on
the loopback interface.
If an address from the loopback interface is used, do
not select an address in the [Link]/8 address
range.
If you do not configure this IPv4 address explicitly, then
Gaia OS uses the global IPv4 address.
n On a ClusterXL Cluster Member or VRRP Cluster
Member, this address can only be the Cluster Virtual IP
address configured on this IPv4 PIM interface.
If you do not configure this IPv4 address explicitly, then
Gaia OS uses the global IPv4 Virtual IP address.

Range: IPv4 address of an IPv4 PIM interface, or or of a loopback


address (not in the [Link]/8 address range).
Default: The IPv4 address of one of the interfaces on which IPv4
PIM is enabled. The default does not apply on Cluster Members.

bootstrap- Disables (off) or enables (on) the IPv4 Bootstrap Candidate.


candidate {off
| on}

bootstrap- Configures the priority advertised in C-BSR messages.


candidate The candidate bootstrap router with the highest priority value is
priority {<0- selected as the bootstrap router for the domain.
255> | default} The C-RP with the lowest priority has the highest preference.
The highest priority value is 0.
Range: 0-255
Default: 64

R82.10 Gaia Advanced Routing Administration Guide | 175


Configuring IPv4 PIM in Gaia Clish

Parameter Description

candidate-rp Configures the IPv4 Candidate Rendezvous Point (RP)


advertise- Advertisement Interval.
interval {<1- Range: 1-3600
3600> | Default: 60
default}

candidate-rp Configures the IPv4 Candidate Rendezvous Point router address


local-address used for the C-RP state machine and in the C-RP-Advertisements
<IPv4 address> sent to the elected bootstrap router.
Best Practice - Configure this local IPv4 address in these
cases:
n You enabled IPv4 PIM on two or more interfaces.
n An IPv4 PIM interface has two or more IPv4 addresses.

Important:
n On a single Security Gateway, this address can be that
of the IPv4 PIM interfaces or an address configured on
the loopback interface.
If an address from the loopback interface is used, do
not select an address in the [Link]/8 address
range.
If you do not configure this IPv4 address explicitly, then
Gaia OS uses the global IPv4 address.
n On a ClusterXL Cluster Member or VRRP Cluster
Member, this address can only be the Cluster Virtual IP
address configured on this IPv4 PIM interface.
If you do not configure this IPv4 address explicitly, then
Gaia OS uses the global IPv4 Virtual IP address.

Range: IPv4 address of an IPv4 PIM interface, or or of a loopback


address (not in the [Link]/8 address range).
Default: Selects the IPv4 address of one of the interfaces on
which IPv4 PIM is enabled. The default does not apply on Cluster
Members.

R82.10 Gaia Advanced Routing Administration Guide | 176


Configuring IPv4 PIM in Gaia Clish

Parameter Description

candidate-rp Configure the IPv4 Multicast Group, for which this router is
multicast-group designated as the candidate rendezvous point.
<IPv4
n <IPv4 address>
address>/<
Subnet mask> The multicast IPv4 address of the group(s) in CIDR
{off | on} notation, for which this rendezvous point is responsible.
Range: Dotted-quad ([224-239].[0-255].[0-255].[0-255])
Default: [Link]/4
n <Subnet mask>
The IPv4 mask length.
Range: 1-32
Default: None

Important - When you enable a Static Rendezvous Point, it


overrides the configuration from the Candidate Rendezvous
Point. If a multicast group matches Rendezvous Points in
both Static RP and Candidate RP, then Gaia OS uses the
Static RP.

candidate-rp Disables (off) or enables (on) Gaia as an IPv4 Candidate


{off | on} Rendezvous Point router.

candidate-rp Configures the priority of this C-RP.


priority {<0- All IPv4 PIM routers select the same RP for a multicast group
255> | default} address from the list of C-RPs received in the bootstrap
messages from the elected BSR.
The lower the Local Preference of the C-RP, the higher the
priority.
Range: 0-255
Default: 192

data-interval Configures the life-time of a new IPv4 PIM forwarding entry.


{<11-3600> | Subsequently, the life of the entry is extended in different ways
default} based on the location of this router in the network.
For example, in some cases the receipt of PIM control messages
(periodic join/prune messages) extends the life of the entry and in
others the presence of local senders of multicast traffic prevents
the deletion of the entry.
Range: 11-3600 seconds
Default: 210 seconds

R82.10 Gaia Advanced Routing Administration Guide | 177


Configuring IPv4 PIM in Gaia Clish

Parameter Description

hello-interval Configures the interval between IPv4 PIM Hello messages that
{<1-21845> | are sent on a multicast-capable interface.
default} Hello messages are addressed to the All-PIM-Routers multicast
group ([Link]), so that PIM routers may discover neighbors
on a multi-access network.
Range: 1-21845 seconds
Default: 30 seconds

interface <Name Mandatory.


of Interface> Specifies the interface, on which to enable IPv4 PIM.

interface <Name Configures the IPv4 Designated Router (DR) priority advertised in
of Interface> the IPv4 PIM Hello messages that are sent on the interface.
dr-priority This is used for DR selection on a LAN.
{<0-4294967295> The router with the highest priority is selected as the designated
| default} router.
To break a tie, the DR is selected on the basis of the highest IP
address.
If even one router does not advertise a DR priority configured, the
DR election is based on the IP address.
Notes:
n To make sure that an IPv4 PIM neighbor supports DR
Priority:
a. Run this command in Gaia Clish on the Security
Gateway:
show pim neighbor <IPv4 Address
of Neighbor>
b. For neighbors that advertise a DR selection
priority value, this message appears in the
summary:
DRPriorityCapable Yes
n Because Gaia OS does not support IGMP for
unnumbered interfaces, it cannot function as a DR in
the presence of another router.

Range: 0-4294967295
Default: 1

interface <Name Disables (off) or enables (on) IPv4 PIM on the specified
of Interface> interface.
{off | on}

R82.10 Gaia Advanced Routing Administration Guide | 178


Configuring IPv4 PIM in Gaia Clish

Parameter Description

interface <Name Disables (off) or enables (on) the use of the IPv4 VRRP Virtual
of Interface> IP address on this interface:
virtual-address
{off | on}
n IPv4 PIM runs on this interface only after the router
becomes a VRRP Master after a failover.
n Creates the neighbor relationship with the IPv4 Virtual IP
address, if the router is a VRRP Master. The VRRP Master
in the VRRP pair sends Hello messages that include the
Virtual IP as the source address and processes PIM control
messages from routers that neighbor the VRRP pair.

Note - You cannot configure this option when ClusterXL is


enabled.
Range: off, or on
Default: off

interface-all- Disables IPv4 PIM on all interfaces.


off

jp-delay- Configures the maximum interval from the time when the unicast
interval {<1- Reverse Path Forwarding (RPF) neighbor (towards a source or
3600> | the RP) changes, and a triggered Join/Prune message is sent.
default} Range: 1-3600 seconds
Default: 5 seconds

jp-interval Configures the interval between sending Join/Prune messages.


{<1-3600> | Range: 1-3600 seconds
default} Default: 60 seconds

mode {dense | Mandatory.


sparse | ssm} Configures the IPv4 PIM mode:
n dense - Dense Mode
n sparse - Sparse Mode
n ssm - Source-Specific Multicast

register- Configures the mean interval between receipt of a register-stop


suppress- and the time when registers can be sent again.
interval {<60- A lower value means more frequent register bursts at the
3600> | rendezvous point.
default} A higher value means a longer join latency for new receivers.
Range: 60-3600 seconds
Default: 60

R82.10 Gaia Advanced Routing Administration Guide | 179


Configuring IPv4 PIM in Gaia Clish

Parameter Description

state-refresh Disables (off) or enables (on) the use of state refresh messages
{off | on} to delay timing out prune state of multicast traffic that has no
active receivers.
This helps suppress the flood-and-prune cycle inherent to Dense
Mode.

state-refresh- For Dense Mode, configures the interval at which state refresh
interval {<1- messages are sent for multicast traffic originated by directly-
255> | default} connected sources.
Range: 1-255 seconds
Default: 60 seconds

state-refresh- For Dense Mode, configures the time-to-live (TTL) placed in the
ttl {<1-255> | state refresh messages originated for multicast traffic from
default} directly-connected sources.
You can use this value to limit the forwarding of state refresh
messages in the network.
In the absence of user configuration, it is derived from the
multicast data.
Range: 1-255
Default: None

static-rp {off Disables (off) or enables (on) all IPv4 Static Rendezvous Points
| on}

R82.10 Gaia Advanced Routing Administration Guide | 180


Configuring IPv4 PIM in Gaia Clish

Parameter Description

static-rp rp- Configures the IPv4 Static Rendezvous Point IP address.


address <IPv4 If an associated multicast group and prefix is not configured, the
address> {off | Static Rendezvous Point (RP) is considered to be responsible for
on} all multicast groups ([Link]/4).
This needs to be consistent with the RP information at other
routers in a multicast domain irrespective of the RP-
dissemination mechanism (bootstrap or autoRP) used.
Important:
n When you enable a Static Rendezvous Point, it
overrides the configuration from the Candidate
Rendezvous Point. If a multicast group matches
Rendezvous Points in both Static RP and Candidate
RP, then Gaia OS uses the Static RP.
n The Static RP overrides the RP information received
from other RP-dissemination mechanisms, such as
bootstrap routers.

Range: Any IPv4 address


Default: None

static-rp rp- Configures the IPv4 Multicast Group, for which this router is
address <IPv4 designated as the static rendezvous point.
address>
n <IPv4 address>
multicast-group
<IPv4 The multicast IP address of the group(s) in CIDR notation,
address>/< for which this rendezvous point is responsible.
Subnet mask> Range: Dotted-quad ([224-239].[0-255].[0-255].[0-255])
{off | on} Default: [Link]/4
n <Subnet mask>
Mask length.
Range: 1-32
Default: None

R82.10 Gaia Advanced Routing Administration Guide | 181


Monitoring and Troubleshooting IPv4 PIM

Monitoring and Troubleshooting IPv4 PIM


Important - In IPv4 PIM Dense Mode, when a new IPv4 PIM router joins the existing
network, it may take up to two cycles of PIM prune timer and/or downstream IGMP
report interval, for the intended multicast traffic to start flowing. To improve the PIM-
DM responsiveness, the user can enforce the local-groups / static-groups
configuration.

Monitoring IPv4 PIM in Gaia Portal


1. From the left navigation tree, click Advanced Routing > PIM.
2. In the top right corner, click Monitoring.

3. In the PIM Monitor section, click the Information category.

Note - The page is static. To see the latest values, click Reload.

Monitoring IPv4 PIM in Gaia Clish

Syntax for monitoring IPv4 PIM

show pim
bootstrap
candidate-rp
group-rp-mapping <IPv4 Multicast Group>
interface <Name of Interface>
interfaces
joins
[detailed]
group <IPv4 Multicast Group> [detailed]
memory
neighbor <IPv4 PIM Neighbor>
neighbors
rps
sparse-mode-stats
stats
summary
timers
virtual-interfaces

R82.10 Gaia Advanced Routing Administration Guide | 182


Monitoring and Troubleshooting IPv4 PIM

Parameters for monitoring IPv4 PIM

Parameter Description

bootstrap Shows the IPv4 PIM Bootstrap Router status.

candidate-rp Shows the IPv4 PIM Candidate Rendezvous Point


status.

group-rp-mapping <IPv4 Shows the IPv4 PIM Group-to-Rendezvous Point


Multicast Group> mapping.

interface <Name of Shows the status of the specified IPv4 PIM


Interface> interface.

interfaces Shows the status of all IPv4 PIM interfaces.

joins [detailed] Shows the IPv4 PIM Sparse-Mode join state for all
IPv4 Multicast Groups.

joins group <IPv4 Multicast Shows the IPv4 PIM Sparse-Mode join state for the
Group> [detailed] specified IPv4 Multicast Group.

memory Shows the IPv4 PIM memory usage.

neighbor <IPv4 PIM Shows the status of the specifiedIPv4 PIM


Neighbor> Neighbor.

neighbors Shows the status of all IPv4 PIM Neigbors.

rps Shows the IPv4 PIM Rendezvous Points.

sparse-mode-stats Shows the IPv4 PIM Sparse and SSM Mode


statistics.

stats Shows the IPv4 PIM statistics.

summary Shows the IPv4 PIM summary information.

timers Shows the timers.

virtual-interfaces Shows all IPv4 PIM virtual interfaces.

R82.10 Gaia Advanced Routing Administration Guide | 183


Monitoring and Troubleshooting IPv4 PIM

Troubleshooting IPv4 PIM


See "Trace Options" on page 672.
Need to enable the traces for all these modules:

Name in Gaia
Name in Gaia Clish Related Chapter
Portal

PIM pim "PIM" on page 155

MFC mfc "Multicast Forwarding Cache (MFC)"


on page 730

IGMP igmp "IGMP" on page 126

IP Reachability ip-reachability- "IP Reachability Detection" on


Detection detection page 243

R82.10 Gaia Advanced Routing Administration Guide | 184


IPv6 PIM

IPv6 PIM
Introduction
IPv6 Protocol-Independent Multicast (PIM) can forward IPv6 multicast packets with a unicast
protocol.
IPv6 PIM efficiently routes IPv6 multicast traffic for groups that span wide area (and inter-
domain) networks.
It works with all existing unicast routing protocols.
IPv6 PIM supports these modes:
n Sparse Mode (PIM SM)
n Source-Specific Multicast Mode(PIM SSM)

Notes:
n You can enable only one mode of IPv6 PIM at a time.
n Due to a Gaia OS limitation, a maximum of 31 PIM interfaces can be
configured.
If more interface are configured, IPv6 PIM runs only on the first 31
interfaces.
n You must configure an Access Control rule that accepts IPv6 PIM traffic.

IPv6 PIM Sparse Mode (SM)


This mode is most useful when:
n There are few IPv6 receivers in a group.
n IPv6 senders and receivers are separated by WAN links.
n The type of IPv6 traffic is intermittent.

R82.10 Gaia Advanced Routing Administration Guide | 185


IPv6 PIM

IPv6 PIM Source-Specific Multicast (SSM)


Mode
This mode is most useful when:
n Most of IPv6 multicast traffic is from well-known sources.
n It is desirable to avoid the overhead of shared tree and rendezvous point processing
associated with sparse mode.
SSM is a version of PIM Sparse Mode. It is used in conjunction with MLD v2 to request or block
multicast traffic from specific sources. For example, when a host requests traffic for a multicast
group from a specific source, SSM sends PIM join/prune messages towards the source.

The multicast group IPv6 range from FF30::/96 to FF3F::/96 is reserved for SSM.
In addition, only shortest-path-tree (SPT) join/prune messages for these groups are accepted
from neighboring routers. All other multicast groups are processed as in native Sparse Mode.
SSM does not need a Rendezvous Point (RP). The presence of an RP for any of the SSM
groups does not have any influence on the processing of join/prune messages.

R82.10 Gaia Advanced Routing Administration Guide | 186


Configuring IPv6 PIM in Gaia Portal

Configuring IPv6 PIM in Gaia Portal


In This Section:

Configuring IPv6 PIM Modes 187


Configuring IPv6 PIM on Interfaces 189
Configuring IPv6 PIM Advanced Options 192
Configuring IPv6 PIM Bootstrap and Rendezvous Point Settings 195

Warning - Multicast Forwarding Cache (MFC) static entries and IPv6 PIM are
mutually exclusive features and must not be enabled at the same time ("Multicast
Forwarding Cache (MFC)" on page 730).

Important - In a Cluster, you must configure all the Cluster Members in the same way.

Configuring IPv6 PIM Modes


To configure IPv6 PIM Sparse Mode (SM)

1. From the left navigation tree, click Advanced Routing > IPv6 PIM.
2. In the IPv6 PIM Global Settings section:
a. Select Sparse Mode (SM).

b. Click Apply.
3. In the IPv6 PIM Interfaces section, add the applicable interfaces.

See the "Configuring IPv6 PIM on Interfaces" on page 189 section below.
4. Optional: In the Advanced Options section, configure the applicable settings.
See the "Configuring IPv6 PIM Advanced Options" on page 192 section below.
5. Optional: In the Bootstrap and Rendezvous Point Settings section, configure the
applicable settings.
See the "Configuring IPv6 PIM Bootstrap and Rendezvous Point Settings" on
page 195 section below.
6. Configure the IPv6 Static Multicast Routes.
See "Static Multicast Routes" on page 213.

R82.10 Gaia Advanced Routing Administration Guide | 187


Configuring IPv6 PIM in Gaia Portal

To configure IPv6 PIM Source-Specific Multicast (SSM)

1. From the left navigation tree, click Advanced Routing > PIM.
2. In the PIM Global Settings section:
a. Select Source-Specific Multicast (SSM).
b. Click Apply.
3. In the IPv6 PIM Interfaces section, add the applicable interfaces.
See the "Configuring IPv6 PIM on Interfaces" on the next page section below.
4. Optional: In the Advanced Options section, configure the applicable settings.
See the "Configuring IPv6 PIM Advanced Options" on page 192 section below.

5. Optional: In the Bootstrap and Rendezvous Point Settings section, configure the
applicable settings.
See the "Configuring IPv6 PIM Bootstrap and Rendezvous Point Settings" on
page 195 section below.
6. Configure the Static Multicast Routes.
See "Static Multicast Routes" on page 213.

R82.10 Gaia Advanced Routing Administration Guide | 188


Configuring IPv6 PIM in Gaia Portal

Configuring IPv6 PIM on Interfaces


To configure IPv6 PIM on an interface

1. From the left navigation tree, click Advanced Routing > IPv6 PIM.
2. Select the IPv6 PIM Mode.
See "Configuring IPv6 PIM Modes" on page 187.
3. In the IPv6 PIM Interfaces section, click Add.
Alternatively, select the configured interface and click Edit.
4. Configure the applicable settings.

Parameter Description

Interface Specifies the interface, on which to enable PIM.

Use Virtual Select this option to use the IPv6 VRRP Virtual IP address on this
Address interface:
n PIM runs on this interface only after the router becomes a

VRRP Master after a failover.


n Creates the neighbor relationship with the Virtual IP, if the

router is a VRRP Master. The VRRP Master in the VRRP pair


sends Hello messages that include the Virtual IP as the
source address and processes PIM control messages from
routers that neighbor the VRRP pair.
Note - You cannot configure this option when ClusterXL is
enabled.
Range: Enabled, or Cleared
Default: Cleared

R82.10 Gaia Advanced Routing Administration Guide | 189


Configuring IPv6 PIM in Gaia Portal

Parameter Description

DR Priority The Designated Router priority advertised in the PIM Hello


messages that are sent on the interface.
This is used for DR selection on a LAN.
The router with the highest priority is selected as the designated
router.
To break a tie, the DR is selected on the basis of the highest IPv6
address.
If even one router does not advertise a DR priority configured, the
DR election is based on the IPv6 address.
Note - To make sure that an IPv6 PIM neighbor supports DR
Priority:
a. Run this command in Gaia Clish on the Security
Gateway:
show ipv6 pim neighbor <IPv6 Address
of Neighbor>
b. For neighbors that advertise a DR selection priority
value, this message appears in the summary:
DRPriorityCapable Yes
Range: 0-4294967295
Default: 1

5. Click Save.

To disable IPv6 PIM on an interface

1. From the left navigation tree, click Advanced Routing > IPv6 PIM.

2. In the IPv6 PIM Interfaces section, select the interface.


3. Click Delete.
There is no prompt to confirm.

To disable IPv6 PIM on all interfaces

1. From the left navigation tree, click Advanced Routing > IPv6 PIM.
2. In the IPv6 PIM Interfaces section, click Delete All.
3. Click OK to confirm.

R82.10 Gaia Advanced Routing Administration Guide | 190


Configuring IPv6 PIM in Gaia Portal

To restart IPv6 PIM on all interfaces

1. From the left navigation tree, click Advanced Routing > IPv6 PIM.
2. In the IPv6 PIM Interfaces section, click Restart All.
3. Click OK to confirm.

R82.10 Gaia Advanced Routing Administration Guide | 191


Configuring IPv6 PIM in Gaia Portal

Configuring IPv6 PIM Advanced Options


Warning - The default settings are based on the IPv6 PIM RFCs. Changing these
settings may lead to unexpected network behavior.

These settings are optional.


1. From the left navigation tree, click Advanced Routing > IPv6 PIM.
2. In the Advanced Options section, click Edit Settings.
3. Configure the applicable settings.
Description of General Timers

Parameter Description

Hello Interval between PIM Hello messages that are sent on a multicast-
Interval capable interface.
Hello messages are addressed to the All-PIM-Routers multicast
group ([Link]), so that PIM routers may discover neighbors on
a multi-access network.
Range: 1-21845 seconds
Default: 30 seconds

Data Interval The life-time of a new PIM forwarding entry.


Subsequently, the life of the entry is extended in different ways
based on the location of this router in the network.
For example, in some cases the receipt of PIM control messages
(periodic join/prune messages) extends the life of the entry and in
others the presence of local senders of multicast traffic prevents
the deletion of the entry.
Range: 11-3600 seconds
Default: 210 seconds

Assert If an assert battle on an upstream interface results in the selection


Interval of a PIM neighbor other than the unicast reverse-path-forwarding
(RPF) neighbor towards the source of the data traffic (for which the
assert battle was generated) as the designated forwarder on that
interface, then the winner is used as the upstream neighbor for all
subsequent join/prune messages.
This change is timed-out after expiry of the assert interval.
Range: 1-3600 seconds
Default: 180 seconds

R82.10 Gaia Advanced Routing Administration Guide | 192


Configuring IPv6 PIM in Gaia Portal

Parameter Description

Join Prune Interval between sending Join/Prune messages.


Interval Range: 1-3600 seconds
Default: 60 seconds

Join Prune The maximum interval from the time when the unicast Reverse
Delay Path Forwarding (RPF) neighbor (towards a source or the RP)
Interval changes, and a triggered Join/Prune message is sent.
Range: 1-3600 seconds
Default: 5 seconds

Description of Assert Ranks

Parameter Description

Direct Compares the cost of protocols to find which router will forward
Kernel multicast data packets on a multi-access LAN.
Static These values are used in assert messages sent out on a LAN
OSPF3 when a router detects data packets on an interface other than the
OSPF3 ASE incoming interface towards the source of the data.
RIPNG These values must be the same for all routers on a multi-access
BGP LAN that run the same protocol.
IS-IS Therefore, the default values were specially configured to match
those of other implementations.
n Range: 0-255
n Defaults:
l Direct: 0

l Kernel: 40

l Static: 60

l OSPF3: 10

l OSPF3 ASE: 150

l RIPNG: 100

l BGP: 170

l IS-IS: 15

R82.10 Gaia Advanced Routing Administration Guide | 193


Configuring IPv6 PIM in Gaia Portal

Description of Sparse Mode Timers

Parameter Description

Register The mean interval between receipt of a register-stop and the


Suppression time when registers can be sent again.
Interval A lower value means more frequent register bursts at the
rendezvous point.
A higher value means a longer join latency for new receivers.
Range: 60-3600 seconds
Default: 60

CRP Advertise The interval between which candidate-rendezvous point routers


Interval send candidate-rendezvous point advertisements to the elected
bootstrap router.
Range: 1-3600 seconds
Default: 60 seconds

4. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 194


Configuring IPv6 PIM in Gaia Portal

Configuring IPv6 PIM Bootstrap and Rendezvous Point


Settings
These settings are optional.
To configure this router as an IPv6 Bootstrap router or an IPv6 Rendezvous Point

1. From the left navigation tree, click Advanced Routing > IPv6 PIM.
2. In the IPv6 PIM Global Settings section, in the PIM Protocol field, select one these:
n Sparse Mode (SM)
n Source Specific Multicast (SSM)
3. In the Bootstrap and Rendezvous Point Settings section, click Edit Settings.

4. To enable the router as an IPv6 Bootstrap Router:


a. Select Enable Bootstrap Router.
Description

If enabled, this router is a candidate bootstrap router (C-BSR). All candidate


Rendezvous Points (C-RPs) send C-RP-Advertisements to the selected
bootstrap router (BSR).
The BSR then disseminates this information in bootstrap messages across
the PIM domain.
To prevent a single point of failure, configure more than one router in a
domain as a candidate BSR.
Default: Cleared

R82.10 Gaia Advanced Routing Administration Guide | 195


Configuring IPv6 PIM in Gaia Portal

b. Optional: Enter the Local Address of the bootstrap router.


Description

Address used for the C-BSR state machine and the bootstrap messages.
The higher the IPv6 address, the higher the priority.

Best Practice - Configure this local IPv6 address in these cases:


n You enabled IPv6 PIM on two or more interfaces.
n An IPv6 PIM interface has two or more IPv6 addresses.

Important:
n On a single Security Gateway, this address can be that of the

IPv6 PIM interfaces or an address configured on the loopback


interface.
If an address from the loopback interface is used, do not select
an address in the ::1/128 address range.
If you do not configure this IPv6 address explicitly, then Gaia
OS uses the global IPv6 address.
n On a ClusterXL Cluster Member or VRRP Cluster Member, this

address can only be the Cluster Virtual IP address configured


on this IPv6 PIM interface.
If you do not configure this IPv6 address explicitly, then Gaia
OS uses the global IPv6 Virtual IP address.

Range: IPv6 address of an IPv6 PIM interface, or of a loopback address (not


in the ::1/128 address range).

Default: The IPv6 address of one of the interfaces on which IPv6 PIM is
enabled. The default does not apply on Cluster Members.

c. Optional: Enter the Priority.


Description

The priority advertised in C-BSR messages.


The candidate bootstrap router with the highest priority value is selected as
the bootstrap router for the domain.
The higher the value, the higher the priority.
Range: 0-255
Default: 64

5. To enable the router as an IPv6 Candidate Rendezvous Point:

R82.10 Gaia Advanced Routing Administration Guide | 196


Configuring IPv6 PIM in Gaia Portal

a. Select Enable Candidate RP to configure Gaia as a candidate rendezvous


point router.
b. Optional: Enter the Local Address of the Candidate Rendezvous Point router.
Description

Address used for the C-RP state machine and in the C-RP-Advertisements
sent to the elected bootstrap router.
The higher the IPv6 address, the higher the priority.

Best Practice - Configure this local IPv6 address in these cases:


n You enabled IPv6 PIM on two or more interfaces.
n An IPv6 PIM interface has two or more IPv6 addresses.

Important:
n On a single Security Gateway, this address can be that of the

IPv6 PIM interfaces or an address configured on the loopback


interface.
If an address from the loopback interface is used, do not select
an address in the ::1/128 address range.
If you do not configure this IPv6 address explicitly, then Gaia
OS uses the global IPv6 address.
n On a ClusterXL Cluster Member or VRRP Cluster Member, this

address can only be the Cluster Virtual IP address configured


on this IPv6 PIM interface.
If you do not configure this IPv6 address explicitly, then Gaia
OS uses the global IPv6 Virtual IP address.

Range: IPv6 address of an IPv6 PIM interface, or of a loopback address (not


in the ::1/128 address range).

Default: The IPv6 address of one of the interfaces on which IPv6 PIM is
enabled. The default does not apply on Cluster Members.

c. Optional: Enter the Priority.


Description

The priority of this C-RP.


All PIM routers select the same RP for a multicast group address from the list
of C-RPs received in the bootstrap messages from the elected BSR.
The lower the value, the higher the priority.
Range: 0-255
Default: 192

R82.10 Gaia Advanced Routing Administration Guide | 197


Configuring IPv6 PIM in Gaia Portal

d. Optional: Click Add to configure a Multicast Group and Subnet mask for which
this router is designated as the candidate rendezvous point.
Description

n Multicast Group
The multicast IPv6 address of the group(s), for which this rendezvous
point is responsible.
Range: from [FF00]:[0000]: ... :[0000] to [FF0F]:[FFFF]: ... :[FFFF]
Default: None
n Subnet mask
Mask length.

Range: 8-128
Default: None

Important - When you enable a Static Rendezvous Point, it overrides


the configuration from the Candidate Rendezvous Point. If a
multicast group matches Rendezvous Points in both Static RP and
Candidate RP, then Gaia OS uses the Static RP.

6. To enable the router as an IPv6 Static Rendezvous Point:

R82.10 Gaia Advanced Routing Administration Guide | 198


Configuring IPv6 PIM in Gaia Portal

a. Select Enable Static RP.


b. Optional: Click Add to enter the Static Rendezvous Point IPv6 address.
Description

If an associated multicast group and prefix is not configured, the Static


Rendezvous Point (RP) is considered to be responsible for all multicast
groups (FF01::2).
This needs to be consistent with the RP information at other routers in a
multicast domain irrespective of the RP-dissemination mechanism (bootstrap
or autoRP) used.

Important:
n When you enable a Static Rendezvous Point, it overrides the

configuration from the Candidate Rendezvous Point. If a


multicast group matches Rendezvous Points in both Static RP
and Candidate RP, then Gaia OS uses the Static RP.
n The Static RP overrides the RP information received from other

RP-dissemination mechanisms, such as bootstrap routers.

Range: Any IPv6 address


Default: None

c. Optional: Click Add to configure a Multicast Group and Subnet mask for which
this router is designated as the static rendezvous point.
Description

n Multicast Group
The multicast IPv6 address of the group(s), for which this rendezvous
point is responsible.
Range: from [FF00]:[0000]: ... :[0000] to [FF0F]:[FFFF]: ... :[FFFF]
Default: None
n Subnet mask
Mask length.
Range: 8-128
Default: None

7. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 199


Configuring IPv6 PIM in Gaia Clish

Configuring IPv6 PIM in Gaia Clish


Warning- Multicast Forwarding Cache (MFC) static entries and IPv6 PIM are mutually
exclusive features and must not be enabled at the same time ("Multicast Forwarding
Cache (MFC)" on page 730).

Important - In a Cluster, you must configure all the Cluster Members in the same way.

n To see the available "set" commands for IPv6 PIM, enter in Gaia Clish:

set ipv6 pim[Esc][Esc]

n To see the available "show" commands for IPv6 PIM, enter in Gaia Clish:

show ipv6 pim[Esc][Esc]

See "Monitoring and Troubleshooting IPv6 PIM" on page 210.


n To see the available "restart" commands for IPv6 PIM, enter in Gaia Clish:

restart pim6[Esc][Esc]

R82.10 Gaia Advanced Routing Administration Guide | 200


Configuring IPv6 PIM in Gaia Clish

Syntax for configuring IPv6 PIM

set ipv6 pim


assert-interval {<1-3600> | default}
assert-rank protocol {bgp | direct | isis | kernel | ospf3
| ospf3ase | ripng | static} rank {<0-255> | default}
bootstrap-candidate
local-address <IPv6 Address> {on | off}
{on | off}
priority {<0-255> | default}
candidate-rp
advertise-interval {<1-3600> | default}
local-address <IPv6 Address> {on | off}
multicast-group <IPv6 Address> {on | off}
{on | off}
priority {<0-255> | default}
data-interval {<11-3600> | default}
hello-interval {<1-21845> | default}
interface <Name of Interface>
dr-priority {<0-4294967295> | default}
{on | off}
virtual-address {on | off}
interface-all-off
jp-delay-interval {<1-3600> | default}
jp-interval {<1-3600> | default}
mode {sparse | ssm}
register-suppress-interval {<60-3600> | default}
static-rp
{on | off}
rp-address <IPv6 Address>
multicast-group <IPv6 Address> {on | off}
{on | off}
unicast-bsm {on | off}

Parameters for configuring IPv6 PIM

The mandatory parameters are marked Mandatory. All other parameters are optional.

R82.10 Gaia Advanced Routing Administration Guide | 201


Configuring IPv6 PIM in Gaia Clish

Parameter Description

assert-interval Configures the assert interval.


{<1-3600> | If an assert battle on an upstream interface results in the selection
default} of an IPv6 PIM neighbor other than the unicast reverse-path-
forwarding (RPF) neighbor towards the source of the data traffic
(for which the assert battle was generated) as the designated
forwarder on that interface, then the winner is used as the
upstream neighbor for all subsequent join/prune messages.
This change is timed-out after expiry of the assert interval.
Range: 1-3600 seconds
Default: 180 seconds

assert-rank Configures the protocol, for which to configure the assert rank:
protocol
<Protocol>
n bgp - Routes learned via the IPv6 BGP protocol
n direct - Routes directly connected to an IPv6 network
interface
n isi - IS-IS routes for IPv6
n kernel - Kernel routes for IPv6
n ospf3 - Routes learned via the IPv6 OSPF v3 protocol
n ospf3ase - External routes learned via the IPv6 OSPF v3
ASE protocol
n rip - Routes learned via the IPv6 RIPng protocol
n static - Static IPv6 routes

R82.10 Gaia Advanced Routing Administration Guide | 202


Configuring IPv6 PIM in Gaia Clish

Parameter Description

rank {<0-255> | Configures the IPv6 protocol rank to compare the cost of
default} protocols to find which router will forward multicast data packets
on a multi-access LAN.
These values are used in assert messages sent out on a LAN
when a router detects data packets on an interface other than the
incoming interface towards the source of the data.
These values must be the same for all routers on a multi-access
LAN that run the same protocol.
Therefore, the default values were specially configured to match
those of other implementations.
n Range: 0-255
n Defaults:
l BGP: 170

l Direct: 0

l IS-IS: 15

l Kernel: 40

l OSPF v3: 10

l OSPF v3 ASE: 150

l RIPng: 100

l Static: 60

R82.10 Gaia Advanced Routing Administration Guide | 203


Configuring IPv6 PIM in Gaia Clish

Parameter Description

bootstrap- Configures the IPv6 Bootstrap Candidate Local Address used for
candidate the C-BSR state machine and the bootstrap messages.
local-address Best Practice - Configure this local IPv6 address in these
<IPv6 address> cases:
n You enabled IPv6 PIM on two or more interfaces.
n An IPv6 PIM interface has two or more IPv6 addresses.

Important:
n On a single Security Gateway, this address can be that
of the IPv6 PIM interfaces or an address configured on
the loopback interface.
If an address from the loopback interface is used, do
not select an address in the ::1/128 address range.
If you do not configure this IPv6 address explicitly, then
Gaia OS uses the global IPv6 address.
n On a ClusterXL Cluster Member or VRRP Cluster
Member, this address can only be the Cluster Virtual IP
address configured on this IPv6 PIM interface.
If you do not configure this IPv6 address explicitly, then
Gaia OS uses the global IPv6 Virtual IP address.

Range: IPv6 address of an IPv6 PIM interface, or of a loopback


address (not in the ::1/128 address range).
Default: The IPv6 address of one of the interfaces on which IPv6
PIM is enabled. The default does not apply on Cluster Members.

bootstrap- Disables (off) or enables (on) the IPv6 Bootstrap Candidate.


candidate {off
| on}

bootstrap- Configures the priority advertised in C-BSR messages.


candidate The candidate bootstrap router with the highest priority value is
priority {<0- selected as the bootstrap router for the domain.
255> | default} The C-RP with the lowest priority has the highest preference.
The highest priority value is 0.
Range: 0-255
Default: 64

candidate-rp Configures the IPv6 Candidate Rendezvous Point (RP)


advertise- Advertisement Interval.
interval {<1- Range: 1-3600
3600> | Default: 60
default}

R82.10 Gaia Advanced Routing Administration Guide | 204


Configuring IPv6 PIM in Gaia Clish

Parameter Description

candidate-rp Configures the IPv6 Candidate Rendezvous Point router address


local-address used for the C-RP state machine and in the C-RP-Advertisements
<IPv6 address> sent to the elected bootstrap router.
Best Practice - Configure this local IPv6 address in these
cases:
n You enabled IPv6 PIM on two or more interfaces.
n An IPv6 PIM interface has two or more IPv6 addresses.

Important:
n On a single Security Gateway, this address can be that
of the IPv6 PIM interfaces or an address configured on
the loopback interface.
If an address from the loopback interface is used, do
not select an address in the ::1/128 address range.
If you do not configure this IPv6 address explicitly, then
Gaia OS uses the global IPv6 address.
n On a ClusterXL Cluster Member or VRRP Cluster
Member, this address can only be the Cluster Virtual IP
address configured on this IPv6 PIM interface.
If you do not configure this IPv6 address explicitly, then
Gaia OS uses the global IPv6 Virtual IP address.

Range: IPv6 address of an IPv6 PIM interface, or of a loopback


address (not in the ::1/128 address range).
Default: Selects the IPv6 address of one of the interfaces on
which IPv6 PIM is enabled. The default does not apply on Cluster
Members.

R82.10 Gaia Advanced Routing Administration Guide | 205


Configuring IPv6 PIM in Gaia Clish

Parameter Description

candidate-rp Configure the IPv6 Multicast Group, for which this router is
multicast-group designated as the candidate rendezvous point.
<IPv6
n <IPv6 address>
address>/<
Subnet mask> The multicast IPv6 address of the group(s) in CIDR
{off | on} notation, for which this rendezvous point is responsible.
Range: from [FF00]:[0000]: ... :[0000] to [FF0F]:[FFFF]: ... :
[FFFF]
Default: None
n <Subnet mask>
The IPv6 mask length.
Range: 8-128
Default: None

Important - When you enable a Static Rendezvous Point, it


overrides the configuration from the Candidate Rendezvous
Point. If a multicast group matches Rendezvous Points in
both Static RP and Candidate RP, then Gaia OS uses the
Static RP.

candidate-rp Disables (off) or enables (on) Gaia as an IPv6 Candidate


{off | on} Rendezvous Point router.

candidate-rp Configures the priority of this C-RP.


priority {<0- All IPv6 PIM routers select the same RP for a multicast group
255> | default} address from the list of C-RPs received in the bootstrap
messages from the elected BSR.
The lower the Local Preference of the C-RP, the higher the
priority.
Range: 0-255
Default: 192

data-interval Configures the life-time of a new IPv6 PIM forwarding entry.


{<11-3600> | Subsequently, the life of the entry is extended in different ways
default} based on the location of this router in the network.
For example, in some cases the receipt of PIM control messages
(periodic join/prune messages) extends the life of the entry and in
others the presence of local senders of multicast traffic prevents
the deletion of the entry.
Range: 11-3600 seconds
Default: 210 seconds

R82.10 Gaia Advanced Routing Administration Guide | 206


Configuring IPv6 PIM in Gaia Clish

Parameter Description

hello-interval Configures the interval between IPv6 PIM Hello messages that
{<1-21845> | are sent on a multicast-capable interface.
default} Hello messages are addressed to the IPv6 All-PIM-Routers
multicast group (FF01::2), so that PIM routers may discover
neighbors on a multi-access network.
Range: 1-21845 seconds
Default: 30 seconds

interface <Name Mandatory.


of Interface> Specifies the interface, on which to enable IPv6 PIM.

interface <Name Configures the IPv6 Designated Router (DR) priority advertised in
of Interface> the IPv6 PIM Hello messages that are sent on the interface.
dr-priority This is used for DR selection on a LAN.
{<0-4294967295> The router with the highest priority is selected as the designated
| default} router.
To break a tie, the DR is selected on the basis of the highest IP
address.
If even one router does not advertise a DR priority configured, the
DR election is based on the IP address.
Notes:
n To make sure that an IPv6 PIM neighbor supports DR
Priority:
a. Run this command in Gaia Clish on the Security
Gateway:
show ipv6 pim neighbor <IPv6
Address of Neighbor>
b. For neighbors that advertise a DR selection
priority value, this message appears in the
summary:
DRPriorityCapable Yes
n Because Gaia OS does not support IGMP for
unnumbered interfaces, it cannot function as a DR in
the presence of another router.

Range: 0-4294967295
Default: 1

interface <Name Disables (off) or enables (on) IPv6 PIM on the specified
of Interface> interface.
{off | on}

R82.10 Gaia Advanced Routing Administration Guide | 207


Configuring IPv6 PIM in Gaia Clish

Parameter Description

interface <Name Disables (off) or enables (on) the use of the IPv6 VRRP Virtual
of Interface> IP address on this interface:
virtual-address
{off | on}
n IPv6 PIM runs on this interface only after the router
becomes a VRRP Master after a failover.
n Creates the neighbor relationship with the IPv6 Virtual IP
address, if the router is a VRRP Master. The VRRP Master
in the VRRP pair sends Hello messages that include the
Virtual IP as the source address and processes PIM control
messages from routers that neighbor the VRRP pair.

Note - You cannot configure this option when ClusterXL is


enabled.
Range: off, or on
Default: off

interface-all- Disables IPv6 PIM on all interfaces.


off

jp-delay- Configures the maximum interval from the time when the unicast
interval {<1- Reverse Path Forwarding (RPF) neighbor (towards a source or
3600> | the RP) changes, and a triggered Join/Prune message is sent.
default} Range: 1-3600 seconds
Default: 5 seconds

jp-interval Configures the interval between sending Join/Prune messages.


{<1-3600> | Range: 1-3600 seconds
default} Default: 60 seconds

mode {sparse | Mandatory.


ssm} Configures the IPv6 PIM mode:
n sparse - Sparse Mode
n ssm - Source-Specific Multicast

register- Configures the mean interval between receipt of a register-stop


suppress- and the time when registers can be sent again.
interval {<60- A lower value means more frequent register bursts at the
3600> | rendezvous point.
default} A higher value means a longer join latency for new receivers.
Range: 60-3600 seconds
Default: 60

static-rp {off Disables (off) or enables (on) all IPv6 Static Rendezvous
| on} Points.

R82.10 Gaia Advanced Routing Administration Guide | 208


Configuring IPv6 PIM in Gaia Clish

Parameter Description

static-rp rp- Configures the IPv6 Static Rendezvous Point IP address.


address <IPv6 If an associated multicast group and prefix is not configured, the
address> {off | Static Rendezvous Point (RP) is considered to be responsible for
on} all IPv6 multicast groups (FF01::2).
This needs to be consistent with the RP information at other
routers in a multicast domain irrespective of the RP-
dissemination mechanism (bootstrap or autoRP) used.
Important:
n When you enable a Static Rendezvous Point, it
overrides the configuration from the Candidate
Rendezvous Point. If a multicast group matches
Rendezvous Points in both Static RP and Candidate
RP, then Gaia OS uses the Static RP.
n The Static RP overrides the RP information received
from other RP-dissemination mechanisms, such as
bootstrap routers.

Range: Any IPv6 address


Default: None

static-rp rp- Configures the IPv6 Multicast Group, for which this router is
address <IPv6 designated as the static rendezvous point.
address>
n <IPv6 address>
multicast-group
<IPv6 The multicast IPv6 address of the group(s) in CIDR
address>/< notation, for which this rendezvous point is responsible.
Subnet mask> Range: from [FF00]:[0000]: ... :[0000] to [FF0F]:[FFFF]: ... :
{off | on} [FFFF]
Default: None
n <Subnet mask>
The IPv6 mask length.
Range: 8-128
Default: None

unicast-bsm {on Disables (off) or enables (on) the sending and receiving of
| off} unicast bootstrap messages.

R82.10 Gaia Advanced Routing Administration Guide | 209


Monitoring and Troubleshooting IPv6 PIM

Monitoring and Troubleshooting IPv6 PIM


Monitoring IPv6 PIM in Gaia Portal
1. From the left navigation tree, click Advanced Routing > IPv6 PIM.
2. In the top right corner, click Monitoring.
3. In the IPv6 PIM Monitor section, click the Information category.

Note - The page is static. To see the latest values, click Reload.

Monitoring IPv6 PIM in Gaia Clish

Syntax for monitoring IPv6 PIM

show ipv6 pim


bootstrap
candidate-rp
group-rp-mapping <Multicast Group>
interface <Name of Interface>
interfaces
joins
detailed
group <Multicast Group> detailed
memory
neighbor <IPv6 PIM Neighbor>
neighbors
rps
sparse-mode-stats
stats
summary
timers
virtual-interfaces

Parameters for monitoring IPv6 PIM

Parameter Description

bootstrap Shows the IPv6 PIM Bootstrap Router status.

candidate-rp Shows the IPv6 PIM Candidate Rendezvous Point


status.

R82.10 Gaia Advanced Routing Administration Guide | 210


Monitoring and Troubleshooting IPv6 PIM

Parameter Description

group-rp-mapping <IPv6 Shows the IPv6 PIM Group-to-Rendezvous Point


Multicast Group> mapping.

interface <Name of Shows the status of the specified IPv6 PIM


Interface> interface.

interfaces Shows the status of all IPv6 PIM interfaces.

joins [detailed] Shows the IPv6 PIM Sparse-Mode join state for all
IPv6 Multicast Groups.

joins group <IPv6 Multicast Shows the IPv6 PIM Sparse-Mode join state for the
Group> [detailed] specified IPv6 Multicast Group.

memory Shows the IPv6 PIM memory usage.

neighbor <IPv6 PIM Shows the status of the specifiedIPv6 PIM


Neighbor> Neighbor.

neighbors Shows the status of all IPv6 PIM Neigbors.

rps Shows the IPv6 PIM Rendezvous Points.

sparse-mode-stats Shows the IPv6 PIM Sparse and SSM Mode


statistics.

stats Shows the IPv6 PIM statistics.

summary Shows the IPv6 PIM summary information.

timers Shows the timers.

virtual-interfaces Shows all IPv6 PIM virtual interfaces.

R82.10 Gaia Advanced Routing Administration Guide | 211


Monitoring and Troubleshooting IPv6 PIM

Troubleshooting IPv6 PIM


See "Trace Options" on page 672.
Need to enable the traces for all these modules:

Name in Gaia Name in Gaia


Related Chapter
Portal Clish

IPv6 PIM pim6 "IPv6 PIM" on page 185

IPv6 MFC mfc6 "Multicast Forwarding Cache (MFC)" on


page 730

MLD mld "Multicast Listener Discovery (MLD)" on


page 138

R82.10 Gaia Advanced Routing Administration Guide | 212


Static Multicast Routes

Static Multicast Routes


Note - PIM is the only protocol that uses static multicast routes.

Static multicast routes are used to provide a parent multicast protocol like PIM (see "PIM" on
page 155 and "IPv6 PIM" on page 185) a different set of nexthops to use for the RPF (reverse-
path-forwarding) checks.
When conducting an RPF check, these routes are examined first, and, if no nexthop is found,
the unicast routing table is examined.
PIM expects packets to arrive on the reverse-path forwarding (RPF) interface - the interface
used to reach the source of the multicast data.
PIM also checks the RPF to learn which interface it should use to send join/prune messages.
By default, PIM checks the unicast routing table to identify the RPF interface.
Static multicast routes provide an alternative route table to use for the RPF check.
If a static multicast route and a unicast route are available for a specific destination, PIM uses
the static multicast route.
Static multicast routes let PIM be independent of unicast routing.
This lets you deploy topologies in which multicast and unicast traffic flow over different paths.
For example, in order to balance the traffic load, you can separate the HTTP traffic from the
stock quotes traffic. You simply configure a static multicast route to the source network that
specifies a next hop gateway address different from the next hop address (for the same
source) in the unicast routing table.

R82.10 Gaia Advanced Routing Administration Guide | 213


Configuring Static Multicast Routes in Gaia Portal

Configuring Static Multicast Routes in Gaia


Portal
Important - In a Cluster, you must configure all the Cluster Members in the same way.

To add a static multicast route

1. From the left navigation tree, click Advanced Routing > Static Multicast Routes.
2. In the Static Multicast Routes section, click Add.
3. Configure the multicast destination parameters:
n In the Destination field, enter the IPv4 address.
n In the Subnet mask field, enter the IPv4 network mask.
4. In the Add Gateway section, configure the next hop gateways for the multicast route:
a. Click Add Gateway.
b. In the IPv4 Address field, enter the IPv4 unicast address of the next hop
gateway.
c. Optional: In the Priority field, enter the priority of this next hop gateway.
Description

The priority value defines which next hop gateway is selected as the nexthop,
when multiple next hop gateways are configured for the same static multicast
route.
n The lower the priority, the higher the preference.
n When multiple next hop gateways are configured with the same priority,
the one with the lower IPv4 address (for example, [Link] instead
of [Link]) is selected.
n next hop gateways with no priority configured are preferred over next
hop gateways with a configured priority value.
Range: None, or 1-8
Default: None (to set the default value, delete the current value 1-8)

d. Click OK.
5. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 214


Configuring Static Multicast Routes in Gaia Portal

To edit a static multicast route

1. From the left navigation tree, click Advanced Routing > Static Multicast Routes.
2. In the Static Multicast Routes section, select the route.
3. Click Edit.
4. Configure the applicable settings and click OK.
5. Click Save.

To delete a static multicast route

1. From the left navigation tree, click Advanced Routing > Static Multicast Routes.

2. In the Static Multicast Routes section, select the route.


3. Click Delete.

R82.10 Gaia Advanced Routing Administration Guide | 215


Configuring Static Multicast Routes in Gaia Clish

Configuring Static Multicast Routes in Gaia


Clish
Important - In a Cluster, you must configure all the Cluster Members in the same way.

n To see the available "set" commands for Static Multicast Routes, enter in Gaia Clish:

set static-mroute[Esc][Esc]

n To see the available "show" commands for Static Multicast Routes, enter in Gaia Clish:

show static-mroute[Esc][Esc]

Syntax

set static-mroute {<IPv4 Network Address>/<Subnet mask> |


default}
nexthop gateway address <IPv4 Address>
{off | on}
[priority {<1-8> | default} on]
off

Parameters

Parameter Description

static-mroute <IPv4 Configures the route to a destination IPv4 multicast


Network address.
Address>/<Subnet mask>
n <IPv4 Network Address>
The IPv4 multicast address of the network in
CIDR notation.
Range: Dotted-quad ([224-239].[0-255].[0-255].
[0-255])
Default: None
n <Subnet mask>
Mask length.
Range: 1-32
Default: None

static-mroute default Configures this route as default route.

R82.10 Gaia Advanced Routing Administration Guide | 216


Configuring Static Multicast Routes in Gaia Clish

Parameter Description

nexthop gateway n on - Configures and enables the IPv4 unicast


address <IPv4 Address> address of the next hop gateways for the multicast
{off | on} route.
n off - Disables the IPv4 unicast address of the
next hop gateways for the multicast route.

priority {<1-8> | Optional. Configures the priority of this next hop


default} on gateway.
The priority value defines which next hop gateway is
selected as the nexthop, when multiple next hop
gateways are configured for the same static multicast
route.
n The lower the priority, the higher the preference.
n When multiple next hop gateways are configured
with the same priority, the one with the lower IPv4
address (for example, [Link] instead of
[Link]) is selected.
n next hop gateways with no priority configured are
preferred over next hop gateways with a
configured priority value.
Range: 1-8, or default
Default: None

set static-mroute Disables the configured static multicast route.


{<IPv4 Network
Address>/<Subnet mask>
| default} off

R82.10 Gaia Advanced Routing Administration Guide | 217


Configuring Static Multicast Routes in Gaia Clish

To add or edit a static multicast route

1. Connect to the command line.


2. Log in to Gaia Clish.
3. Configure the multicast destination parameters:

set static-mroute {<IPv4 Network Address>/<Subnet mask> |


default}
nexthop gateway address <IPv4 Address>
on
[priority {<1-8> | default} on]

4. Save the configuration:

save config

To delete a next hop gateway in the static multicast route

1. Connect to the command line.


2. Log in to Gaia Clish.
3. Configure the multicast destination parameters:

set static-mroute {<IPv4 Network Address>/<Subnet mask> |


default} nexthop gateway address <IPv4 Address> off

4. Save the configuration:

save config

To delete a static multicast route completely

1. Connect to the command line.


2. Log in to Gaia Clish.
3. Configure the multicast destination parameters:

set static-mroute {<IPv4 Network Address>/<Subnet mask> |


default} off

4. Save the configuration:

save config

R82.10 Gaia Advanced Routing Administration Guide | 218


Monitoring Static Multicast Routes

Monitoring Static Multicast Routes


Monitoring Static Multicast Routes in Gaia Portal
1. From the left navigation tree, click Advanced Routing > Static Multicast Routes.
2. In the top right corner, click Monitoring.

Note - The page is static. To see the latest values, click Reload.

Monitoring Static Multicast Routes in Gaia Clish

show static-mroute

Troubleshooting IGMP
See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 219


RIP

RIP
The Routing Information Protocol (RIP) is one of the oldest, and still widely used, Interior
Gateway Protocols (IGP).
RIP uses only the number of hops between nodes to determine the cost of a route to a
destination network and does not consider network congestion or link speed.
Other shortcomings of RIP are that it can create excessive network traffic if there are a large
number of routes and that it has a slow convergence time and is less secure than other IGP,
such as OSPF.
Routers using RIP broadcast their routing tables on a periodic basis to other routers, whether
or not the tables have changed.

Each update contains paired values consisting of an IP network address and a distance to that
network.
The distance is expressed as an integer, the hop count metric. Directly connected networks
have a metric of 1. Networks reachable through one other router are two hops, and so on. The
maximum number of hops in a RIP network is 15 and the protocol treats anything equal to or
greater than 16 as unreachable.

R82.10 Gaia Advanced Routing Administration Guide | 220


RIPv1

RIPv1
Network Mask
RIP 1 derives the network mask of received networks and hosts from the network mask of the
interface from which the packet was received.
If a received network or host is on the same natural network as the interface over which it was
received, and that network is subnetted (the specified mask is more specific than the natural
network mask), then the subnet mask is applied to the destination.
If bits outside the mask are set, it is assumed to be a host. Otherwise, it is assumed to be a
subnet.

Auto Summarization
The Check Point implementation of RIPv1 supports auto summarization.
This allows the router to aggregate and redistribute non-classful routes in RIP v1.

R82.10 Gaia Advanced Routing Administration Guide | 221


RIPv2

RIPv2
The RIP version 2 protocol adds capabilities to RIP. Some of the most notable RIPv2
enhancements follow.

Network Mask
The RIPv1 protocol assumes that all sub-networks of a given network have the same network
mask.
It uses this assumption to calculate the network masks for all routes received.
This assumption prevents subnets with different network masks from being included in RIP
packets.

RIPv2 adds the ability to specify explicitly the network mask for each network in a packet.

Authentication
RIPv2 packets also can contain one of two types of authentication methods that can be used to
verify the validity of the supplied routing data.
The first method is a simple password in which an authentication key of up to 16 characters is
included in the packet.
If this password does not match what is expected, the packet is discarded.
This method provides very little security, as it is possible to learn the authentication key by
watching RIP packets.
The second method uses the MD5 algorithm to create a crypto checksum of a RIP packet and
an authentication key of up to 16 characters.

The transmitted packet does not contain the authentication key itself; instead, it contains a
crypto checksum called the digest.
The receiving router performs a calculation using the correct authentication key and discards
the packet if the digest does not match.
In addition, a sequence number is maintained to prevent the replay of older packets.
This method provides stronger assurance that routing data originated from a router with a valid
authentication key.

R82.10 Gaia Advanced Routing Administration Guide | 222


Configuring RIP in Gaia Portal

Configuring RIP in Gaia Portal


Important - In a Cluster, you must configure all the Cluster Members in the same way.

1. From the left navigation tree, click the Advanced Routing > RIP.
2. Optional: In the RIP Global Settings section, configure the applicable settings and click
Apply Global Settings.
Description

Parameter Description

Update Interval The amount of time between regularly scheduled RIP


updates.
To prevent synchronization of periodic updates, RIP updates
are actually sent at a time from the uniform distribution on the
interval (0.5*"Update Interval value", 1.5*"Update Interval
value").
Important - Be careful when you set this parameter,
because RIP has no protocol mechanism to detect
misconfiguration.
Range: 1-65535 seconds
Default: 30 seconds

Expire Interval The amount of time that must pass with no update for a given
route before the route is considered to have timed out.
Note - This value must be 6 times the Update Interval
before the network drops packets, which contain an
update.
Range: 1-65535 seconds
Default: 180 seconds

R82.10 Gaia Advanced Routing Administration Guide | 223


Configuring RIP in Gaia Portal

Parameter Description

Auto Applies only to RIP v1.


Summarization Controls whether to aggregate and redistribute automatically
the non-classful RIP v1 into RIP v2.
Important:
n If you do not select this option, you must use route

aggregation and route redistribution and configure


the aggregation and redistribution manually.
n Be careful when you configure this option, because

RIP protocol has no mechanism to detect


misconfiguration.
Range: Selected, or Cleared
Default: Selected

3. In the RIP Interfaces section, add the applicable interfaces.


a. Click Add.
b. In the Interface field, select the applicable interface.
c. In the Version field, select the RIP version.
Description

If you select v2, the default is to send full RIP v2 packets on the RIP multicast
address.
n Range: v1, or v2
n Default: v1

R82.10 Gaia Advanced Routing Administration Guide | 224


Configuring RIP in Gaia Portal

d. In the Metric field, enter the RIP metric.


Description

The RIP metric to add to routes that are sent with the specified interface(s).
This is used to make other routers prefer other sources of RIP routes over this
router.
A higher metric means routes appear more expensive.
Setting the metric to 0 or default removes the stored value.
n Range: None, or 1-16
n Default: None (to configure the default value, delete the current value 1-
16)

e. Select the Accept updates option.


Description

Controls if RIP packets from other routers, which use the interface, are accepted
or ignored.
Ignoring an update may result in suboptimal routing.
Range: Selected, or Cleared
Default: Selected

f. Select the Send updates option.


Description

Controls if RIP packets are sent through the interface.

If you do not select this option, the interface becomes a passive RIP listener.
Range: Selected, or Cleared
Default: Selected

R82.10 Gaia Advanced Routing Administration Guide | 225


Configuring RIP in Gaia Portal

g. Select the Virtual Address option.


Description

Applies only to VRRP Cluster.


Makes RIP run only on the VRRP Virtual IP address related to this interface.
If this router is not a VRRP Master, then RIP does not run, if this option is
selected. It only runs on the VRRP Master.
Make sure that VRRP is configured to accept connections to VRRP IP
addresses.

Note - You must use VRRP Monitored Circuit mode, when you
configure VRRP to work with Virtual IP addresses, and when you
configure Virtual IP support for a dynamic routing protocol, including
RIP.

Range: Selected, or Cleared


Default: Cleared

h. In the Transport field, select how to send the RIP packets.


Description

In the Multicast mode, RIP v2 packets are sent as multicast on this interface.
n Range: Multicast, or Broadcast
n Default: Multicast

R82.10 Gaia Advanced Routing Administration Guide | 226


Configuring RIP in Gaia Portal

i. In the Authentication Type field, select the authentication type.


Description

Applies only to RIP v2.


The type of authentication scheme to use for the link.
In general, routers on a given link must agree on the authentication configuration
in order to form neighbor adjacencies.
This is used to guarantee that routing information is accepted only from trusted
routers.
n None: There is no authentication scheme for the interface to accept routing
information from neighboring routers.
n Simple: Implements a simple authentication scheme for the interface to
accept routing information from neighboring routers.
In the Simple Password field, enter a password that contains from 1 to 16
characters.
These characters are supported:
l a-z
l A-Z
l 0-9
n MD5: Implements an authentication scheme that uses an MD5 algorithm
for the interface to accept routing information from neighboring routers.
In the MD5 Key field, enter a password that contains from 1 to 16
characters.

These characters are supported:


l a-z
l A-Z
l 0-9
l ` ~ ! @ # % ^ & * ( ) { } [ ] : ; , . _ - + =

Select the Cisco Compatibility option to ensure interoperability with Cisco


routers running RIP MD5 authentication.
By default, RIP MD5 is set to conform to the Check Point standard, and not
for Cisco compatibility.

R82.10 Gaia Advanced Routing Administration Guide | 227


Configuring RIP in Gaia Portal

n Range: None, Simple, or MD5


n Default: None

j. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 228


Configuring RIP in Gaia Clish

Configuring RIP in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

n To see the available "set" commands for RIP, enter in Gaia Clish:

set rip[Esc][Esc]

n To see the available "show" commands for RIP, enter in Gaia Clish:

show rip[Esc][Esc]

Syntax

set rip
auto-summary {off | on}
expire-interval {<1-65535. | default}
export-routemap <Name of RouteMap>
off
preference <Preference> on
import-routemap <Name of RouteMap>
off
preference <Preference> on
interface <Name of Interface>
[version {1 | 2} on]
accept-updates {off | on}
authtype
md5 secret <Password> [cisco-compatibility
{off | on}]
none
simple <Password>
metric {<0-16> | default}
{off | on}
send-updates {off | on}
transport {multicast | broadcast}
virtual-address {off | on}
update-interval {<1-65535> | default}

R82.10 Gaia Advanced Routing Administration Guide | 229


Configuring RIP in Gaia Clish

Parameters

The mandatory parameters are marked Mandatory. All other parameters are optional.

Parameter Description

auto-summary {off Applies only to RIP v1.


| on} Controls whether to aggregate and redistribute
automatically the non-classful RIP v1 into RIP v2.
Important:
n If you do not enable this option, you must use
route aggregation and route redistribution and
configure the aggregation and redistribution
manually.
n Be careful when you configure this option,
because RIP protocol has no mechanism to
detect misconfiguration.

Range: off, or on
Default: off

expire-interval The amount of time that must pass with no update for a
{<1-65535. | given route before the route is considered to have timed out.
default} Note - This value must be 6 times the Update Interval
before the network drops packets, which contain an
update.
Range: 1-65535 seconds
Default: 180 seconds

export-routemap Disables the configured Route Map for export policy.


<Name of RouteMap> See "Configuring Route Maps in Gaia Clish" on page 606.
off

export-routemap Configures preference the configured export Route Map.


<Name of RouteMap> Route Maps are applied in order of increasing preference
preference value.
<Preference> on Warning - Configuring an export Route Map for RIP
disables any route-redistribution configurations for
export to RIP. To ensure that RIP continues to advertise
routes according to prior redistribution policy, add
another Route Map to redistribute them.
See "Configuring Route Maps in Gaia Clish" on page 606.

import-routemap Disables the configured Route Map for import policy.


<Name of RouteMap> See "Configuring Route Maps in Gaia Clish" on page 606.
off

R82.10 Gaia Advanced Routing Administration Guide | 230


Configuring RIP in Gaia Clish

Parameter Description

import-routemap Configures preference the configured import Route Map.


<Name of RouteMap> Route Maps are applied in order of increasing preference
preference value.
<Preference> on Warning - Configuring an import Route Map for RIP
disables any inbound-route-filter configurations for
import into RIP. To ensure that RIP continues to learn
routes according to prior redistribution policy, add
another Route Map to redistribute them.
See "Configuring Route Maps in Gaia Clish" on page 606.

interface <Name of Disables (off) or enables (on) RIP on the specified


Interface> {off | interface.
on}

version {1 | 2} Configures the RIP version.


on] If you configure RIP v2, the default is to send full RIP v2
packets on the RIP multicast address.
n Range: 1, or 2
n Default: 1

accept-updates Controls if RIP packets from other routers, which use the
{off | on} interface, are accepted or ignored.
Ignoring an update may result in suboptimal routing.
Range: off, or on
Default: on

R82.10 Gaia Advanced Routing Administration Guide | 231


Configuring RIP in Gaia Clish

Parameter Description

authtype ... Applies only to RIP v2.


The type of authentication scheme to use for the link.
In general, routers on a given link must agree on the
authentication configuration in order to form neighbor
adjacencies.
This is used to guarantee that routing information is
accepted only from trusted routers.
n authtype md5 secret <Password> [cisco-
compatibility {off | on}]
Implements an authentication scheme that uses an
MD5 algorithm for the interface to accept routing
information from neighboring routers.
Password must contain from 1 to 16 characters.
These characters are supported:
l a-z

l A-Z

l 0-9

l ` ~ ! @ # % ^ & * ( ) { } [ ] : ; ,

. _ - + =
n authtype none
There is no authentication scheme for the interface to
accept routing information from neighboring routers.
n authtype simple <Password>
Implements a simple authentication scheme for the
interface to accept routing information from
neighboring routers.
Password must contain from 1 to 16 characters.
These characters are supported:
l a-z

l A-Z

l 0-9

metric {<0-16> | The RIP metric to add to routes that are sent with the
default} specified interface(s).
This is used to make other routers prefer other sources of
RIP routes over this router.
A higher metric means routes appear more expensive.
Setting the metric to 0 or default removes the stored value.
n Range: default, or 1-16
n Default: default (none)

R82.10 Gaia Advanced Routing Administration Guide | 232


Configuring RIP in Gaia Clish

Parameter Description

send-updates {off Controls if RIP packets are sent through the interface.
| on} If you do not enable this option, the interface becomes a
passive RIP listener.
Range: off, or on
Default: on

transport Controls how to send the RIP packets.


{multicast | In the Multicast mode, RIP v2 packets are sent as multicast
broadcast} on this interface.
n Range: multicast, or broadcast
n Default: multicast

virtual-address Applies only to VRRP Cluster.


{off | on} Makes RIP run only on the VRRP Virtual IP address related
to this interface.
If this router is not a VRRP Master, then RIP does not run, if
this option is selected. It only runs on the VRRP Master.
Make sure that VRRP is configured to accept connections to
VRRP IP addresses.
Note - You must use VRRP Monitored Circuit mode,
when you configure VRRP to work with Virtual IP
addresses, and when you configure Virtual IP support
for a dynamic routing protocol, including RIP.
Range: off, or on
Default: off

update-interval The amount of time between regularly scheduled RIP


{<1-65535> | updates.
default} To prevent synchronization of periodic updates, RIP updates
are actually sent at a time from the uniform distribution on
the interval (0.5*"Update Interval value", 1.5*"Update
Interval value").
Important - Be careful when you set this parameter,
because RIP has no protocol mechanism to detect
misconfiguration.
Range: 1-65535 seconds
Default: 30 seconds

R82.10 Gaia Advanced Routing Administration Guide | 233


VRRP Support for RIP

VRRP Support for RIP


Gaia supports the advertising of the Virtual IP address of the VRRP Virtual Router.
You can configure RIP to advertise the VRRP Virtual IP address rather than the actual IP
address of the interface.
If you enable this option, RIP runs only on the VRRP Master of the Virtual Router.
During a failover, RIP stops running on the old VRRP Master and then starts running on the
new VRRP Master.
A traffic break might occur during the time it takes both the VRRP and RIP protocols to learn
the routes again.

The greater the network, the more time it would take RIP to synchronize its database and
install routes again.

Note - Gaia also provides support for BGP, OSPF, and PIM, to advertise the VRRP
Virtual IP address. You must use VRRP Monitored Circuit mode when configuring
Virtual IP support for any dynamic routing protocol, including RIP.

R82.10 Gaia Advanced Routing Administration Guide | 234


Monitoring RIP

Monitoring RIP
Monitoring RIP in Gaia Portal
1. From the left navigation tree, click Advanced Routing > RIP.
2. In the top right corner, click Monitoring.
3. In the RIP Monitor section, click on the Information category.

Note - The page is static. To see the latest values, click Reload.

Monitoring RIP in Gaia Clish

show rip[Esc][Esc]

Troubleshooting RIP
See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 235


RIPng

RIPng
RIPng is an extension of RIP developed for support of IPv6.
In an international network, such as the Internet, it is very unlikely that a single routing protocol
will used for the entire network.
Rather, the network will be organized as a collection of Autonomous Systems (AS), each of
which will, in general, be administered by a single entity.
Each AS will have its own routing technology, which may differ among ASs.
The routing protocol used within an AS is referred to as an Interior Gateway Protocol (IGP).

A separate protocol, called an Exterior Gateway Protocol (EGP), is used to transfer routing
information among the ASs.
RIPng was designed to work as an IGP in moderate-size ASs. It is not intended for use in more
complex environments.
RIPng is intended to allow routers to exchange information for computing routes through an
IPv6-based network.
RIPng is one of a class of algorithms known as Distance Vector algorithms.
For more information, see RFC 2080.

R82.10 Gaia Advanced Routing Administration Guide | 236


Configuring RIPng in Gaia Portal

Configuring RIPng in Gaia Portal


Important - In a Cluster, you must configure all the Cluster Members in the same way.

1. From the left navigation tree, click the Advanced Routing > RIPng.
2. Optional: In the RIPng Global Settings section, configure the applicable settings and
click Apply Global Settings.
Description

Parameter Description

Update The amount of time between regularly scheduled RIPng updates.


Interval To prevent synchronization of periodic updates, RIPng updates are
actually sent at a time from the uniform distribution on the interval
(0.5*"Update Interval value", 1.5*"Update Interval value").
Important - Be careful when you set this parameter, because
RIPng has no protocol mechanism to detect misconfiguration.
Range: 1-65535 seconds
Default: 30 seconds

Expire Specifies how long in seconds a route is kept in the absence of a


Interval RIPng update message.
Note - This value must be 6 times the Update Interval to allow
for the possibility of lost updates.
Range: 1-65535 seconds
Default: 180 seconds

3. In the RIPng Interfaces section, add the applicable interfaces.


a. Click Add.
b. In the Interface field, select the applicable interface.

R82.10 Gaia Advanced Routing Administration Guide | 237


Configuring RIPng in Gaia Portal

c. In the Metric field, enter the RIPng metric.


Description

The RIPng metric to add to routes that are sent with the specified interface(s).
This is used to make other routers prefer other sources of RIPng routes over this
router.
A higher metric means routes appear more expensive.
Setting the metric to 0 or default removes the stored value.
n Range: None, or 1-16
n Default: None (to configure the default value, delete the current value 1-
16)

d. Select the Virtual Address option.


Description

Applies only to VRRP Cluster.


Makes RIPng run only on the VRRP Virtual IP address related to this interface.
If this router is not a VRRP Master, then RIPng does not run, if this option is
selected. It only runs on the VRRP Master.
Make sure that VRRP is configured to accept connections to VRRP IP
addresses.

Note - You must use VRRP Monitored Circuit mode, when you
configure VRRP to work with Virtual IP addresses, and when you
configure Virtual IP support for a dynamic routing protocol, including
RIP.

Range: Selected, or Cleared


Default: Cleared

e. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 238


Configuring RIPng in Gaia Clish

Configuring RIPng in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

n To see the available "set" commands for IPv6 RIPng, enter in Gaia Clish:

set ipv6 ripng[Esc][Esc]

n To see the available "show" commands for IPv6 RIPng, enter in Gaia Clish:

show ipv6 ripng[Esc][Esc]

Syntax

set ipv6 ripng


expire-interval {<1-65535. | default}
export-routemap <Name of RouteMap>
off
preference <Preference> on
import-routemap <Name of RouteMap>
off
preference <Preference> on
interface <Name of Interface>
metric VALUE
{off | on}
virtual-address {off | on}
update-interval VALUE

Parameters

The mandatory parameters are marked Mandatory. All other parameters are optional.

Parameter Description

expire-interval Specifies how long in seconds a route is kept in the absence


{<1-65535. | of a RIPng update message.
default} Note - This value must be 6 times the Update Interval to
allow for the possibility of lost updates.
Range: 1-65535 seconds
Default: 180 seconds

export-routemap Disables the configured Route Map for export policy.


<Name of RouteMap> See "Configuring Route Maps in Gaia Clish" on page 606.
off

R82.10 Gaia Advanced Routing Administration Guide | 239


Configuring RIPng in Gaia Clish

Parameter Description

export-routemap Configures preference the configured export Route Map.


<Name of RouteMap> Route Maps are applied in order of increasing preference
preference value.
<Preference> on Warning - Configuring an export Route Map for RIPng
disables any route-redistribution configurations for
export to RIP. To ensure that RIPng continues to
advertise routes according to prior redistribution policy,
add another Route Map to redistribute them.
See "Configuring Route Maps in Gaia Clish" on page 606.

import-routemap Disables the configured Route Map for import policy.


<Name of RouteMap> See "Configuring Route Maps in Gaia Clish" on page 606.
off

import-routemap Configures preference the configured export Route Map.


<Name of RouteMap> Route Maps are applied in order of increasing preference
preference value.
<Preference> on Warning - Configuring an import Route Map for RIPng
disables any inbound-route-filter configurations for
import into RIP. To ensure that RIPng continues to learn
routes according to prior redistribution policy, add
another Route Map to redistribute them.
See "Configuring Route Maps in Gaia Clish" on page 606.

interface <Name of Disables (off) or enables (on) RIPng on the specified


Interface> {off | interface.
on}

metric {<0-16> | The RIPng metric to add to routes that are sent with the
default} specified interface(s).
This is used to make other routers prefer other sources of
RIPng routes over this router.
A higher metric means routes appear more expensive.
Setting the metric to 0 or default removes the stored value.
n Range: default, or 1-16
n Default: default (none)

R82.10 Gaia Advanced Routing Administration Guide | 240


Configuring RIPng in Gaia Clish

Parameter Description

virtual-address Applies only to VRRP Cluster.


{off | on} Makes RIPng run only on the VRRP Virtual IP address
related to this interface.
If this router is not a VRRP Master, then RIPng does not run,
if this option is selected. It only runs on the VRRP Master.
Make sure that VRRP is configured to accept connections to
VRRP IP addresses.
Note - You must use VRRP Monitored Circuit mode,
when you configure VRRP to work with Virtual IP
addresses, and when you configure Virtual IP support
for a dynamic routing protocol, including RIP.
Range: off, or on
Default: off

update-interval The amount of time between regularly scheduled RIPng


{<1-65535> | updates.
default} To prevent synchronization of periodic updates, RIPng
updates are actually sent at a time from the uniform
distribution on the interval (0.5*"Update Interval value",
1.5*"Update Interval value").
Important - Be careful when you set this parameter,
because RIPng has no protocol mechanism to detect
misconfiguration.
Range: 1-65535 seconds
Default: 30 seconds

R82.10 Gaia Advanced Routing Administration Guide | 241


Monitoring RIPng

Monitoring RIPng
Monitoring RIPng in Gaia Portal
1. From the left navigation tree, click Advanced Routing > RIP.
2. In the top right corner, click Monitoring.
3. In the RIPng Monitor section, click on the Information category.

Note - The page is static. To see the latest values, click Reload.

Monitoring RIPng in Gaia Clish

show ipv6 ripng[Esc][Esc]

Troubleshooting RIPng
See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 242


IP Reachability Detection

IP Reachability Detection
The IP Reachability Detection feature uses the Bidirectional Forwarding Detection (BFD)
protocol or the ICMP ping to detect whether remote IP addresses are reachable.

Introducing Bidirectional Forwarding Detection (BFD)


From R80.20, the Gaia OS supports Bidirectional Forwarding Detection (BFD).
For more information, see RFC 5880 and RFC 5881.
n In a ClusterXL High Availability mode, only the Active member sends and accepts BFD
packets.
n In a VRRP cluster, only the Master member sends and accepts BFD packets.
n ClusterXL Standby and VRRP Backup cluster members do not send or accept BFD
packets. They treat all their peer cluster members as reachable.
From R80.30, the Gaia OS supports BFD in Static Routes. BFD for static routes uses BFD
protocol to monitor reachability of a BFD peer and updates the status of an associated static
route nexthop in accordance to the reachability status. The status of the static route nexthop is
"down", if that BFD peer is unreachable.

Note - Routing Event Trigger does not support VRRP Cluster.

R82.10 Gaia Advanced Routing Administration Guide | 243


Configuring IP Reachability Detection in Gaia Portal

Configuring IP Reachability Detection in Gaia


Portal
Important - In a Cluster, you must configure all the Cluster Members in the same way.

Best Practice - Do not use the IP Reachability Detection feature in combination with
the Graceful Restart feature in dynamic routing protocols, unless the routing protocols
support the BFD "c-Bit".

1. From the left navigation tree, click Advanced Routing > IP Reachability Detection.
2. In the Global Settings section, configure the applicable settings and click Apply.
Description

The Detect Multiplier, Minimum RX Interval and Minimum TX Interval settings, from
both sides, set the detection time (timeout) that BFD uses.
The Detect Multiplier and the Minimum Interval, multiplied together, make the timeout.

Best Practices:
n The calculated timeout should be at least 1 second, preferably 3

seconds (or more) for reliability. For more details, see RFC 5880.
n On Cluster Members, make sure the calculated timeout is longer than

the time necessary for the cluster to complete an unattended failover in


your environment. We recommend that you first test failover in your
environment.

These setting are global for all BFD sessions on a Security Gateway or VSX Virtual
System.

R82.10 Gaia Advanced Routing Administration Guide | 244


Configuring IP Reachability Detection in Gaia Portal

Parameters

Parameter Description

BFD Detect Configures the BFD detect multiplier that the system advertises.
Multiplier It determines the remote system timeout.
Smaller values produce quicker detection.
greater values produce better reliability.
If the remote peer's Detect Multiplier is 1, the detection time on a
Gaia gateway increases by 12.5% above the RFC 5880
specification, to improve reliability.
Range: 1-100
Default: 10
Recommended: At least 3

BFD Configures the BFD minimum RX interval that the system


Minimum RX advertises.
Interval It configures the local system timeout and the rate at which the
remote system transmits packets.
Smaller values produce quicker detection.
greater values reduce network load.
Range: 50-1000 milliseconds
Default: 300 milliseconds

BFD Configures the BFD minimum TX interval that this system


Minimum TX advertises.
Interval It configures the remote system timeout and the rate at which the
local system transmits packets.
Smaller values produce quicker detection.
greater values reduce network load.
Range: 50-1000 milliseconds
Default: 300 milliseconds

Ping Count This feature detects whether various remote IP addresses are
reachable using ICMP ping.
Specifies the number of missed packets (no ICMP Echo Reply) to
be tolerated in a row before the address is considered "not
reachable."
Range: 1-100
Default: 3

R82.10 Gaia Advanced Routing Administration Guide | 245


Configuring IP Reachability Detection in Gaia Portal

Parameter Description

Ping Interval This feature detects whether various remote IP addresses are
reachable using ICMP ping.
Specifies the interval between ICMP Echo Request packets that
are sent.
Range: 50-1000 seconds
Default: 3 seconds

3. In the Static Sessions section, add the applicable sessions.


a. Click Add.
b. In the Address Family field, select either IPv4 or IPv6.

c. In the Address field, enter the applicable IP address.

R82.10 Gaia Advanced Routing Administration Guide | 246


Configuring IP Reachability Detection in Gaia Portal

d. In the Type field, select the BFD type.


Singlehop BFD

Requires that the remote address be exactly one hop away (see RFC 5881).
BFD Singlehop Control packets use the UDP destination port 3784.
BFD Singlehop Control packets use the UDP source ports from 49152 to 65535.

Multihop BFD

Allows the remote address to be any number of hops away - even zero, although
this is seldom useful (see RFC 5883).
To support this extra versatility, with multihop BFD you must specify the Local
Address of this Gaia.
Multihop BFD only works if the remote and local IP addresses on the peers are
configured correctly:
n On Peer #1:
l The session IP address (remote IP address) is the local IP address
configured on Peer #2
l The session local IP address is the local IP address configured on
Peer #1
n On Peer #2:
l The session IP address (remote IP address) is the local IP address
configured on Peer #1
l The session local IP address is the local IP address configured on
Peer #2

BFD Multihop Control packets use the UDP destination port 4784.

Ping

Detects whether remote IP addresses are reachable using ICMP ping.


ICMP Echo packets use the UDP destination port 3785.

Note - BFD only works if both ends are configured to perform the same
BFD type - on both ends perform singlehop, on both ends perform
multihop, or on both ends perform ping.

e. Click Save.
4. In the BFD Authentication section, configure the applicable authentication settings.

R82.10 Gaia Advanced Routing Administration Guide | 247


Configuring IP Reachability Detection in Gaia Portal

Description

BFD can be authenticated on a given address range, with specified Authentication


Type, Key ID, and Shared Secret.
BFD authentication is disabled by default.
If BFD authentication is already enabled on the address range, you can add another
Key (up to ten) with a unique Key ID, or replace the configured Key.
For BFD authentication to work properly, you must configure the local and remote
BFD peers to:
n Both have authentication enabled.
n Have the same authentication type setting.
n Have the exact same set of Keys, with matching Key IDs and Shared Secrets.

Note - You can delete the configured BFD Authentication settings, including
keys and authentication type. In this case, if a greater, overlapping range is
configured for authentication, that range's settings are used.

Procedure

a. Click Add.
b. In the Address Family field, select either IPv4 or IPv6.
c. Configure whether BFD Authentication must apply to all IP addresses.

Otherwise, you explicitly configure the applicable IP address range.


n For IPv4: Select All IPv4 Addresses.
n For IPv6: Select All IPv6 Addresses.

R82.10 Gaia Advanced Routing Administration Guide | 248


Configuring IP Reachability Detection in Gaia Portal

d. Configure the applicable IP address range of the peer.


Configuration in the address range applies to any BFD sessions, whose remote
peer addresses are in the range.
If ranges overlap, the narrowest range takes precedence (for example:
[Link]/24 overrides [Link]/16).
For IPv4

In the Address field, enter the applicable IPv4 address.


In the Subnet mask field, enter the applicable IPv4 subnet mask. If not
specified explicitly, it defaults to the maximum of 32.
Examples:
n [Link]/0 - All IPv4 addresses
n [Link]/8 - Addresses from [Link] through [Link]
n [Link]/24 - Addresses from [Link] through [Link]
n [Link]/32 - A single address, [Link]
n [Link] - A single address, [Link]

For IPv6

In the IPv6 Address / Mask Length field, enter the applicable IPv6 address
and the Mask Length.
If the Mask Length is not specified explicitly, it defaults to the maximum of 128.
Examples:
n ::/0 - All IPv6 addresses (including link-local)
n fe80::/10 - All link-local addresses (requires interface)

R82.10 Gaia Advanced Routing Administration Guide | 249


Configuring IP Reachability Detection in Gaia Portal

e. In the Authentication Type field, select the authentication type.


For more information, see RFC 5880.
If you change the authentication type of a session, its existing keys are switched
to the new authentication type.
None

No authentication is used.
If you switch from another authentication type to this type, all keys are
removed and authentication is disabled for this range of peer addresses (even
if a greater, overlapping range is configured for authentication).

Meticulous MD5, or MD5

The use of these authentication types is strongly discouraged.


These authentication types use a 16-byte MD5 digest calculated over the
outgoing BFD Control packet, but the Key itself is not carried in the packet.
For Meticulous MD5, the sequence number is incremented on every packet.
For MD5, the sequence number is occasionally incremented.

Meticulous SHA1, or SHA1

These authentication types use a SHA1 hash calculated over the outgoing
BFD Control packet.

For Meticulous SHA1, the sequence number is incremented on every packet.


For SHA1, the sequence number is occasionally incremented.

Best Practice - Use one of these authentication types.

R82.10 Gaia Advanced Routing Administration Guide | 250


Configuring IP Reachability Detection in Gaia Portal

f. Configure the applicable Keys:


i. Click Add.
ii. In the Key ID field, enter the Key ID from 0 to 255.
Description

This number uniquely identifies the key, if more than one key is used.
BFD supports the use of multiple keys (up to ten).
Make sure that the Configures of keys (Key IDs and Shared Secrets) are
identical to those on the remote peer.

Note - Gaia transmits only the Key with the lowest Key ID
number. Gaia accepts packets with any key.

iii. The Enter secret as hex option:


n If this option is cleared (default), each ASCII character in the shared
secret represents one byte.
n If this option is selected, you specify the shared secret in
hexadecimal notation, with two hex digits to represent each byte.

Best Practice - Do not enable this option. The alternative hex


option is provided for versatility and interoperability, to support
special characters, such as single quote, double quote, and
others.

iv. In the Secret (or Hex Secret) field, enter the shared secret.
Description

n Supports only ASCII characters (example: "testing"), or Hex digits


(example: 74657374696e67).
Spaces are not allowed.
n For Meticulous MD5 and MD5 - The secret must contain from 1 to
16 characters. In Hex, must contain from 2 to 32 hex digits.
n For Meticulous SHA1 and SHA1 - The secret must contain from 1
to 20 characters. In Hex, must contain from 2 to 40 hex digits.
n Interoperability with other vendors may require that you limit the
secret length.
n The configured value is automatically padded to the full length with

R82.10 Gaia Advanced Routing Administration Guide | 251


Configuring IP Reachability Detection in Gaia Portal

null bytes.

v. Click OK.
g. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 252


Configuring IP Reachability Detection in Gaia Clish

Configuring IP Reachability Detection in Gaia


Clish
Important - In a Cluster, you must configure all the Cluster Members in the same way.

Best Practice - Do not use the IP Reachability Detection feature in combination with
the Graceful Restart feature in dynamic routing protocols, unless the routing protocols
support the BFD "c-Bit".
n To see the available "set" commands for IP Reachability Detection, enter in Gaia Clish:

set ip-reachability-detection[Esc][Esc]

n To see the available "show" commands for IP Reachability Detection, enter in Gaia
Clish:

show ip-reachability-detection[Esc][Esc]

Syntax

set ip-reachability-detection
bfd
address <IP Address>
authtype delete
authtype none
authtype {md5 | meticulous-md5 | sha1 | meticulous-
sha1} key <0-255>
hex-secret "<Hex Password>"
off
secret "<Password>"
enable-bfd multihop local-address <IPv4 Address>
enable-bfd off
enable-bfd on
detect-multiplier {<1-100> | default}
min-rx-interval {<50-1000> | default}
min-tx-interval {<50-1000> | default}
ping
address <IPv4 Address> enable-ping {off | on}
count {<1-100> | default}
interval {<1-100> | default}

R82.10 Gaia Advanced Routing Administration Guide | 253


Configuring IP Reachability Detection in Gaia Clish

Parameters

Parameter Description

bfd address <IP Configures the IP address range of the peer.


Address> Configuration in the address range applies to any BFD
sessions, whose remote peer addresses are in the
range.
If ranges overlap, the narrowest range takes
precedence (for example: [Link]/24 overrides
[Link]/16).
For IPv4
Specify the applicable IPv4 address and optionally the
IPv4 subnet mask.
If the subnet mask is not specified explicitly, it defaults
to the maximum of 32.
Examples:
n [Link]/0 - All IPv4 addresses
n [Link]/8 - Addresses from [Link] through
[Link]
n [Link]/24 - Addresses from [Link] through
[Link]
n [Link]/32 - A single address, [Link]
n [Link] - A single address, [Link]

For IPv6
Specify the applicable IPv6 address and optionally the
Mask Length.
If the Mask Length is not specified explicitly, it defaults
to the maximum of 128.
Examples:
n ::/0 - All IPv6 addresses (including link-local)
n fe80::/10 - All link-local addresses (requires
interface)

bfd address <IP Deletes the BFD authentication settings, including


Address> authtype keys and authentication type.
delete In this case, if a greater, overlapping range is
configured for authentication, that range's settings are
used.

R82.10 Gaia Advanced Routing Administration Guide | 254


Configuring IP Reachability Detection in Gaia Clish

Parameter Description

bfd address <IP No BFD authentication is used.


Address> authtype none If you switch from another authentication type to this
type, all keys are removed and authentication is
disabled for this range of peer addresses (even if a
greater, overlapping range is configured for
authentication).

bfd address <IP Configures the BFD Authentication type and key.
Address> authtype {md5
| meticulous-md5 | sha1 BFD Authentication
| meticulous-sha1} key BFD can be authenticated on a given address range,
<0-255> with specified Authentication Type, Key ID, and
Shared Secret.
BFD authentication is disabled by default.
If BFD authentication is already enabled on the
address range, you can add another Key (up to ten)
with a unique Key ID, or replace the configured Key.
For BFD authentication to work properly, you must
configure the local and remote BFD peers to:
n Both have authentication enabled.
n Have the same authentication type setting.
n Have the exact same set of Keys, with
matching Key IDs and Shared Secrets.

Note - You can delete the configured


BFD Authentication settings, including keys and
authentication type. In this case, if a greater,
overlapping range is configured for
authentication, that range's settings are used.

R82.10 Gaia Advanced Routing Administration Guide | 255


Configuring IP Reachability Detection in Gaia Clish

Parameter Description

BFD Authentication Types

n Meticulous MD5, or MD5


The use of these authentication types is
strongly discouraged.
These authentication types use a 16-byte MD5
digest calculated over the outgoing BFD
Control packet, but the Key itself is not carried
in the packet.
For Meticulous MD5, the sequence number is
incremented on every packet.
For MD5, the sequence number is
occasionally incremented.
n Meticulous SHA1, or SHA1
These authentication types use a SHA1 hash
calculated over the outgoing BFD Control
packet.
For Meticulous SHA1, the sequence number
is incremented on every packet.
For SHA1, the sequence number is
occasionally incremented.
Best Practice - Use one of these
authentication types.

BFD Authentication Key


This number uniquely identifies the key, if more than
one key is used.
BFD supports the use of multiple keys (up to ten).
Make sure that the Configures of keys (Key IDs and
Shared Secrets) are identical to those on the remote
peer.
Note - Gaia transmits only the Key with the
lowest Key ID number. Gaia accepts packets
with any key.
Range: 0-255
Default: None

R82.10 Gaia Advanced Routing Administration Guide | 256


Configuring IP Reachability Detection in Gaia Clish

Parameter Description

bfd address <IP Specifies the shared secret in hexadecimal notation,


Address> authtype with two hex digits to represent each byte.
<Type> key <0-255> hex- Best Practice - Do not enable this option. The
secret "<Hex Password>" alternative hex option is provided for versatility
and interoperability, to support special
characters, such as single quote, double quote,
and others.
n Supports only Hex digits (example:
"74657374696e67").
Spaces are not allowed.
n For Meticulous MD5 and MD5 - The secret
must contain from 2 to 32 hex digits.
n For Meticulous SHA1 and SHA1 - The secret
must contain from 2 to 40 hex digits.
n Interoperability with other vendors may require
that you limit the secret length.
n The configured value is automatically padded to
the full length with null bytes.

bfd address <IP Removes a BFD authentication key from the


Address> authtype configuration.
<Type> key <0-255> off Leaves other keys alone.
When you remove the last BFD authentication key
from an address range, then BFD uses the settings
from a broader overlapping address range (if any). If
there is none, then BFD operates without
authentication.
This can disable BFD authentication if no more keys
are left.

R82.10 Gaia Advanced Routing Administration Guide | 257


Configuring IP Reachability Detection in Gaia Clish

Parameter Description

bfd address <IP Specifies the shared secret, in which each ASCII
Address> authtype character represents one byte.
<Type> key <0-255>
secret "<Password>" Best Practice - Use this option.

n Supports only ASCII characters (example:


"testing").
Spaces are not allowed.
n For Meticulous MD5 and MD5 - The secret
must contain from 1 to 16 characters.
n For Meticulous SHA1 and SHA1 - The secret
must contain from 1 to 20 characters.
n Interoperability with other vendors may require
that you limit the secret length.
n The configured value is automatically padded to
the full length with null bytes.

bfd address <IP Enables multihop BFD for this IP address.


Address> enable-bfd Allows the remote address to be any number of hops
multihop local-address away - even zero, although this is seldom useful (see
<IPv4 Address> RFC 5883).
To support this extra versatility, with multihop BFD you
must specify the Local Address of this Gaia.
Multihop BFD only works if the remote and local IP
addresses on the peers are configured correctly:
n On Peer #1:
l The session IP address (remote IP

address) is the local IP address configured


on Peer #2
l The session local IP address is the local IP

address configured on Peer #1


n On Peer #2:
l The session IP address (remote IP

address) is the local IP address configured


on Peer #1
l The session local IP address is the local IP

address configured on Peer #2


BFD Multihop Control packets use the UDP
destination port 4784.

bfd address <IP Disables BFD completely for this IP address.


Address> enable-bfd off

R82.10 Gaia Advanced Routing Administration Guide | 258


Configuring IP Reachability Detection in Gaia Clish

Parameter Description

bfd address <IP Enables singlehop BFD for this IP address.


Address> enable-bfd on Requires that the remote address be exactly one hop
away (see RFC 5881).
BFD Singlehop Control packets use the UDP
destination port 3784.
BFD Singlehop Control packets use the UDP source
ports from 49152 to 65535.

bfd detect-multiplier Configures the BFD detect multiplier that the system
{<1-100> | default} advertises.
It determines the remote system timeout.
Smaller values produce quicker detection.
greater values produce better reliability.
If the remote peer's Detect Multiplier is 1, the detection
time on a Gaia gateway increases by 12.5% above the
RFC 5880 specification, to improve reliability.
This setting is global for all BFD sessions on a
Security Gateway or VSX Virtual System.
Range: 1-100
Default: 10
Recommended: At least 3

bfd min-rx-interval Configures the BFD minimum RX interval that the


{<50-1000> | default} system advertises.
It configures the local system timeout and the rate at
which the remote system transmits packets.
Smaller values produce quicker detection.
greater values reduce network load.
This setting is global for all BFD sessions on a
Security Gateway or VSX Virtual System.
Range: 50-1000 milliseconds
Default: 300 milliseconds

bfd min-tx-interval Configures the BFD minimum TX interval that this


{<50-1000> | default} system advertises.
It configures the remote system timeout and the rate
at which the local system transmits packets.
Smaller values produce quicker detection.
greater values reduce network load.
This setting is global for all BFD sessions on a
Security Gateway or VSX Virtual System.
Range: 50-1000 milliseconds
Default: 300 milliseconds

R82.10 Gaia Advanced Routing Administration Guide | 259


Configuring IP Reachability Detection in Gaia Clish

Parameter Description

ping address <IPv4 This feature detects whether various remote IP


Address> enable-ping addresses are reachable using ICMP ping.
{off | on} Disables (off) or enables (on) ICMP Echo for this
IP address.

ping count {<1-100> | This feature detects whether various remote IP


default} addresses are reachable using ICMP ping.
Specifies the number of missed packets (no ICMP
Echo Reply) to be tolerated in a row before the
address is considered "not reachable."
Range: 1-100
Default: 3

ping interval {<1-100> This feature detects whether various remote IP


| default} addresses are reachable using ICMP ping.
Specifies the interval between ICMP Echo Request
packets that are sent.
This setting is global for all BFD sessions on a
Security Gateway or VSX Virtual System.
Range: 50-1000 seconds
Default: 3 seconds

R82.10 Gaia Advanced Routing Administration Guide | 260


Monitoring IP Reachability Detection

Monitoring IP Reachability Detection


You can see the basic BFD settings (configured or default), and a table of the peer IP
addresses and their statuses.

Monitoring IP Reachability Detection in Gaia Portal


1. From the left navigation tree, click Advanced Routing > IP Reachability Detection.
2. In the top right corner, click Monitoring.
3. In the IP Reachability Detection Monitor section, click on the Information category.

Note - The page is static. To see the latest values, click Reload.

Monitoring IP Reachability Detection in Gaia Clish

show ip-reachability-detection[Esc][Esc]

Output example with the summary level of detail


MyGW> show ip-reachability-detection summary
BFD Minimum TX Interval: 300 ms
BFD Minimum RX Interval: 300 ms
BFD Detect Multiplier: 10
Remote Address Protocol Reachable
[Link] BFD No
[Link] BFD Yes
13::1 BFD Yes
34::4 BFD Yes
fe80::a1 (bond212) BFD Yes
MyGW>

Output example with the maximum level of detail

MyGW> show ip-reachability-detection ip-address [Link]

Field in the output Description

Remote Address [Link] IP address of the peer.

Protocol: BFD Is BFD used?

Reachable: No Is the peer reachable (according to


the BFD protocol state)?

Downtime: 0 days 0 hrs 2 mins 21 secs How long in current status (uptime or
downtime)?

BFD Protocol Details BFD protocol-specific data.

R82.10 Gaia Advanced Routing Administration Guide | 261


Monitoring IP Reachability Detection

Field in the output Description

Session State: 1 (Down) State, and if state is not Up, diagnostic


code.
Diagnostics: Local: 1 (Control Detection Time Expired)
Remote: 0 (No Diagnostic)

Advertised Min RX: 300 ms TX: 1000 ms Intervals advertised by us and the
Received Min RX: 0 ms TX: 300 ms Multiplier: 10 peer; detect multiplier advertised by
the peer (as in RFC 5880).

Detection Time: 3.0 sec Failure detection time. It is often


longer when the connection is already
down (as shown here) than when it is
up.
Rounded to the nearest tenth of a
second.

Rx Count: 223 last: 144728 ms ago BFD packets received for this
session: total count and time since the
last accepted packet.

Rx Drops by Reason: Count by reason of BFD packets


received but rejected.
These counters do not include
packets not received by the interface,
packets dropped by the Firewall,
invalid BFD packets, or unidentified
as part of the session.
Counts are reset on boot, when BFD
session is deleted, or if routed
restarts.

for authentication:

0 apparent config mismatch Mismatch: The two endpoints have


different authentication configurations
(mismatch of authentication type or
key ID).
For example, one uses BFD
authentication and the other does not.
You may see this when you change
configurations.

0 bad packet form Badly formatted authentication


section in an otherwise valid BFD
packet. Very rare.

0 sequence numbering Sequence number of a received


packet is out of order.
If you see this for a short time, it
indicates that a peer is reachable
again or that the configuration
changed.
If this count continuously increases, it
can indicate an attempted replay
attack.

204 message digest / password The received packet has an incorrect


message digest. This shows when the
two peers do not have the same
shared secret configured for BFD
authentication.

R82.10 Gaia Advanced Routing Administration Guide | 262


Monitoring IP Reachability Detection

Field in the output Description

0 for discriminator values The discriminator in a BFD packet


was zero, when that was not
permitted.
If you see this for a short time, it
indicates that a peer, which was not
reachable, is reachable again.

0 for TTL IPv4 Time to Live (TTL) field of the


packet was not equal to 255, as
required by RFC 5881.
Can indicate misconfiguration or
attempted attack (rare).

Tx Count: 226 (0 failed) last: 393 ms ago Count of BFD packets sent out of the
BFD module in this session, and when
was the last packet sent.
If the Firewall drops a packet, it is
counted here as transmitted and not
as failed.

Local Discriminator: 742320834 (0x2c3eeac2) A random, unique discriminator


identifies a BFD session, on a Gaia
machine.

UDP Source Port: 61244 The UDP source port, from which
BFD packets are sent by this host to
this peer.

Number of Transitions: 4 A record of recent transitions


Last 10 Transitions: (reachable or not reachable) with this
peer.
Current time is: Oct 30 12:58:05
The output shows the current date
State Time and time, for easy comparison with
Not Reachable Oct 30 12:55:44 the date and time of the events.
Reachable Oct 30 12:55:36
Not Reachable Oct 30 12:55:05
Reachable Oct 30 12:55:05

Troubleshooting IP Reachability Detection

See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 263


Monitoring IP Reachability Detection

IPsec Routing
Use IPsec Routing to configure static IPsec Security Associations (SA) in conjunction with
dynamic routing protocols.
When you configure a static SA in conjunction with a dynamic routing protocol, Gaia
encapsulates the routing protocol header in the packet of the configured IPsec protocols.
Benefits of IPsec Routing:
n Data integrity protection
n Data source authentication
n Data confidentiality
R82.10 supports IPsec Routing for:

Protocol Category Supported Protocol

IPsec Authentication Header (AH)

Dynamic Routing IPv6 OSPFv3

Configuring IPsec Routing in Gaia Portal


Important - In a Cluster, you must configure all the Cluster Members in the same way.

Configuring a new Security Association (SA)

1. From the left navigation tree, click Advanced Routing > IPsec Routing.
2. In the Security Associations section, click Add.
3. Configure the applicable settings:
a. In the SPI field, enter or select a number between 256 and 4294967295.
b. In the Integrity Algorithm field, select the applicable algorithm and enter the
applicable hash key.

Best Practice - Do not use weak algorithms MD5 or SHA1.

4. Click Save.
5. Use this SA in the OSPFv3 interface settings:

R82.10 Gaia Advanced Routing Administration Guide | 264


Monitoring IP Reachability Detection

a. From the left navigation tree, click Advanced Routing > IPv6 OSPF.
b. In the Interfaces section, add or edit an interface.
c. In the Security field, select IPsec.
d. In the Security Association field, select the applicable SA.
e. Click Save.
See "Configuring IPv6 OSPFv3 Interfaces in Gaia Portal" on page 348.

Editing an existing Security Association (SA)

1. From the left navigation tree, click Advanced Routing > IPsec Routing.
2. In the Security Associations section, select the applicable SA.

3. Click Edit.
4. Configure the applicable settings.
5. Click Save.

Deleting an existing Security Association (SA)

1. Remove this SA from the OSPFv3 settings of an applicable interface.


See "Configuring IPv6 OSPFv3 Interfaces in Gaia Portal" on page 348.
2. From the left navigation tree, click Advanced Routing > IPsec Routing.

3. In the Security Associations section, select the applicable SA.


4. Click Delete.

Configuring IPsec Routing in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

n To see the available "set" commands for IPsec Routing, enter in Gaia Clish:

set ipsec-routing[Esc][Esc]

n To see the available "show" commands for IPsec Routing, enter in Gaia Clish:

show ipsec-routing[Esc][Esc]

After you configure IPsec Routing, use the applicable SA in the OSPFv3 interface settings.
See "Configuring IPv6 OSPFv3 Interfaces in Gaia Clish" on page 362.

R82.10 Gaia Advanced Routing Administration Guide | 265


Monitoring IP Reachability Detection

Syntax

set ipsec-routing
spi <SPI> ah algorithm {md5 | sha1 | sha256 | sha384 |
sha512} key <Key>
off

Parameters

Parameter Description

spi <SPI> Configures the unique system-wide


Security Parameters Index (SPI).
Range: 256-4294967295
Default: None

ah algorithm {md5 | sha1 | Configures the IPsec Authentication


sha256 | sha384 | sha512} Header (AH) algorithm.
n md5 - Applies the HMAC-MD5-96
authentication
n sha1 - Applies the HMAC-SHA1-96
authentication
n sha256 - Applies the HMAC-SHA-
256-128 authentication
n sha384 - Applies the HMAC-SHA-
384-192 authentication
n sha512 - Applies the HMAC-SHA-
512-256 authentication

Best Practice - Do not use weak


algorithms MD5 or SHA1.

key <Key> Configures the IPsec Authentication


Header key.
n MD5 requires exactly 32
hexadecimal characters
n SHA1 requires exactly 40
hexadecimal characters
n SHA256 requires exactly 64
hexadecimal characters
n SHA384 requires exactly 96
hexadecimal characters
n SHA512 requires exactly 128
hexadecimal characters

R82.10 Gaia Advanced Routing Administration Guide | 266


Monitoring IP Reachability Detection

Parameter Description

off Removes the configuration for this


Security Association.

Monitoring IPsec Routing


Monitoring IPsec Routing in Gaia Portal
1. From the left navigation tree, click Advanced Routing > IPsec Routing.
2. In the top right corner, click Monitoring.

The Statistics section shows the Authentication Header (AH) data.

Note - The page is static. To see the latest values, click Reload.

Monitoring IPsec Routing in Gaia Clish


n To see the IPsec Routing statistics, run:

show ipsec-routing stats

n To see the OSPFv3 security setting on a specific interface, run:

show ipv6 ospf3 interface <Name of Interface> detailed

Refer to the section Security.

R82.10 Gaia Advanced Routing Administration Guide | 267


OSPF

OSPF
Open Shortest Path First (OSPF) is an Interior Gateway Protocol (IGP) used to exchange
routing information between routers within a single autonomous system (AS).
OSPF calculates the best path based on true costs using a metric assigned by a network
administrator.
RIP, the oldest IGP protocol chooses the least-cost path based on hop count.
OSPF is more efficient than RIP, has a quicker convergence, and provides equal-cost
multipath routing where packets to a single destination can be sent using more than one
interface.

OSPF is suitable for complex networks with a large number of routers. It can coexist with RIP
on a network.
You can run OSPF over a route-based VPN by enabling OSPF on a virtual tunnel interface
(VTI).
Gaia supports OSPFv2, which supports IPv4 addressing, and OSPFv3, which supports IPv6
addressing.
To learn about OSPFv3, see "IPv6 OSPF" on page 335.

R82.10 Gaia Advanced Routing Administration Guide | 268


Configuring IPv4 OSPFv2 Router ID

Configuring IPv4 OSPFv2 Router ID


The Router ID uniquely identifies the router in the autonomous system.
By default, Gaia Operating System selects the highest IPv4 address from all configured
interfaces.
The OSPFv2 protocol uses the Router ID.

Best Practice - Configure the Router ID explicitly, rather than relying on the default
setting. Setting the Router ID prevents the ID from changing if the default interface
used for the router ID goes down.
On a Security Gateway, use an address on a loopback interface that is not the
loopback address [Link] (configure an additional Loopback interface and
assign an IP address to it from the 128.0.0.x / 24 subnet - see the R82.10 Gaia
Administration Guide).
Important:
n Do not use the IP address [Link] as the Router ID.
n In a Cluster, you must configure the Router ID and you must configure its value
to one of the Cluster Virtual IP addresses.
In a Cluster, you must configure all the Cluster Members in the same way.

You can configure IPv4 OSPFv2 Router ID in Gaia Portal or Gaia Clish.
Configuring IPv4 OSPFv2 Router ID in Gaia Portal

To configure the Global Router ID


1. From the left navigation tree, click Advanced Routing > OSPF.
2. In the Instances section, select the Default instance.

3. In the Router ID section, enter the IPv4 address.


4. Click Apply Router ID.

To configure the Router ID for an OSPFv2 Instance


1. From the left navigation tree, click Advanced Routing > OSPF.
2. In the Instances section, select the instance (other than Default).
3. In the Router ID section, enter the IPv4 address.
4. Click Apply Router ID.

R82.10 Gaia Advanced Routing Administration Guide | 269


Configuring IPv4 OSPFv2 Router ID

Configuring IPv4 OSPFv2 Router ID in Gaia Clish

Syntax to configure the Global Router ID

set router-id {<IPv4 Address> | default}

Syntax to configure the Router ID for an OSPFv2 Instance

set ospf instance {<1-65535> | default} router-id {<IPv4


Address> | default}

Parameters

Parameter Description

instance {<1- Specifies an OSPF Instance ID to configure.


65535> | If you configure the Router ID for an OSPF Instance, this Router
default} ID overrides the Global Router ID configured on the system.

<IP Address> Specifies a specific IPv4 address in dotted-quad ([1-255].[1-255].


[1-255].[1-255]) format.

default Selects the highest interface address when OSPF is enabled.

Viewing IPv4 OSPFv2 Router ID in Gaia Clish

Syntax to view the Global Router ID

show router-id

Syntax to view the Router ID of an OSPFv2 Instance

show ospf instance {<1-65535> | default} router-id

Parameters

Parameter Description

instance {<1-65535> | default} Specifies an OSPF Instance ID to configure.

R82.10 Gaia Advanced Routing Administration Guide | 270


Configuring IPv4 OSPFv2 in Gaia Portal

Configuring IPv4 OSPFv2 in Gaia Portal


Important:
n In a Cluster, you must configure all the Cluster Members in the same way.
n Start the OSPF configuration from Router ID (see "Configuring IPv4 OSPFv2
Router ID" on page 269).
n Gaia Clish does not have commands for route filtering and redistribution. You
must configure inbound routing policies and redistribution of routes through the
Gaia Portal.
You can configure route maps and route aggregation using Gaia Clish
commands. Route map configuration done through the Gaia Clish takes
precedence over route filtering and redistribution configured in the Gaia Portal.
For example, if OSPF uses route maps for inbound filtering, anything configured
in the Gaia Portal for inbound route filters for OSPF is ignored. You can still use
the Gaia Portal to configure route redistribution into OSPF.

Procedure
1. From the left navigation tree, click Advanced Routing > OSPF.
2. Configure the Router ID.
See "Configuring IPv4 OSPFv2 Router ID" on page 269.
3. Optional: Configure additional OSPF Areas (in addition to the backbone area).

See "Configuring IPv4 OSPFv2 Areas in Gaia Portal" on page 276.


4. Configure the Global Options.
See "Configuring IPv4 OSPFv2 Global Options in Gaia Portal" on page 273.

5. Optional: For each OSPF Area, you can add one or more IPv4 address ranges, if you
want to reduce the number of routing entries that the OSPF Area advertises into the
OSPF backbone.

Note - To prevent an address range from being advertised into the backbone,
select the option Restrict for the address range

6. Configure OSPF Interfaces.


See "Configuring IPv4 OSPFv2 Interfaces in Gaia Portal" on page 285.
7. Optional: Configure the OSPF Instances.
See "Configuring IPv4 OSPFv2 Multiple Instances" on page 323.
8. Configure OSPF Virtual Links for any area that does not connect directly to the

R82.10 Gaia Advanced Routing Administration Guide | 271


Configuring IPv4 OSPFv2 in Gaia Portal

backbone area.
See "Configuring IPv4 OSPFv2 Virtual Links in Gaia Portal" on page 292.

R82.10 Gaia Advanced Routing Administration Guide | 272


Configuring IPv4 OSPFv2 Global Options in Gaia Portal

Configuring IPv4 OSPFv2 Global Options in Gaia Portal


Important - In a Cluster, you must configure all the Cluster Members in the same way.

1. From the left navigation tree, click Advanced Routing > OSPF.
2. In the Global Options section, click Edit Global Options.
3. Configure the applicable settings.
Description

Parameter Description

SPF Delay Configures the time to wait before recalculating the OSPF
routing table after a change in the topology.
Range: 1-60 seconds
Default: 2 seconds

SPF Hold Time Configures the minimum time between recalculations of the
OSPF routing table.
Range: 1-60 seconds
Default: 5 seconds

Default ASE Configures a default cost to use when routes from other
Route Cost protocols are redistributed into OSPF as Autonomous System
External (ASE) routes.
This default is ignored for any redistributed routes, which
already have a cost.
If the route has a cost already specified, that cost takes
precedent.
Range: 1-6777215
Default: 1

R82.10 Gaia Advanced Routing Administration Guide | 273


Configuring IPv4 OSPFv2 Global Options in Gaia Portal

Parameter Description

Default ASE Configures the default route type to use when routes from other
Route Type protocols are redistributed into OSPF as Autonomous System
External (ASE) routes.
This default is ignored for any redistributed routes, which
already have a type.
If the route has a type already specified, that type takes
precedent.
A type 1 route is internal and its metric can be used directly by
OSPF for comparison.
A type 2 route is external and is assumed to have a greater cost
than any internal route.
Range: Type 1, or Type 2
Default: 1

RFC 1583 Configures the RFC 1583 backward compatibility mode.


Compatibility This implementation of OSPF is based on RFC 2178, which
fixed some looping problems in earlier specifications.
Best Practice - If this implementation runs in an
environment with implementations based on RFC 1583 or
earlier, then enable this option to ensure backwards
compatibility.
Range: Selected, or Cleared
Default: Selected

Graceful Graceful Restart enables this router to act as a helper for other
Restart Helper routers when they undergo a graceful restart.
When a grace LSA is received from a neighbor, the neighbor is
kept in the forwarding path with full adjacency till either the
grace-period (advertised in the grace LSA) expires, or there is a
topology change.
The helper functionality is supported for both planned and
unplanned restarts.
Note - Graceful Restart is not compatible with VRRP
Preempt Mode. You must disable VRRP Preempt Mode
before you enable this option.
Range: Selected, or Cleared
Default: Cleared

R82.10 Gaia Advanced Routing Administration Guide | 274


Configuring IPv4 OSPFv2 Global Options in Gaia Portal

Parameter Description

Graceful Configures Graceful Restart for this router.


Restart n To disable, clear this option.
n To enable, select this option and configure the Grace

Period - enter a value between 1 and 1800 seconds. The


default grace period is 120 seconds.
The Graceful Restart option causes this router to act as a re-
starting router according to RFC 3623.
The re-starter functionality is supported for both planned and
unplanned restarts for both IPv4 OSPFv2 and IPv6 OSPFv3
when using VRRP and OSPFv3 only when using ClusterXL.
Notes:
n Graceful Restart is not compatible with VRRP

Preempt Mode. You must disable VRRP Preempt


Mode before you enable this option.
n In ClusterXL, the re-starter functionality is supported

for both planned and unplanned restarts for IPv6


OSPFv3 only.
n In VRRP Cluster, the re-starter functionality is

supported for both planned and unplanned restarts for


both IPv4 OSPFv2 and IPv6 OSPFv3.
Range: Selected, or Cleared
Default: Cleared

Force Hellos Enabling this feature sends out forced Hello packets at the
specified interval when the Dynamic Routing Daemon is busy
processing updates or synching data to standby nodes.
These extra Hello packets are in addition to the typical hello
packets in OSPF.
This feature is required to maintain neighbor adjacencies when
processing large number of updates.
n To disable, clear this option.
n To enable, select this option and configure the Force

Hellos Timer - enter a value between 2 and 10 seconds.


The timer is 5 seconds.
Range: Selected, or Cleared
Default: Cleared

4. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 275


Configuring IPv4 OSPFv2 Areas in Gaia Portal

Configuring IPv4 OSPFv2 Areas in Gaia Portal


In This Section:

Important - In a Cluster, you must configure all the Cluster Members in the same way.

For description of OSPFv2 Areas, see "IPv4 OSPF Types of Areas" on page 330.

Configuring a Normal Area


1. From the left navigation tree, click Advanced Routing > OSPF.

2. In the Areas section, click Add.


3. In the Area field, enter the OSPF Area ID.
Description

n For the backbone area, enter backbone.


(By default, the backbone area is enabled. You can disable the backbone area if
the system does not have interfaces on the backbone area.)
n For other areas, enter an ID in one of these formats:
l integer between 0 and 4294967295
l dotted quad form (example: [Link] for area id 1)

4. In the Area Type field, select Normal.


5. In the Address Ranges section, add the applicable IPv4 address ranges to be
advertised into the backbone area.
Description

An IPv4 address range is defined by a prefix and a mask length in CIDR notation
format (for example, [Link]/[Link]).
An area can be configured with any number of address ranges.
These ranges are used to reduce the number of routing entries that an area will emit
into the backbone area (and hence all areas).
If a given prefix aggregates a number of more specific prefixes within an area, then an
address range can be configured and will be the only prefix advertised into the
backbone.

R82.10 Gaia Advanced Routing Administration Guide | 276


Configuring IPv4 OSPFv2 Areas in Gaia Portal

Important - Pay attention when you configure an address range that includes
addresses, which are not contained within the area. If a range is marked as
restricted, then no advertisement is injected into the backbone.

Instructions

a. Click Add.
b. In the IPv4 address field, enter the IPv4 address range prefix (for example,
[Link]).
c. In the Subnet mask field, enter the IPv4 subnet mask (for example,
[Link]).
d. Optional: Select the Restrict option to blocks the given address range from
being advertised into the backbone area. Otherwise, the given address range is
advertised.
Range: Selected, or Cleared
Default: Cleared
e. Click OK.

6. In the Stub Networks section, add the applicable stub networks.


Description

A network address is defined by a prefix and a mask length in CIDR notation format
(for example, [Link]/[Link]).

OSPF can advertise routes of networks, which are not running OSPF by using a stub
network.

The advertised routes appear as OSPF internal routes, and can be filtered for export
at area borders using OSPF area ranges.
Any advertised network prefix must be directly connected to the router, where the stub
network is configured.
Meaning, one of the router's interface addresses must be within the network to be
included in the router LSA.
For OSPFv2, IPv4 Stub hosts may be configured by using a mask length of 32.
This feature also supports advertising a network that can be activated by the local
address of a point-to-point interface. To advertise reachability to such an network, you
must configure an IP address for the network along with a non-zero cost.

R82.10 Gaia Advanced Routing Administration Guide | 277


Configuring IPv4 OSPFv2 Areas in Gaia Portal

Instructions

a. Click Add.
b. In the IPv4 address field, enter the IPv4 address range prefix (for example,
[Link]).
c. In the Subnet mask field, enter the IPv4 subnet mask (for example,
[Link]).
d. Optional: In the Cost field, enter the cost associated with the stub network as
reached through this router.
The higher the cost, the less preferred the route.
Range: 1-65535

Default: 1
e. Click OK.

7. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 278


Configuring IPv4 OSPFv2 Areas in Gaia Portal

Configuring a Stub Area


1. From the left navigation tree, click Advanced Routing > OSPF.
2. In the Areas section, click Add.
3. In the Area field, enter the OSPF Area ID.
Description

Enter an ID in one of these formats:


n integer between 0 and 4294967295
n dotted quad form (example: [Link] for area id 1)

4. In the Area Type field, select Stub.


5. In the Cost for Default Route field, enter the routing cost associated with the default
route for this area.
Description

The higher the cost, the less preferred the route.


Range: 1-16777215
Default: 1

6. The Import Summary Routes option controls if this area is Totally-Stubby.


Description

A Totally-Stubby Area does not have Type 4 or Type 5 LSAs. It has only a single Type
3 LSA, which describes a default route.
n When this option is cleared, the area is Totally-Stubby.
n When this option is selected, the area is Not Totally-Stubby.
Range: Selected, or Cleared
Default: Selected

7. In the Address Ranges section, add the applicable IPv4 address ranges to be
advertised into the backbone area.
Description

An IPv4 address range is defined by a prefix and a mask length in CIDR notation
format (for example, [Link]/[Link]).
An area can be configured with any number of address ranges.

R82.10 Gaia Advanced Routing Administration Guide | 279


Configuring IPv4 OSPFv2 Areas in Gaia Portal

These ranges are used to reduce the number of routing entries that an area will emit
into the backbone area (and hence all areas).
If a given prefix aggregates a number of more specific prefixes within an area, then an
address range can be configured and will be the only prefix advertised into the
backbone.

Important - Pay attention when you configure an address range that includes
addresses, which are not contained within the area. If a range is marked as
restricted, then no advertisement is injected into the backbone.

Instructions

a. Click Add.

b. In the IPv4 address field, enter the IPv4 address range prefix (for example,
[Link]).
c. In the Subnet mask field, enter the IPv4 subnet mask (for example,
[Link]).
d. Optional: Select the Restrict option to blocks the given address range from
being advertised into the backbone area. Otherwise, the given address range is
advertised.
Range: Selected, or Cleared
Default: Cleared
e. Click OK.

8. In the Stub Networks section, add the applicable stub networks.


Description

A network address is defined by a prefix and a mask length in CIDR notation format
(for example, [Link]/[Link]).
OSPF can advertise routes of networks, which are not running OSPF by using a stub
network.
The advertised routes appear as OSPF internal routes, and can be filtered for export
at area borders using OSPF area ranges.
Any advertised network prefix must be directly connected to the router, where the stub
network is configured.
Meaning, one of the router's interface addresses must be within the network to be
included in the router LSA.
For OSPFv2, IPv4 Stub hosts may be configured by using a mask length of 32.

R82.10 Gaia Advanced Routing Administration Guide | 280


Configuring IPv4 OSPFv2 Areas in Gaia Portal

This feature also supports advertising a network that can be activated by the local
address of a point-to-point interface. To advertise reachability to such an network, you
must configure an IP address for the network along with a non-zero cost.

Instructions

a. Click Add.
b. In the IPv4 address field, enter the IPv4 address range prefix (for example,
[Link]).
c. In the Subnet mask field, enter the IPv4 subnet mask (for example,
[Link]).
d. Optional: In the Cost field, enter the cost associated with the stub network as
reached through this router.
The higher the cost, the less preferred the route.
Range: 1-65535
Default: 1
e. Click OK.

9. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 281


Configuring IPv4 OSPFv2 Areas in Gaia Portal

Configuring a Not So Stubby Area


1. From the left navigation tree, click Advanced Routing > OSPF.
2. In the Areas section, click Add.
3. In the Area field, enter the OSPF Area ID.
Description

Enter an ID in one of these formats:


n integer between 0 and 4294967295
n dotted quad form (example: [Link] for area id 1)

4. In the Area Type field, select NSSA.


5. In the Translator Role field, select how this router translates Type 7 LSAs into Type 5
LSAs.
Description

This option controls whether or not this NSSA Border Router unconditionally
translates Type 7 LSAs into Type 5 LSAs.
n When the value Always is selected, this router translates LSAs regardless of the
translator state of other NSSA routers.
n When configured as Candidate, this router participates in the translator election
to determine if it performs such duties.

If the NSSA router is not an Area Border Router, this option does not have any effect.
Range: Always, or Candidate

Default: Candidate

6. In the Translator Stability Interval field, enter the time.


Description

This time controls how long this Type 7 LSA translator continues to perform its
translator duties once it determined that it is no longer the elected translator.
Range: 1-655335 seconds
Default: 40 seconds

7. Select the Import Summary Routes option to import routes from Summary LSAs (Type 3
LSAs) into this area.

R82.10 Gaia Advanced Routing Administration Guide | 282


Configuring IPv4 OSPFv2 Areas in Gaia Portal

Description

OSPF routers send packets called Link State Advertisements (LSAs) to all adjacent
routers in an area.
Areas are smaller groups within the Autonomous System that can be defined in order
to limit the flooding of LSAs.
Many LSA types do not leave the area, from which they originated.
This increases efficiency and saves network bandwidth.
Type 3 LSAs are originated by Area Border Routers (ABRs) and are flooded to
adjacent routers in a given area.
Each Type 3 LSA describes a route to a network which is external to the area but is
internal to the local Autonomous System.
Range: Selected, or Cleared
Default: Selected

8. In the Default Route Type field, select the default route type.
Description

n A Type 1 route is internal and its metric can be used directly by OSPF for
comparison.
n A Type 2 route is external and is assumed to have a greater cost than any
internal route.

9. In the Cost for Default Route field, enter the routing cost associated with the default
route for this area.
Description

The higher the cost, the less preferred the route.


Range: 1-16777215
Default: 1

10. The Redistribution option controls which LSA types are originated by this router.
Description

When this option is selected, this router generates both Type 5 LSAs and Type 7
LSAs.
When this option is cleared, this router generates only Type 5 LSAs.
Range: Selected, or Cleared

R82.10 Gaia Advanced Routing Administration Guide | 283


Configuring IPv4 OSPFv2 Areas in Gaia Portal

Default: Selected

11. In the Type 7 Address Ranges section, add the applicable IPv4 address ranges to be
advertised into the backbone area.
Description

An IPv4 address range is defined by a prefix and a mask length in CIDR notation
format (for example, [Link]/[Link]).
An area can be configured with any number of address ranges.
These ranges are used to reduce the number of routing entries that an area will emit
into the backbone area (and hence all areas).
If a given prefix aggregates a number of more specific prefixes within an area, then an
address range can be configured and will be the only prefix advertised into the
backbone.

Important - Pay attention when you configure an address range that includes
addresses, which are not contained within the area. If a range is marked as
restricted, then no advertisement is injected into the backbone.

Instructions

a. Click Add.
b. In the IPv4 address field, enter the IPv4 address range prefix (for example,
[Link]).

c. In the Subnet mask field, enter the IPv4 subnet mask (for example,
[Link]).
d. Optional: Select the Restrict option to blocks the given address range from
being advertised into the backbone area. Otherwise, the given address range is
advertised.
Range: Selected, or Cleared
Default: Cleared
e. Click OK.

12. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 284


Configuring IPv4 OSPFv2 Interfaces in Gaia Portal

Configuring IPv4 OSPFv2 Interfaces in Gaia Portal


Important - In a Cluster, you must configure all the Cluster Members in the same way.

1. From the left navigation tree, click Advanced Routing > OSPF.
2. In the Interfaces section, click Add.
3. In the Interface field, select the applicable interface.
4. In the Area field, select the area to assign to this interface.

Note - An entry for the Backbone area appears even if it is disabled.

5. In the Hello Interval field, enter the time.


Description

Configures the delay time between Hello packets on this interface.


The OSPF Hello Protocol is responsible for establishing and maintaining adjacencies
(i.e. connections) between neighboring OSPF routers.
For broadcast networks, the Hello is also used to dynamically discover neighbors.

Important - For a given link, this value must be the same for all OSPF routers.

Range: 1-65535 seconds

Default: 10 seconds for broadcast networks, 30 seconds for point-to-point networks

6. In the Router Dead Interval field, enter the time.


Description

Configures the time after receipt of the last Hello packet, at which a neighbor is
declared dead.
Typically this is four times the Hello interval.

Important - For a given link, this value must be the same for all OSPF routers.

Range: 1-65535 seconds


Default: 40 seconds for broadcast networks, 120 seconds for point-to-point networks

7. In the Retransmit Interval field, enter the time.

R82.10 Gaia Advanced Routing Administration Guide | 285


Configuring IPv4 OSPFv2 Interfaces in Gaia Portal

Description

Configures the time between LSA retransmissions for this interface.


This value is also used when retransmitting database description and link state
request packets.
This value should be much higher than the expected round-trip delay between any two
routers on the network.
Being conservative helps avoid unnecessary retransmissions.

Important - For a given link, this value must be the same for all OSPF routers.

Range: 1-65535 seconds

Default: 5 seconds

8. In the Link Cost field, enter the cost of using the given interface for a route.
Description

The higher the cost, the less preferred the interface.


This is overridden by routing policy - Route Redistribution Rules and Route Maps.
Range: 1-65535
Default: 1

9. In the Election Priority field, enter the priority used in the Designated Router (DR)
election on the link.
Description

When two routers attempt to become the DR, the one with the higher priority is
elected.
However, if there is already an elected DR, then it continues as the DR regardless of
priority.
This prevents frequent changes in the DR state.
The priority is only applicable to shared-media like Ethernet.
A DR is not elected on point-to-point interfaces.
A router with priority 0 is not eligible to become the DR.
Range: 0-255
Default: 1

R82.10 Gaia Advanced Routing Administration Guide | 286


Configuring IPv4 OSPFv2 Interfaces in Gaia Portal

10. The Passive option controls the passive mode for this interface.
Description

When passive mode is enabled, the OSPF interface does not send Hello packets.
This means that the link does not form any adjacencies.
Passive mode enables the network associated with the interface to be included in the
intra-area route calculation rather than redistributing the network into OSPF and
having it as an Autonomous System External (ASE) route.
In passive mode, all interface configuration information, with the exception of the
associated area and the cost, is ignored.
Range: Selected, or Cleared

Default: Cleared (The interface sends Hello packets)

11. The Use Virtual Address option controls the VRRP mode for this interface.
Description
Important:
n Configure this option on VRRP Cluster Members when the given

interface is configured as a VRRP interface.


n Do not configure this option on ClusterXL Cluster Members.

When this option is enabled, OSPF uses the VRRP Virtual IP Address associated with
the VRRP interface instead of the physical IP address.

In addition, OSPF only runs when this router is the VRRP Master for the given
interface.
Range: Selected, or Cleared

Default: Cleared

12. The Subtract Authlen option controls whether to subtract the size of the authentication
information from the advertised interface MTU.
Description

Configure this option when peering over a Virtual Link with Gaia R76 or lower, or IPSO
4.x or lower (see "Configuring IPv4 OSPFv2 Virtual Links in Gaia Clish" on page 318).
These older routing daemons automatically subtract the size of the authentication
information from the advertised interface MTU, which leads to an MTU mismatch with
newer versions.
Range: Selected, or Cleared
Default: Cleared

R82.10 Gaia Advanced Routing Administration Guide | 287


Configuring IPv4 OSPFv2 Interfaces in Gaia Portal

13. The IP Reachability Detection option controls BFD (Bidirectional Forwarding Detection)
for each neighbor, from which it hears on this interface.
Description

Directs OSPF to start BFD (Bidirectional Forwarding Detection) for each neighbor,
from which it hears on this interface.
The BFD session is started only after OSPF transitions to 'Full' state with the neighbor.
Once the BFD session is up, OSPF responds to changes in BFD state.
If a neighbor does not have BFD configured or it does not respond to BFD control
packets, it does not impact OSPF operation. OSPF can operate with both BFD and
non-BFD neighbors on the same interface.

Before you enable this option, see "IP Reachability Detection" on page 243.
n Make sure the Firewall policy allows traffic to the UDP port 3784 in both
directions.
n Make sure the SmartConsole topology is correct (issues with incorrect Firewall
topology can cause anti-spoofing to interfere with BFD traffic).
Range: Selected, or Cleared
Default: Selected

14. In the Authentication section, configure the Authentication Mode.


Description

Authentication guarantees that routing information is accepted only from trusted


routers.

A message digest or message authentication code is included in outgoing OSPF


packets, so that receivers can authenticate these packets.

Important - Both OSPF sides must agree on these settings for the OSPF
authentication to work, and to form OSPF adjacencies.

R82.10 Gaia Advanced Routing Administration Guide | 288


Configuring IPv4 OSPFv2 Interfaces in Gaia Portal

Instructions

R82.10 Gaia Advanced Routing Administration Guide | 289


Configuring IPv4 OSPFv2 Interfaces in Gaia Portal

a. In the Authentication Mode field, select the applicable mode:

Mode Description

None Does not authenticate OSPF packets. This is the default


option.

Simple Authenticates OSPF packets with a simple password.


The simple password must contain from 1 to 8
alphanumeric ASCII characters.

R82.10 Gaia Advanced Routing Administration Guide | 290


Configuring IPv4 OSPFv2 Interfaces in Gaia Portal

Mode Description

Cryptographic Authenticates OSPF packets with MD5 or HMAC.


This OSPFv2 HMAC-SHA authentication (RFC 5709) is
backward-compatible with the OSPFv2 MD5
authentication.
For cryptographic authentication, at least one key needs
to be configured, with Key ID, Algorithm, and Secret.
If you configure multiple keys:
n When transmitting OSPF packets, Gaia uses the

key with the highest Key ID. Gaia includes a


message digest or message authentication code in
the outgoing OSPF packets to enable receivers to
authenticate them.
n When receiving OSPF packets, Gaia accepts all the

configured keys.
The available algorithms are listed in the decreasing
order of their cryptographic strength:
n hmac-sha-512 - Provides a cryptographic SHA-512

hash based on the configured secret.


n hmac-sha-384 - Provides a cryptographic SHA-384

hash based on the configured secret.


n hmac-sha-256 - Provides a cryptographic SHA-256

hash based on the configured secret. We


recommend this algorithm for best interoperability.
n hmac-sha-1 - Provides a cryptographic SHA-1

hash based on the configured secret.


n md5 - Provides a cryptographic MD5 hash based

on the configured key.


A shared secret (password) for cryptographic
authentication:
n For HMAC algorithms - Alphanumeric string from 1

to 80 characters. May not contain spaces or '\'


characters.
n For MD5 algorithm - Alphanumeric string from 1 to

16 characters. May not contain spaces or '\'


characters.

b. Click Save.

15. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 291


Configuring IPv4 OSPFv2 Virtual Links in Gaia Portal

Configuring IPv4 OSPFv2 Virtual Links in Gaia Portal


Important - In a Cluster, you must configure all the Cluster Members in the same way.

Description
The virtual link is effectively a tunnel across an adjacent non-backbone area, whose endpoint
must be any of the adjacent area's border routers that has an interface in the backbone area.
You must configure a virtual link for any area that does not connect directly to the backbone
area.
You configure the virtual link on both the ABR for the discontiguous area and another ABR that
does connect to the backbone.
The virtual link acts like a point-to-point link.
The routing protocol traffic that flows along the virtual link uses intra-area routing only.
If the router is an Area Border Router with no interfaces in the backbone area, a Virtual Link
must be configured to connect it to the backbone.
This link is effectively a tunnel across an adjacent Transit Area.
The other endpoint of the Virtual Link must be an OSPF router which has an interface
connected to the backbone, and which also has an interface connected to the Transit Area.

Procedure

1. From the left navigation tree, click Advanced Routing > OSPF.
2. In the Areas section, configure an OSPFv2 area to use as a Transit Area for this virtual
link.
Description

A Transit Area is the area shared between the two endpoint routers of the Virtual Link.
LSAs are sent to/from the backbone via this Transit Area.

3. In the Interfaces section, assign the applicable Transit Area to the applicable interface.
4. In the Virtual Links section, click Add.
5. In the Remote Router ID field, enter the Router ID of the other endpoint for this Virtual
Link (for example:[Link]).
6. In the Transit Area field, select the applicable area.
7. In the Hello Interval field, enter the time.

R82.10 Gaia Advanced Routing Administration Guide | 292


Configuring IPv4 OSPFv2 Virtual Links in Gaia Portal

Description

Configures the delay time between Hello packets on this interface.


The OSPF Hello Protocol is responsible for establishing and maintaining adjacencies
(i.e. connections) between neighboring OSPF routers.
For broadcast networks, the Hello is also used to dynamically discover neighbors.

Important - For a given link, this value must be the same for all OSPF routers.

Range: 1-65535 seconds


Default: 10 seconds for broadcast networks, 30 seconds for point-to-point networks

8. In the Router Dead Interval field, enter the time.


Description

Configures the time after receipt of the last Hello packet, at which a neighbor is
declared dead.
Typically this is four times the Hello interval.

Important - For a given link, this value must be the same for all OSPF routers.

Range: 1-65535 seconds


Default: 40 seconds for broadcast networks, 120 seconds for point-to-point networks

9. In the Retransmit Interval field, enter the time.


Description

Configures the time between LSA retransmissions for this interface.


This value is also used when retransmitting database description and link state
request packets.
This value should be much higher than the expected round-trip delay between any two
routers on the network.
Being conservative helps avoid unnecessary retransmissions.

Important - For a given link, this value must be the same for all OSPF routers.

Range: 1-65535 seconds


Default: 5 seconds

10. In the Authentication section, configure the Authentication Mode.

R82.10 Gaia Advanced Routing Administration Guide | 293


Configuring IPv4 OSPFv2 Virtual Links in Gaia Portal

Description

Authentication guarantees that routing information is accepted only from trusted


routers.
A message digest or message authentication code is included in outgoing OSPF
packets, so that receivers can authenticate these packets.

Important - Both OSPF sides must agree on these settings for the OSPF
authentication to work, and to form OSPF adjacencies.

R82.10 Gaia Advanced Routing Administration Guide | 294


Configuring IPv4 OSPFv2 Virtual Links in Gaia Portal

Instructions

R82.10 Gaia Advanced Routing Administration Guide | 295


Configuring IPv4 OSPFv2 Virtual Links in Gaia Portal

a. In the Authentication Mode field, select the applicable mode:

Mode Description

None Does not authenticate OSPF packets. This is the default


option.

Simple Authenticates OSPF packets with a simple password.


The simple password must contain from 1 to 8
alphanumeric ASCII characters.

R82.10 Gaia Advanced Routing Administration Guide | 296


Configuring IPv4 OSPFv2 Virtual Links in Gaia Portal

Mode Description

Cryptographic Authenticates OSPF packets with MD5 or HMAC.


This OSPFv2 HMAC-SHA authentication (RFC 5709) is
backward-compatible with the OSPFv2 MD5
authentication.
For cryptographic authentication, at least one key needs
to be configured, with Key ID, Algorithm, and Secret.
If you configure multiple keys:
n When transmitting OSPF packets, Gaia uses the

key with the highest Key ID. Gaia includes a


message digest or message authentication code in
the outgoing OSPF packets to enable receivers to
authenticate them.
n When receiving OSPF packets, Gaia accepts all the

configured keys.
The available algorithms are listed in the decreasing
order of their cryptographic strength:
n hmac-sha-512 - Provides a cryptographic SHA-512

hash based on the configured secret.


n hmac-sha-384 - Provides a cryptographic SHA-384

hash based on the configured secret.


n hmac-sha-256 - Provides a cryptographic SHA-256

hash based on the configured secret. We


recommend this algorithm for best interoperability.
n hmac-sha-1 - Provides a cryptographic SHA-1

hash based on the configured secret.


n md5 - Provides a cryptographic MD5 hash based

on the configured key.


A shared secret (password) for cryptographic
authentication:
n For HMAC algorithms - Alphanumeric string from 1

to 80 characters. May not contain spaces or '\'


characters.
n For MD5 algorithm - Alphanumeric string from 1 to

16 characters. May not contain spaces or '\'


characters.

b. Click Save.

11. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 297


Configuring IPv4 OSPFv2 in Gaia Clish

Configuring IPv4 OSPFv2 in Gaia Clish


Important:
n In a Cluster, you must configure all the Cluster Members in the same way.
n Start the OSPF configuration from Router ID (see "Configuring IPv4 OSPFv2
Router ID" on page 269).
n Gaia Clish does not have commands for route filtering and redistribution. You
must configure inbound routing policies and redistribution of routes through the
Gaia Portal.
You can configure route maps and route aggregation using Gaia Clish
commands. Route map configuration done through the Gaia Clish takes
precedence over route filtering and redistribution configured in the Gaia Portal.
For example, if OSPF uses route maps for inbound filtering, anything configured
in the Gaia Portal for inbound route filters for OSPF is ignored. You can still use
the Gaia Portal to configure route redistribution into OSPF.
n To see the available "set" commands for IPv4 OSPFv2, enter in Gaia Clish:

set ospf[Esc][Esc]

n To see the available "show" commands for IPv4 OSPFv2, enter in Gaia Clish:

show ospf[Esc][Esc]

n To see the available "restart" commands for IPv4 OSPFv2, enter in Gaia Clish:

restart ospf[Esc][Esc]

R82.10 Gaia Advanced Routing Administration Guide | 298


Configuring IPv4 OSPFv2 in Gaia Clish

Procedure
1. Connect to the command line.
2. Log in to Gaia Clish.
3. Configure the Router ID.
See "Configuring IPv4 OSPFv2 Router ID" on page 269.
4. Optional: Configure additional OSPF Areas (in addition to the backbone area).
See "Configuring IPv4 OSPFv2 Areas in Gaia Clish" on page 304.
5. Configure the Global Options.

See "Configuring IPv4 OSPFv2 Global Options in Gaia Clish" on page 300.
6. Optional: For each OSPF Area, you can add one or more IPv4 address ranges, if you
want to reduce the number of routing entries that the OSPF Area advertises into the
OSPF backbone.

Note - To prevent an address range from being advertised into the backbone,
select the option Restrict for the address range

7. Configure OSPF Interfaces.


See "Configuring IPv4 OSPFv2 Interfaces in Gaia Clish" on page 312.
8. Optional: Configure the OSPF Instances.

See "Configuring IPv4 OSPFv2 Multiple Instances" on page 323.


9. Configure OSPF Virtual Links for any area that does not connect directly to the
backbone area.

See "Configuring IPv4 OSPFv2 Virtual Links in Gaia Clish" on page 318.
10. Save the configuration:

save config

R82.10 Gaia Advanced Routing Administration Guide | 299


Configuring IPv4 OSPFv2 Global Options in Gaia Clish

Configuring IPv4 OSPFv2 Global Options in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

Global settings apply to all configured OSPF areas, including the backbone and stub areas.
Syntax

set ospf instance {<1-65535> | default}


default-ase-cost {<1-6777215> | default}
default-ase-type {1 | 2}
force-hellos
{off | on}
timer {<2-10> | default}
graceful-restart-helper {off | on}
graceful-restart
{off | on}
grace-period {<1-1800> | default}
{off | on}
rfc1583-compatibility {off | on}
spf-delay {<1-60> | default}
spf-holdtime {<1-60> | default}
set ospf
rfc1583-compatibility {off | on}
spf-delay {<1-60> | default}
spf-holdtime {<1-60> | default}

Parameters

Parameter Description

instance {<1- Specifies an OSPF Instance ID to configure.


65535> | default}

instance {<1- Disables (off) or enables (on) the specified OSPF Instance.
65535> | default}
{off | on}

R82.10 Gaia Advanced Routing Administration Guide | 300


Configuring IPv4 OSPFv2 Global Options in Gaia Clish

Parameter Description

default-ase-cost Configures a default cost to use when routes from other


{<1-6777215> | protocols are redistributed into OSPF as Autonomous
default} System External (ASE) routes.
This default is ignored for any redistributed routes, which
already have a cost.
If the route has a cost already specified, that cost takes
precedent.
Range: 1-6777215, or default
Default: 1

default-ase-type Configures the default route type to use when routes from
{1 | 2} other protocols are redistributed into OSPF as Autonomous
System External (ASE) routes.
This default is ignored for any redistributed routes, which
already have a type.
If the route has a type already specified, that type takes
precedent.
A type 1 route is internal and its metric can be used directly
by OSPF for comparison.
A type 2 route is external and is assumed to have a greater
cost than any internal route.
Range: 1, or 2
Default: 1

force-hellos Enabling this feature sends out forced Hello packets at the
{<options>} specified interval when the Dynamic Routing Daemon is busy
processing updates or synching data to standby nodes.
These extra Hello packets are in addition to the typical hello
packets in OSPF.
This feature is required to maintain neighbor adjacencies
when processing large number of updates.
Range: off, on, or timer
Default: off

force-hellos timer Configures the time between one forced OSPF Hello
{<2-10> | default} message to the next.
Range: 2-10 seconds
Default: 5 seconds

R82.10 Gaia Advanced Routing Administration Guide | 301


Configuring IPv4 OSPFv2 Global Options in Gaia Clish

Parameter Description

graceful-restart- Disables (off) or enables (on) the Graceful Restart Helper.


helper {off | on} Graceful Restart enables this router to act as a helper for
other routers when they undergo a graceful restart.
When a grace LSA is received from a neighbor, the neighbor
is kept in the forwarding path with full adjacency till either the
grace-period (advertised in the grace LSA) expires, or there
is a topology change.
The helper functionality is supported for both planned and
unplanned restarts.
Note - Graceful Restart is not compatible with VRRP
Preempt Mode. You must disable VRRP Preempt Mode
before you enable this option.
Range: off, or on
Default: off

graceful-restart Configures Graceful Restart for this router.


{off | on | grace-
period {<1-1800> |
n To disable, set it to off.
default}}
n To enable, set it to on.
n To configure the time, set a value between 1 and 1800
seconds. The default grace period is 120 seconds.
The Graceful Restart option causes this router to act as a re-
starting router according to RFC 3623.
The re-starter functionality is supported for both planned and
unplanned restarts for both IPv4 OSPFv2 and IPv6 OSPFv3
when using VRRP and OSPFv3 only when using ClusterXL.
Notes:
n Graceful Restart is not compatible with VRRP
Preempt Mode. You must disable VRRP Preempt
Mode before you enable this option.
n In ClusterXL, the re-starter functionality is
supported for both planned and unplanned restarts
for IPv6 OSPFv3 only.
n In VRRP Cluster, the re-starter functionality is
supported for both planned and unplanned restarts
for both IPv4 OSPFv2 and IPv6 OSPFv3.

R82.10 Gaia Advanced Routing Administration Guide | 302


Configuring IPv4 OSPFv2 Global Options in Gaia Clish

Parameter Description

rfc1583- Configures the RFC 1583 backward compatibility mode.


compatibility {off This implementation of OSPF is based on RFC 2178, which
| on} fixed some looping problems in earlier specifications.
Best Practice - If this implementation runs in an
environment with implementations based on RFC 1583
or earlier, then enable this option to ensure backwards
compatibility.
Range: off, or on
Default: on

spf-delay {<1-60> Configures the time to wait before recalculating the OSPF
| default} routing table after a change in the topology.
Range: 1-60 seconds
Default: 2 seconds

spf-holdtime {<1- Configures the minimum time between recalculations of the


60> | default} OSPF routing table.
Range: 1-60 seconds
Default: 5 seconds

R82.10 Gaia Advanced Routing Administration Guide | 303


Configuring IPv4 OSPFv2 Areas in Gaia Clish

Configuring IPv4 OSPFv2 Areas in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

For description of OSPFv2 Areas, see "IPv4 OSPF Types of Areas" on page 330.
The configuration is applicable to OSPF Multiple Instances (see "Configuring IPv4 OSPFv2
Multiple Instances" on page 323).
Description

An OSPF area defines a group of routers, which run OSPF and have complete topology
information for the given area.

An OSPF area uses an Area Border Router (ABR) to exchange routing information with
other areas via the backbone area.
Routes for a given area are summarized into the backbone area.
The backbone area then redistributes this summary information to other areas.
By definition, an ABR has interfaces to more than one area.
One of those areas must be either the backbone or an OSPF Virtual Link to the backbone.
OSPF forces a hub and spoke area topology, with the backbone area always being the hub.

R82.10 Gaia Advanced Routing Administration Guide | 304


Configuring IPv4 OSPFv2 Areas in Gaia Clish

Syntax

set ospf [instance {<1-65535> | default}] area <OSPF Area ID>


nssa
default-cost {<1-16777215> | default}
default-metric-type {1 | 2}
import-summary-routes {off | on}
{off | on}
range <IPv4 Address>/<Mask Length>
{off | on}
restrict {off | on}
redistribution {off | on}
translator-role {always | candidate}
translator-stability-interval {<1-65535> | default}
{off | on}
range <IPv4 Address>/<Mask Length>
{off | on}
restrict {off | on}
stub
default-cost {<1-16777215> | default}
{off | on}
summary {off | on}
stub-network <IPv4 Address>/<Mask Length>
{off | on}
stub-network-cost {<1-65535> | default}

Parameters

Parameter Description

set ospf Specifies an OSPF Area ID (for this OSPF Instance).


[instance {<1- Best Practice - Enter the area ID as a dotted quad. The
65535> | area ID [Link] is reserved for the backbone.
default}] Range:
area <OSPF Area
ID> n backbone
By default, the backbone area is enabled.
You can disable the backbone area if the system does not
have interfaces on the backbone area.
n integer between 1 and 4294967295
n dotted quad form (example: [Link] for area id 1)
Default: none

R82.10 Gaia Advanced Routing Administration Guide | 305


Configuring IPv4 OSPFv2 Areas in Gaia Clish

Parameter Description

set ospf Configures this area as a Not-So-Stubby Area.


[instance {<1- A Not-So-Stubby Area is an OSPF Stub Area, which can carry
65535> | routes learned by other protocols such as BGP or RIP.
default}]
area <OSPF Area Note - The backbone area cannot be an NSSA area.
ID> nssa

nssa default- Configures the routing cost associated with the default route for
cost {<1- this area.
16777215> | The higher the cost, the less preferred the route.
default} Range: 1-16777215, or default
Default: 1

nssa default- Configures the default route type for the Not-So-Stubby Area
metric-type {1 | (NSSA).
2}
n A type 1 route is internal and its metric can be used
directly by OSPF for comparison.
n A type 2 route is external and is assumed to have a
greater cost than any internal route.
Range: 1, or 2
Default: 1

nssa import- Disables (off) or enables (on) the import of routes from
summary-routes Summary LSAs (Type 3 LSAs) into this area.
{off | on} OSPF routers send packets called Link State Advertisements
(LSAs) to all adjacent routers in an area.
Areas are smaller groups within the Autonomous System that
can be defined in order to limit the flooding of LSAs.
Many LSA types do not leave the area from which they
originated.
This increases efficiency and saves network bandwidth.
Type 3 LSAs are originated by Area Border Routers (ABRs)
and are flooded to adjacent routers in a given area.
Each Type 3 LSA describes a route to a network which is
external to the area but is internal to the local Autonomous
System.
Range: off, or on
Default: on

R82.10 Gaia Advanced Routing Administration Guide | 306


Configuring IPv4 OSPFv2 Areas in Gaia Clish

Parameter Description

nssa {off | on} Removes (off) or configures (on) the Not-So-Stubby option
for this area.
Range: off, or on
Default: none

nssa range <IPv4 Removes (off), adds (on), or restricts (restrict) the OSPF
Address>/<Mask address range in this area.
Length>
{off | on |
n off - Removes the given address range from the list of
restrict {off | ranges to be advertised into the backbone area.
on}}
n on - Configures the given address range to be advertised
into the backbone area.
n restrict - Blocks (off) or allows (on) the given
address range from being advertised into the backbone
area.
An IPv4 address range is defined by a prefix and a mask length
in CIDR notation format (for example, [Link]/24).
An area can be configured with any number of address ranges.
These ranges are used to reduce the number of routing entries
that an area will emit into the backbone area (and hence all
areas).
If a given prefix aggregates a number of more specific prefixes
within an area, then an address range can be configured and
will be the only prefix advertised into the backbone.
Important - Pay attention when you configure an address
range that includes addresses, which are not contained
within the area. If a range is marked as restricted, then no
advertisement is injected into the backbone.
Range: off, on, or restrict
Default: none

nssa Controls if both Type 5 LSAs and Type 7 LSAs (on), or only
redistribution Type 5 LSAs (off) are originated by this router.
{off | on} This is only relevant when the router is an NSSA Border
Router.
Range: off, or on
Default: on

R82.10 Gaia Advanced Routing Administration Guide | 307


Configuring IPv4 OSPFv2 Areas in Gaia Clish

Parameter Description

nssa translator- Configures the translation of Type 7 LSAs into Type 5 LSAs.
role {always | Specifies whether or not this NSSA Border Router
candidate} unconditionally translates Type 7 LSAs into Type 5 LSAs.
n When configured as "always", this router translates
LSAs regardless of the translator state of other NSSA
routers.
n When configured as "candidate", this router
participates in the translator election to determine if it
performs such duties.
If the NSSA router is not an Area Border Router, this option
does not have any effect.
Range: always, or candidate
Default: candidate

nssa translator- Configures the Translator Stability Interval.


stability- This time controls how long this Type 7 LSA translator
interval {<1- continues to perform its translator duties once it determined
65535> | that it is no longer the elected translator.
default} Range: 1-655335 seconds, or default
Default: 40 seconds

set ospf Removes (off) or creates (on) the area and all related
[instance {<1- configuration.
65535> |
default}]
area <OSPF Area>
{off | on}

set ospf Configures an OSPF address range for this area.


[instance {<1- An IPv4 address range is defined by a prefix and a mask length
65535> | in CIDR notation format (for example, [Link]/24).
default}] An area can be configured with any number of address ranges.
area <OSPF Area> These ranges are used to reduce the number of routing entries
range <IPv4 that an area will emit into the backbone area (and hence all
Address>/<Mask areas).
Length> If a given prefix aggregates a number of more specific prefixes
within an area, then an address range can be configured and
will be the only prefix advertised into the backbone.
Important - Pay attention when you configure an address
range that includes addresses, which are not contained
within the area. If a range is marked as restricted, then no
advertisement is injected into the backbone.

R82.10 Gaia Advanced Routing Administration Guide | 308


Configuring IPv4 OSPFv2 Areas in Gaia Clish

Parameter Description

range <IPv4 Removes (off), adds (on), or restricts (restrict) the OSPF
Address>/<Mask address range in this area.
Length> {off |
on | restrict
n off - Removes the given address range from the list of
{off | on}} ranges to be advertised into the backbone area.
n on - Configures the given address range to be advertised
into the backbone area.
n restrict - Blocks (off) or allows (on) the given
address range from being advertised into the backbone
area.
Range: off, on, or restrict
Default: none

set ospf Configures this area as a Stub Area.


[instance {<1- Stub areas do not allow Type 5 LSAs to be propagated into or
65535> | throughout the area and instead depend on default routing for
default}] external destinations.
area <OSPF Area> You can configure an area as a Stub Area to reduce the
stub number of entries in the routing table.
Routes external to the OSPF domain are not added to the
routing table.

Note - The backbone area cannot be a stub area.

stub default- Configures the routing cost associated with the default route for
cost {<1- this area.
16777215> | The higher the cost, the less preferred the route.
default} Range: 1-16777215, or default
Default: 1

stub {off | on} Disables (off) or enables (on) this stub area:
n off - Reconfigures the given area to not be a Stub Area.
n on - Configures the given area to be a Stub Area.
Range: off, or on
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 309


Configuring IPv4 OSPFv2 Areas in Gaia Clish

Parameter Description

stub summary Disables (off) or enables (on) reception of summary LSAs into
{off | on} the area.
A Totally-Stubby Area does not have Type 4 or Type 5 LSAs.
It has only a single Type 3 LSA, which describes a default
route.
n When this option is disabled, the area is Totally-Stubby.
n When this option is enabled, the area is Not Totally-
Stubby.
Range: off, or on
Default: on

set ospf Configures a Stub Network for this area.


[instance {<1- A network address is defined by a prefix and a mask length in
65535> | CIDR notation format (for example, [Link]/24).
default}] OSPF can advertise routes of networks, which are not running
area <OSPF Area> OSPF by using a stub network.
stub-network The advertised routes appear as OSPF internal routes, and can
<IPv4 be filtered for export at area borders using OSPF area ranges.
Address>/<Mask Any advertised network prefix must be directly connected to the
Length> router, where the stub network is configured.
Meaning, one of the router's interface addresses must be within
the network to be included in the router LSA.
For OSPFv2, IPv4 Stub hosts may be configured by using a
mask length of 32.
For OSPFv3, IPv6 Stub hosts may be configured by using a
mask length of 128.
This feature also supports advertising a network that can be
activated by the local address of a point-to-point interface. To
advertise reachability to such an network, you must configure
an IP address for the network along with a non-zero cost.

stub-network Controls the stub network for this area:


<IPv4
Address>/<Mask
n off - Removes the given stub network from the given
Length> {off | area.
on}
n on - Adds the given stub network to the given area.
Range: off, or on
Default: none

R82.10 Gaia Advanced Routing Administration Guide | 310


Configuring IPv4 OSPFv2 Areas in Gaia Clish

Parameter Description

stub-network Configures the cost associated with the stub network as


<IPv4 reached through this router.
Address>/<Mask The higher the cost, the less preferred the route.
Length> Range: 1-65535, or default
stub-network- Default: 1
cost {<1-65535>
| default}

R82.10 Gaia Advanced Routing Administration Guide | 311


Configuring IPv4 OSPFv2 Interfaces in Gaia Clish

Configuring IPv4 OSPFv2 Interfaces in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

The configuration is applicable to OSPF Multiple Instances (see "Configuring IPv4 OSPFv2
Multiple Instances" on page 323).
Syntax

set ospf [instance {<1-65535> | default}] interface <Name of


Interface>
area <OSPF Area ID> {off | on}
authtype
cryptographic key <1-255> {off | algorithm
<Algorithm> secret "<Password>"}
{none | simple "<Password>"}
cost {<1-65535> | default}
dead-interval {<1-65535> | default}
hello-interval {<1-65535> | default}
ip-reachability-detection {off | on}
passive {off | on}
point-to-point {off | on}
priority <0-255> | default}
retransmit-interval {<1-65535> | default}
subtract-authlen {off | on}
virtual-address {off | on}

Parameters

Parameter Description

interface <Name of Specifies the name of the interface.


Interface>

area <OSPF Area ID> Disables (off) or enables (on) this OSPF area on the
{off | on} interface.

R82.10 Gaia Advanced Routing Administration Guide | 312


Configuring IPv4 OSPFv2 Interfaces in Gaia Clish

Parameter Description

authtype Disables (off) or enables (algorithm) the


cryptographic key cryptographic authentication with MD5 or HMAC.
<1-255> {off | Authentication guarantees that routing information is
algorithm accepted only from trusted routers. A message digest or
<Algorithm> secret message authentication code is included in outgoing
"<Password>"} OSPF packets, so that receivers can authenticate these
packets.
This OSPFv2 HMAC-SHA authentication (RFC 5709) is
backward-compatible with the OSPFv2 MD5
authentication.
Important - Both OSPF sides must agree on these
settings for the OSPF authentication to work, and to
form OSPF adjacencies.
For cryptographic authentication, at least one key needs
to be configured, with Key ID, Algorithm, and Secret.
If you configure multiple keys:
n When transmitting OSPF packets, Gaia uses the
key with the highest Key ID. Gaia includes a
message digest or message authentication code in
the outgoing OSPF packets to enable receivers to
authenticate them.
n When receiving OSPF packets, Gaia accepts all the
configured keys.

The available algorithms are listed in the decreasing order


of their cryptographic strength:
n hmac-sha-512 - Provides a cryptographic SHA-512
hash based on the configured secret.
n hmac-sha-384 - Provides a cryptographic SHA-384
hash based on the configured secret.
n hmac-sha-256 - Provides a cryptographic SHA-256
hash based on the configured secret. We
recommend this algorithm for best interoperability.
n hmac-sha-1 - Provides a cryptographic SHA-1 hash
based on the configured secret.
n md5 - Provides a cryptographic MD5 hash based on
the configured key.
A shared secret (password) for cryptographic
authentication:

R82.10 Gaia Advanced Routing Administration Guide | 313


Configuring IPv4 OSPFv2 Interfaces in Gaia Clish

Parameter Description

n For HMAC algorithms - Alphanumeric string from 1


to 80 characters. May not contain spaces or '\'
characters.
n For MD5 algorithm - Alphanumeric string from 1 to
16 characters. May not contain spaces or '\'
characters.

authtype {none | Disables (none) or enables (simple) the authentication.


simple "<Password>"} Authentication guarantees that routing information is
accepted only from trusted routers.
In general, all routers on an interface or link must agree
on the authentication settings to form adjacencies.
The simple password must contain from 1 to 8
alphanumeric ASCII characters.

cost {<1-65535> | Configures the cost of using the given interface for a
default} route.
The higher the cost, the less preferred the interface.
This is overridden by routing policy - Route Redistribution
Rules and Route Maps.
Range: 1-65535, or default
Default: 1

dead-interval {<1- Configures the time after receipt of the last Hello packet,
65535> | default} at which a neighbor is declared dead.
Typically this is four times the Hello interval.
Important - For a given link, this value must be the
same for all OSPF routers.
Range: 1-65535 seconds, or default
Default: 40 seconds for broadcast networks, 120 seconds
for point-to-point networks

R82.10 Gaia Advanced Routing Administration Guide | 314


Configuring IPv4 OSPFv2 Interfaces in Gaia Clish

Parameter Description

hello-interval {<1- Configures the delay time between Hello packets on this
65535> | default} interface.
The OSPF Hello Protocol is responsible for establishing
and maintaining adjacencies (i.e. connections) between
neighboring OSPF routers.
For broadcast networks, the Hello is also used to
dynamically discover neighbors.
Important - For a given link, this value must be the
same for all OSPF routers.
Range: 1-65535 seconds, or default
Default: 10 seconds for broadcast networks, 30 seconds
for point-to-point networks

ip-reachability- Directs OSPF to start BFD (Bidirectional Forwarding


detection {off | on} Detection) for each neighbor, from which it hears on this
interface.
The BFD session is started only after OSPF transitions to
'Full' state with the neighbor.
Once the BFD session is up, OSPF responds to changes
in BFD state.
If a neighbor does not have BFD configured or it does not
respond to BFD control packets, it does not impact OSPF
operation. OSPF can operate with both BFD and non-
BFD neighbors on the same interface.
Before you enable this option, see "IP Reachability
Detection" on page 243.
n Make sure the Firewall policy allows traffic to the
UDP port 3784 in both directions.
n Make sure the SmartConsole topology is correct
(issues with incorrect Firewall topology can cause
anti-spoofing to interfere with BFD traffic).
Range: off, or on
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 315


Configuring IPv4 OSPFv2 Interfaces in Gaia Clish

Parameter Description

passive {off | on} Disables (off) or enables (on) passive mode for this
interface.
When passive mode is enabled, the OSPF interface does
not send Hello packets.
This means that the link does not form any adjacencies.
Passive mode enables the network associated with the
interface to be included in the intra-area route calculation
rather than redistributing the network into OSPF and
having it as an Autonomous System External (ASE) route.
In passive mode, all interface configuration information,
with the exception of the associated area and the cost, is
ignored.
Range: off, or on
Default: off (The interface sends Hello packets)

point-to-point {off Disables (off) or enables (on) Point-to-Point Mode for


| on} the interface.
Use this on broadcast interfaces to skip DR election.
Default:off

priority <0-255> | Configures the priority used in the Designated Router


default} (DR) election on the link.
When two routers attempt to become the DR, the one with
the higher priority is elected.
However, if there is already an elected DR, then it
continues as the DR regardless of priority.
This prevents frequent changes in the DR state.
The priority is only applicable to shared-media like
Ethernet.
A DR is not elected on point-to-point interfaces.
A router with priority 0 is not eligible to become the DR.
Range: 0-255, or default
Default: 1

R82.10 Gaia Advanced Routing Administration Guide | 316


Configuring IPv4 OSPFv2 Interfaces in Gaia Clish

Parameter Description

retransmit-interval Configures the time between LSA retransmissions for this


{<1-65535> | interface.
default} This value is also used when retransmitting database
description and link state request packets.
This value should be much higher than the expected
round-trip delay between any two routers on the network.
Being conservative helps avoid unnecessary
retransmissions.
Important - For a given link, this value must be the
same for all OSPF routers.
Range: 1-65535 seconds, or default
Default: 5 seconds

subtract-authlen Configure this option when peering over a Virtual Link


{off | on} with Gaia R76 or lower, or IPSO 4.x or lower (see
"Configuring IPv4 OSPFv2 Virtual Links in Gaia Clish" on
page 318).
These older routing daemons automatically subtract the
size of the authentication information from the advertised
interface MTU, which leads to an MTU mismatch with
newer versions.
Range: off, or on
Default: off

virtual-address {off Disables (off) or enables (on) VRRP mode for this
| on} interface.
Important:
n Configure this option on VRRP Cluster
Members when the given interface is
configured as a VRRP interface.
n Do not configure this option on ClusterXL
Cluster Members.

When this option is enabled, OSPF uses the VRRP


Virtual IP Address associated with the VRRP interface
instead of the physical IP address.
In addition, OSPF only runs when this router is the VRRP
Master for the given interface.
Range: off, or on
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 317


Configuring IPv4 OSPFv2 Virtual Links in Gaia Clish

Configuring IPv4 OSPFv2 Virtual Links in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

Description

The virtual link is effectively a tunnel across an adjacent non-backbone area, whose
endpoint must be any of the adjacent area's border routers that has an interface in the
backbone area.
You must configure a virtual link for any area that does not connect directly to the backbone
area.
You configure the virtual link on both the ABR for the discontiguous area and another ABR
that does connect to the backbone.
The virtual link acts like a point-to-point link.
The routing protocol traffic that flows along the virtual link uses intra-area routing only.

The configuration is applicable to OSPF Multiple Instances (see "Configuring IPv4 OSPFv2
Multiple Instances" on page 323).
Syntax

set ospf [instance {<1-65535> | default}] area backbone


virtual-link <Router ID> transit-area <Area ID>
authtype cryptographic key <1-255> {off | algorithm
<Algorithm> secret "<Password>"}
authtype {none | simple "<Password>"}
dead-interval {<1-65535> | default}
hello-interval {<1-65535> | default}
{off | on}
retransmit-interval {<1-65535> | default}

Parameters

Parameter Description

set ospf instance {<1- Configures the backbone area.


65535> | default} area
backbone

R82.10 Gaia Advanced Routing Administration Guide | 318


Configuring IPv4 OSPFv2 Virtual Links in Gaia Clish

Parameter Description

set ospf instance {<1- Configures the virtual link and the transit area.
65535> | default} area If the router is an Area Border Router with no
backbone virtual-link interfaces in the backbone area, a Virtual Link
<Router ID> transit-area must be configured to connect it to the
<Area ID> backbone.
This link is effectively a tunnel across an
adjacent Transit Area.
The other endpoint of the Virtual Link must be
an OSPF router which has an interface
connected to the backbone, and which also has
an interface connected to the Transit Area.
A Transit Area is the area shared between the
two endpoint routers of the Virtual Link. LSAs
are sent to/from the backbone via this Transit
Area.
n <Router ID>
The Router ID of the other endpoint for this
Virtual Link (for example:[Link])
n <Area ID>
The Transit Area, which connects this
router to the other endpoint of the Virtual
Link.
Important - You must configure this area
before you configure its settings. Use the
"set ospf area" command.
Supported formats:
l An integer between 1 and

4294967295
l Dotted quad form (for example,

[Link] for area id 1)

R82.10 Gaia Advanced Routing Administration Guide | 319


Configuring IPv4 OSPFv2 Virtual Links in Gaia Clish

Parameter Description

virtual-link <Router ID> Disables (off) or enables (algorithm) the


transit-area <Area ID> cryptographic authentication with MD5 or
authtype cryptographic key HMAC.
<1-255> {off | algorithm Authentication guarantees that routing
<Algorithm> secret information is accepted only from trusted
"<Password>"} routers. A message digest or message
authentication code is included in outgoing
OSPF packets, so that receivers can
authenticate these packets.
This OSPFv2 HMAC-SHA authentication (RFC
5709) is backward-compatible with the OSPFv2
MD5 authentication.
Important - Both OSPF sides must agree
on these settings for the OSPF
authentication to work, and to form OSPF
adjacencies.
For cryptographic authentication, at least one
key needs to be configured, with Key ID,
Algorithm, and Secret.
If you configure multiple keys:
n When transmitting OSPF packets, Gaia
uses the key with the highest Key ID. Gaia
includes a message digest or message
authentication code in the outgoing OSPF
packets to enable receivers to
authenticate them.
n When receiving OSPF packets, Gaia
accepts all the configured keys.
The available algorithms are listed in the
decreasing order of their cryptographic strength:
n hmac-sha-512 - Provides a cryptographic
SHA-512 hash based on the configured
secret.
n hmac-sha-384 - Provides a cryptographic
SHA-384 hash based on the configured
secret.
n hmac-sha-256 - Provides a cryptographic
SHA-256 hash based on the configured
secret. We recommend this algorithm for
best interoperability.

R82.10 Gaia Advanced Routing Administration Guide | 320


Configuring IPv4 OSPFv2 Virtual Links in Gaia Clish

Parameter Description

n hmac-sha-1 - Provides a cryptographic


SHA-1 hash based on the configured
secret.
n md5 - Provides a cryptographic MD5 hash
based on the configured key.
A shared secret (password) for cryptographic
authentication:
n For HMAC algorithms - Alphanumeric
string from 1 to 80 characters. May not
contain spaces or '\' characters.
n For MD5 algorithm - Alphanumeric string
from 1 to 16 characters. May not contain
spaces or '\' characters.

virtual-link <Router ID> Disables (none) or enables (simple) the


transit-area <Area ID> authentication.
authtype {none | simple Authentication guarantees that routing
"<Password>"} information is accepted only from trusted
routers.
In general, all routers on an interface or link
must agree on the authentication settings to
form adjacencies.
The simple password must contain from 1 to 8
alphanumeric ASCII characters.

virtual-link <Router ID> Configures the time after receipt of the last Hello
transit-area <Area ID> packet, at which a neighbor is declared dead.
dead-interval {<1-65535> | Typically this is four times the Hello interval.
default} All routers on an interface must have the same
dead interval.
Range: 1-65535 seconds, or default
Default: 40 seconds for broadcast networks,
120 seconds for point-to-point networks

R82.10 Gaia Advanced Routing Administration Guide | 321


Configuring IPv4 OSPFv2 Virtual Links in Gaia Clish

Parameter Description

virtual-link <Router ID> Configures the delay time between Hello


transit-area <Area ID> packets on this Virtual Link.
hello-interval {<1-65535> | For a given link, this value must be the same for
default} all OSPF routers.
The OSPF Hello Protocol is responsible for
establishing and maintaining adjacencies (i.e.
connections) between neighboring OSPF
routers.
For broadcast networks, the Hello is also used
to dynamically discover neighbors.
Range: 1-65535 seconds, or default
Default: 10 seconds for broadcast networks, 30
seconds for point-to-point networks

virtual-link <Router ID> Removes (off) or creates (on) a Virtual Link.


transit-area <Area ID> {off
| on}

virtual-link <Router ID> Configures the time between LSA


transit-area <Area ID> retransmissions for this interface.
retransmit-interval {<1- This value is also used when retransmitting
65535> | default} database description and link state request
packets.
This value should be much higher than the
expected round-trip delay between any two
routers on the network.
Being conservative helps avoid unnecessary
retransmissions.
Range: 1-65535 seconds, or default
Default: 5 seconds

R82.10 Gaia Advanced Routing Administration Guide | 322


Configuring IPv4 OSPFv2 Multiple Instances

Configuring IPv4 OSPFv2 Multiple Instances


In This Section:

Introduction 323
Adding a New IPv4 OSPFv2 Instance 324
Deleting an Existing IPv4 OSPFv2 Instance 325
Restarting an IPv4 OSPFv2 Instance 326
Resetting IPv4 OSPFv2 Counters 327

Introduction
Multiple OSPF Instances let you separate OSPF into multiple OSPF domains.
Each instance contains a fully independent OSPF database, and routes from one domain are
not automatically advertised to another domain.
You can manually configure route maps to filter and redistribute routes from one domain into
another domain.
The redistributed routes show as OSPF external routes in the routing table of the other
domain.
If two different OSPF instances try to install the same route with equal cost, the route with the
lower next hop IP address is preferred.
If the routes have different costs, the route with the lower cost is selected.
Separate OSPF Instances do not share link state with one another, and will not pass routes
among themselves unless explicitly configured to do so using either Route Redistribution or
Routemaps.

R82.10 Gaia Advanced Routing Administration Guide | 323


Configuring IPv4 OSPFv2 Multiple Instances

Adding a New IPv4 OSPFv2 Instance


Note - To add more instances, the default instance must have at least one OSPF
interface configured and running.

To add a new IPv4 OSPFv2 instance in Gaia Portal

1. From the left navigation tree, click Advanced Routing > OSPF.
2. In the Instances section, click Add OSPF Instance.
3. In the Instance Number field, enter the Instance number from 1 to 65535.
4. Click OK.

To add a new IPv4 OSPFv2 instance in Gaia Clish

1. Connect to the command line.


2. Log in to Gaia Clish.
3. Add a new instance:

set ospf instance {<1-65535> | default} on

4. Save the configuration:

save config

R82.10 Gaia Advanced Routing Administration Guide | 324


Configuring IPv4 OSPFv2 Multiple Instances

Deleting an Existing IPv4 OSPFv2 Instance


To delete an IPv4 OSPFv2 instance in Gaia Portal

1. From the left navigation tree, click Advanced Routing > OSPF.
2. In the Instances section:
a. Select the instance.
b. Click Delete OSPF Instance.
c. Click OK to confirm.

To delete an IPv4 OSPFv2 instance in Gaia Clish

1. Connect to the command line.


2. Log in to Gaia Clish.
3. Delete the instance:

set ospf instance {<1-65535> | default} off

4. Save the configuration:

save config

R82.10 Gaia Advanced Routing Administration Guide | 325


Configuring IPv4 OSPFv2 Multiple Instances

Restarting an IPv4 OSPFv2 Instance


Restarting an IPv4 OSPFv2 Instance lets you clear OSPF database and restart OSPF
adjacency for an instance without restarting the Gaia RouteD daemon.
Important Notes
n Restarting any part of an OSPF protocol tears down all neighbor adjacencies
and brings them back up.
n The protocol's Graceful Restart mechanism does not take effect.
n Side effects of restarting an OSPF instance include:
l Loss of OSPF routes

l Traffic outage

l Network topology reconvergence

n In a ClusterXL or VRRP Cluster, restart of an OSPF instance does not trigger


a cluster failover.

To restart an IPv4 OSPFv2 instance in Gaia Portal

1. From the left navigation tree, click Advanced Routing > OSPF.
2. In the Instances section:
a. Select the OSPF Instance.
b. Click Restart OSPF Instance.

To restart an IPv4 OSPFv2 instance in Gaia Clish

1. Connect to the command line.


2. Log in to Gaia Clish.
3. Restart the OSPF Instance:

restart ospf instance {<1-65535> | default}

R82.10 Gaia Advanced Routing Administration Guide | 326


Configuring IPv4 OSPFv2 Multiple Instances

Resetting IPv4 OSPFv2 Counters


It is possible to reset IPv4 OSPFv2 statistics counters.
To reset IPv4 OSPFv2 counters in Gaia Portal

1. From the left navigation tree, click Advanced Routing > OSPF.
2. In the Instances section:
a. Select the OSPF Instance.
b. Click Reset Counters.
3. In the Reset Counters window:

a. Select the applicable option:


n All - To reset all OSPF counters.
n Packets - To reset only OSPF packet counters.
n Events - To reset only OSPF event counters.
n Errors - To reset only OSPF error counters. If you selected this option, it is
possible to select an OSPF interface (All, or a specific one) and an OSPF
neighbor (All, or a specific one).
b. Click Reset.

To reset IPv4 OSPFv2 counters in Gaia Clish

1. Connect to the command line.


2. Log in to Gaia Clish.

3. Reset the OSPF counters:

reset ospf instance {<1-65535> | default}


all
errors
all
interface <Name of Interface>
neighbor <IPv4 Address of OSPF Neighbor>
events
all
interface <Name of Interface>
packets

Parameters

R82.10 Gaia Advanced Routing Administration Guide | 327


Configuring IPv4 OSPFv2 Multiple Instances

Parameter Description

instance {<1- Specifies an OSPF Instance ID to configure.


65535> |
default}

all Resets all OSPF counters.

errors Resets only OSPF error counters:


<options>
n all
Resets all error counters for all OSPF interfaces in the outputs
of these commands:
l show ospf errors

l show ospf interfaces

l show ospf neighbors

n interface <Name of Interface>


Resets error counters for the specified OSPF interface in the
outputs of these commands:
l show ospf interfaces

l show ospf neighbors

n neighbor <IPv4 Address of OSPF Neighbor>


Resets error counters for the specified OSPF neighbor in the
output of the "show ospf neighbors" command

events Resets only OSPF event counters:


<options>
n all
Resets all event counters for all OSPF interfaces in the
outputs of these commands:
l show ospf events

l show ospf interfaces detailed

n interface <Name of Interface>


Resets event counters for the specified OSPF interface in the
output of the "show ospf interfaces detailed"
command

packets Resets only OSPF packet counters.

R82.10 Gaia Advanced Routing Administration Guide | 328


Monitoring IPv4 OSPFv2

Monitoring IPv4 OSPFv2


Monitoring IPv4 OSPF in Gaia Portal
1. From the left navigation tree, click Advanced Routing > OSPF.
2. In the top right corner, click Monitoring.
3. In the OSPF Monitor section, click on the Information category.

Note - The page is static. To see the latest values, click Reload.

Monitoring IPv4 OSPF in Gaia Clish

show ospf[Esc][Esc]

Troubleshooting IPv4 OSPF


See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 329


IPv4 OSPF Types of Areas

IPv4 OSPF Types of Areas


Routers using OSPF send packets called Link State Advertisements (LSA) to all routers in an
area.
Areas are smaller groups within the AS that you can design to limit the flooding of an LSA to all
routers.
LSAs do not leave the area from which they originated, thus increasing efficiency and saving
network bandwidth.
You must specify at least one area in your OSPF network - the backbone area, which has the
responsibility to propagate information between areas.

The backbone area has the identifier [Link].


You can designate other areas, depending on your network design, of the following types:

Area Type Description

Normal Neither a Stub Area, nor a Not-So-Stubby Area.


Allows all LSAs to pass through.
The backbone is always a normal area.

Stub Stub areas do not allow Type 5 LSAs to be propagated into or throughout
the area and instead depend on default routing for external destinations.
You can configure an area as a Stub Area to reduce the number of entries
in the routing table.
Routes external to the OSPF domain are not added to the routing table.

Note - The backbone area cannot be a stub area.

NSSA (Not NSSA is an OSPF Stub Area, which can carry routes learned by other
So Stubby protocols such as BGP or RIP.
Area) Allows the import of external routes in a limited fashion using Type-7 LSAs.
NSSA border routers translate selected Type 7 LSAs into Type 5 LSAs,
which can then be flooded to all Type-5 capable areas.
Best Practice - Configure an area as an NSSA, if you want to reduce
the size of the routing table, but still want to allow routes that are
redistributed to OSPF.

Note - The backbone area cannot be an NSSA area.

Best Practice - Limit OSPF areas to about 50 routers based on the limitations of
OSPF (traffic overhead, table size, convergence, and so on).

R82.10 Gaia Advanced Routing Administration Guide | 330


IPv4 OSPF Types of Areas

All OSPF areas must be connected to the backbone area. If you have an area that is not
connected to the backbone area, you can connect it by configuring a virtual link, enabling the
backbone area to appear contiguous despite the physical reality.

Note - If you need to connect two networks that both already have backbone areas
and you do not want to reconfigure one to something other than [Link], you can
connect the two backbone areas using a virtual link.

Each router records information about its interfaces when it initializes and builds an LSA
packet. The LSA contains a list of all recently seen routers and their costs. The LSA is
forwarded only within the area it originated in and is flooded to all other routers in the area. The
information is stored in the link-state database, which is identical on all routers in the AS.

R82.10 Gaia Advanced Routing Administration Guide | 331


IPv4 OSPFv2 Area Border Routers

IPv4 OSPFv2 Area Border Routers


Routers called Area Border Routers (ABR) have interfaces to multiple areas.
ABRs compact the topological information for an area and transmit it to the backbone area.
Check Point supports the implementation of ABR behavior as outlined in the Internet draft of
the Internet Engineering Task Force (IETF). The definition of an ABR in the OSPF
specification as outlined in RFC 2328 does not require a router with multiple attached areas to
have a backbone connection. However, under this definition, any traffic destined for areas that
are not connected to an ABR or that are outside the OSPF domain is dropped.
According to the Internet draft, a router is considered to be an ABR if it has more than one area
actively attached and one of them is the backbone area. An area is considered actively
attached if the router has at least one interface in that area that is not down.
Rather than redefine an ABR, the Check Point implementation includes in its routing
calculation summary LSAs from all actively attached areas if the ABR does not have an active
backbone connection, which means that the backbone is actively attached and includes at
least one fully adjacent neighbor. You do not need to configure this feature; it functions
automatically under certain topographies.
IPv4 OSPF uses the following types of routes:
n Intra-area - Have destinations within the same area.
n Interarea - Have destinations in other OSPF areas.
n Autonomous system external (ASE) - Have destinations external to the autonomous
system (AS). These are the routes calculated from Type 5 LSAs.
n NSSA ASE Router - Have destinations external to AS. These are the routes calculated
from Type 7 LSAs.

All routers on a link must agree on the configuration parameters of the link. All routers in an
area must agree on the configuration parameters of the area. A separate copy of the SPF
algorithm is run for each area. Wrong configurations prevent adjacencies from forming
between neighbors, and routing black holes or loops can form.

R82.10 Gaia Advanced Routing Administration Guide | 332


Cluster Support for IPv4 OSPFv2

Cluster Support for IPv4 OSPFv2


Gaia supports the IPv4 OSPFv2 protocol in ClusterXL and VRRP Cluster.
In this configuration, the cluster becomes a Virtual Router.
The neighbor routers see it as a single router, where the Virtual IP address of the cluster
becomes the router ID.
Each Cluster Member runs the OSPF process, but only RouteD daemon in the master state
actively exchanges routing information with the neighbor routers.
When a cluster failover occurs, RouteD daemon on another Cluster Member becomes the
master and begins exchanging routing information with the neighbor routers.

Gaia also supports the OSPF protocol over VPN tunnels, which terminate in ClusterXL or
VRRP Cluster.

ClusterXL
Gaia ClusterXL advertises the Cluster Virtual IP address. The OSPF routes database of the
master is synchronized across all members of the cluster.
The OSPF task of each Cluster Member obtains routing state and information from the master
and installs the routes in the kernel as the master does.
During a cluster failover, RouteD daemon on one of the peer Cluster Members becomes the
new master and then continues where the old master failed.

During the time that the new master resynchronizes routes database with the neighbor routers,
traffic forwarding continues using the old kernel routes until OSPF routes are fully
synchronized and pushed into the kernel.

VRRP Cluster
Gaia supports advertising of the VRRP Virtual IP address instead of the actual interface IP
address.
If you enable this option, but do not enable OSPF Graceful Restart, OSPF runs only on the
VRRP Master.
During a cluster failover, a traffic break may occur, while the new VRRP Master becomes
active and learns the OSPF routes.
This happens because the OSPF route database exists only on the VRRP Master and is not
synchronized on all VRRP Cluster Members.
The larger the network, the larger the OSPF database and the more time it takes OSPF to
synchronize its database and install routes again.
To avoid traffic loss during failovers, you can configure OSPF Graceful Restart.

R82.10 Gaia Advanced Routing Administration Guide | 333


Cluster Support for IPv4 OSPFv2

In this case, the VRRP Master synchronizes the route table with the VRRP Backup members.
If the VRRP Master fails, one of the VRRP Backup members takes on a role of the new VRRP
Master, sends grace-LSAs to the OSPF neighbors, and establishes adjacencies with them.
The new VRRP Master keeps the kernel routes that were installed before the failover until it
establishing full adjacency with the neighbors.

Note - You must use VRRP Monitored-Circuit, when configuring Virtual IP support for
OSPF or any other dynamic routing protocol.

R82.10 Gaia Advanced Routing Administration Guide | 334


IPv6 OSPF

IPv6 OSPF
Open Shortest Path First (OSPF) is a link-state routing protocol that calculates forwarding
tables in an IP-based network.
OSPF is the preferred Interior Gateway Protocol (IGP) for Check Point.
OSPF supports IPv6. OSPF for IPv6 is also referred to as OSPF version 3 (OSPFv3). OSPFv3
is defined in RFC 5340 (which makes RFC 2740 obsolete).
OSPFv3 is supported by both ClusterXL and VRRP clusters.
The IPv6 address which appears in the source of OSPFv3 packets sent on the interface must
be a link-local address, that is, an FE80::/64 address.

A link-local address is automatically added to each interface when IPv6 is enabled on Gaia.
The address is unique per interface and has this format:
n Bytes 0-1: FE:80.
n Bytes 2-7: Zeros.
n Bytes 8-10: 00:1C:7F (Check Point OUI).
n Byte 11: Zeros.
n Bytes 12-15: IPv4 Cluster Virtual IP address
You can override the automatic Link-Local address with manual configuration. The addresses
are used for next hops, to advertise routes, and to send Hello messages. OSPFv3 advertises
the IPv6 addresses defined by the user, but OSPFv3exchanges routes which use the FE80
addresses. A /64 address is required by the OSPFv3 protocol. If the peer router does not use
an FE80::/64 address, OSPFv3 does not work.

OSPFv2 is used with IPv4. See "OSPF" on page 268.

R82.10 Gaia Advanced Routing Administration Guide | 335


Configuring IPv6 OSPFv3 Router ID

Configuring IPv6 OSPFv3 Router ID


The Router ID uniquely identifies the router in the autonomous system.
By default, Gaia Operating System selects the highest IPv4 address from all configured
interfaces.
The OSPFv3 protocol uses the Router ID.

Best Practice - Configure the Router ID explicitly, rather than relying on the default
setting. Configuring the Router ID prevents the ID from changing if the default
interface used for the router ID goes down.
On a Security Gateway, use an address on a loopback interface that is not the
loopback address [Link] (configure an additional Loopback interface and
assign an IP address to it from the 128.0.0.x / 24 subnet - see the R82.10 Gaia
Administration Guide).
Important:
n Do not use the IP address [Link] as the Router ID.
n In a Cluster, you must configure the Router ID and you must configure its value
to one of the Cluster Virtual IP addresses.
In a Cluster, you must configure all the Cluster Members in the same way.

You can configure the IPv6 OSPFv3 Router ID in Gaia Portal or Gaia Clish.
Configuring IPv6 OSPFv3 Router ID in Gaia Portal

To configure the Global Router ID


1. From the left navigation tree, click Advanced Routing > IPv6 OSPF.
2. In the Instances section, select the Default instance.

3. In the Router ID section, enter the IPv4 address.


4. Click Apply Router ID.

To configure the Router ID for an OSPFv3 Instance


1. From the left navigation tree, click Advanced Routing > IPv6 OSPF.
2. In the Instances section, select the instance (other than Default).
3. In the Router ID section, enter the IPv4 address.
4. Click Apply Router ID.

R82.10 Gaia Advanced Routing Administration Guide | 336


Configuring IPv6 OSPFv3 Router ID

Configuring IPv6 OSPFv3 Router ID in Gaia Clish

Syntax to configure the Global Router ID

set router-id {<IPv4 Address> | default}

Syntax to configure the Router ID for an OSPFv3 Instance

set ipv6 ospf3 instance {<1-65535> | default} router-id {<IPv4


Address> | default}

Parameters

Parameter Description

instance {<1- Specifies an OSPFv3 Instance ID to configure.


65535> | If you configure the Router ID for an OSPFv3 Instance, this
default} Router ID overrides the Global Router ID configured on the
system.

<IP Address> Specifies a specific IPv4 address in dotted-quad ([1-255].[1-255].


[1-255].[1-255]) format.

default Selects the highest interface address when OSPFv3 is enabled.

Viewing IPv6 OSPFv3 Router ID in Gaia Clish

Syntax to view the Global Router ID

show router-id

Syntax to view the Router ID of an OSPFv3 Instance

show ipv6 ospf3 instance {<1-65535> | default} router-id

Parameters

R82.10 Gaia Advanced Routing Administration Guide | 337


Configuring IPv6 OSPFv3 in Gaia Portal

Configuring IPv6 OSPFv3 in Gaia Portal


Important:
n In a Cluster, you must configure all the Cluster Members in the same way.
n Start the OSPFv3 configuration from Router ID (see "Configuring IPv6 OSPFv3
Router ID" on page 336).
n Gaia Clish does not have commands for route filtering and redistribution. You
must configure inbound routing policies and redistribution of routes through the
Gaia Portal.
You can configure route maps and route aggregation using Gaia Clish
commands. Route map configuration done through the Gaia Clish takes
precedence over route filtering and redistribution configured in the Gaia Portal.
For example, if OSPFv3 uses route maps for inbound filtering, anything
configured in the Gaia Portal for inbound route filters for OSPFv3 is ignored.
You can still use the Gaia Portal to configure route redistribution into OSPF.

Procedure
1. From the left navigation tree, click Advanced Routing > OSPF.
2. Configure the Router ID.
See "Configuring IPv6 OSPFv3 Router ID" on page 336.
3. Optional: Configure additional OSPF Areas (in addition to the backbone area).

See "Configuring IPv6 OSPFv3 Areas in Gaia Portal" on page 342.


4. Configure the Global Options.
See "Configuring IPv6 OSPFv3 Global Options in Gaia Portal" on page 339.

5. Optional: For each OSPFv3 Area, you can add one or more IPv4 address ranges, if you
want to reduce the number of routing entries that the OSPFv3 Area advertises into the
OSPFv3 backbone.

Note - To prevent an address range from being advertised into the backbone,
select the option Restrict for the address range

6. Configure OSPF Interfaces.


See "Configuring IPv6 OSPFv3 Interfaces in Gaia Portal" on page 348.
7. Optional: Configure the OSPF Instances.
See "Configuring IPv6 OSPFv3 Multiple Instances" on page 366.

R82.10 Gaia Advanced Routing Administration Guide | 338


Configuring IPv6 OSPFv3 Global Options in Gaia Portal

Configuring IPv6 OSPFv3 Global Options in Gaia Portal


Important - In a Cluster, you must configure all the Cluster Members in the same way.

1. From the left navigation tree, click Advanced Routing > IPv6 OSPF.
2. In the Global Options section, click Edit Global Options.
3. Configure the applicable settings.
Description

Parameter Description

SPF Delay Configures the time to wait before recalculating the OSPFv3
routing table after a change in the topology.
Range: 1-60 seconds
Default: 2 seconds

SPF Hold Configures the minimum time between recalculations of the


Time OSPFv3 routing table.
Range: 1-60 seconds
Default: 5 seconds

Default ASE Configures a default cost to use when routes from other protocols
Route Cost are redistributed into OSPFv3 as Autonomous System External
(ASE) routes.
This default is ignored for any redistributed routes, which already
have a cost.
If the route has a cost already specified, that cost takes precedent.
Range: 1-6777215
Default: 1

Default ASE Configures the default route type to use when routes from other
Route Type protocols are redistributed into OSPFv3 as Autonomous System
External (ASE) routes.
This default is ignored for any redistributed routes, which already
have a type.
If the route has a type already specified, that type takes precedent.
A type 1 route is internal and its metric can be used directly by
OSPFv3 for comparison.
A type 2 route is external and is assumed to have a greater cost
than any internal route.
Range: Type 1, or Type 2
Default: 1

R82.10 Gaia Advanced Routing Administration Guide | 339


Configuring IPv6 OSPFv3 Global Options in Gaia Portal

Parameter Description

Graceful Graceful Restart enables this router to act as a helper for other
Restart routers when they undergo a graceful restart.
Helper When a grace LSA is received from a neighbor, the neighbor is
kept in the forwarding path with full adjacency till either the grace-
period (advertised in the grace LSA) expires, or there is a topology
change.
The helper functionality is supported for both planned and
unplanned restarts.
Note - Graceful Restart is not compatible with VRRP Preempt
Mode. You must disable VRRP Preempt Mode before you
enable this option.
Range: Selected, or Cleared
Default: Cleared

Graceful Configures Graceful Restart for this router.


Restart n To disable, clear this option.
n To enable, select this option and configure the Grace Period

- enter a value between 1 and 1800 seconds. The default


grace period is 120 seconds.
The Graceful Restart option causes this router to act as a re-
starting router according to RFC 3623.
The re-starter functionality is supported for both planned and
unplanned restarts for both IPv6 OSPFv3 and IPv6 OSPFv3 when
using VRRP and OSPFv3 only when using ClusterXL.
Notes:
n Graceful Restart is not compatible with VRRP Preempt

Mode. You must disable VRRP Preempt Mode before


you enable this option.
n In ClusterXL, the re-starter functionality is supported for

both planned and unplanned restarts for IPv6 OSPFv3


only.
n In VRRP Cluster, the re-starter functionality is supported

for both planned and unplanned restarts for both IPv6


OSPFv3 and IPv6 OSPFv3.
Range: Selected, or Cleared
Default: Cleared

R82.10 Gaia Advanced Routing Administration Guide | 340


Configuring IPv6 OSPFv3 Global Options in Gaia Portal

Parameter Description

Force Hellos Enabling this feature sends out forced Hello packets at the
specified interval when the Dynamic Routing Daemon is busy
processing updates or synching data to standby nodes.
These extra Hello packets are in addition to the typical hello
packets in OSPF.
This feature is required to maintain neighbor adjacencies when
processing large number of updates.
n To disable, clear this option.
n To enable, select this option and configure the Force Hellos

Timer - enter a value between 2 and 10 seconds. The timer is


5 seconds.
Range: Selected, or Cleared
Default: Cleared

4. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 341


Configuring IPv6 OSPFv3 Areas in Gaia Portal

Configuring IPv6 OSPFv3 Areas in Gaia Portal


In This Section:

Important - In a Cluster, you must configure all the Cluster Members in the same way.

For description of OSPFv3 Areas, see "IPv6 OSPFv3 Types of Areas" on page 375.

Configuring a Normal Area


1. From the left navigation tree, click Advanced Routing > OSPF.

2. In the Areas section, click Add.


3. In the Area field, enter the OSPFv3 Area ID.
Description

n For the backbone area, enter backbone.


(By default, the backbone area is enabled. You can disable the backbone area if
the system does not have interfaces on the backbone area.)
n For other areas, enter an ID in one of these formats:
l integer between 0 and 4294967295
l dotted quad form (example: [Link] for area id 1)

4. In the Area Type field, select Normal.


5. In the Address Ranges section, add the applicable IPv6 address ranges to be
advertised into the backbone area.
Description

An IPv6 address range is defined by a prefix and a mask length in CIDR notation
format (for example, FC00:1::0/64).
An area can be configured with any number of address ranges.
These ranges are used to reduce the number of routing entries that an area will emit
into the backbone area (and hence all areas).
If a given prefix aggregates a number of more specific prefixes within an area, then an
address range can be configured and will be the only prefix advertised into the
backbone.

R82.10 Gaia Advanced Routing Administration Guide | 342


Configuring IPv6 OSPFv3 Areas in Gaia Portal

Important - Pay attention when you configure an address range that includes
addresses, which are not contained within the area. If a range is marked as
restricted, then no advertisement is injected into the backbone.

Instructions

a. Click Add.
b. In the IPv6 address / Mask Length field, enter the IPv6 address range prefix (for
example, FC00:1::0) and the IPv6 mask length (for example, 64).
c. Optional: Select the Restrict option to blocks the given address range from
being advertised into the backbone area. Otherwise, the given address range is
advertised.

Range: Selected, or Cleared


Default: Cleared
d. Click OK.

6. In the Stub Networks section, add the applicable stub networks.


Description

An IPv6 address range is defined by a prefix and a mask length in CIDR notation
format (for example, FC00:1::0/64).
OSPFv3 can advertise routes of networks, which are not running OSPFv3 by using a
stub network.

The advertised routes appear as OSPFv3 internal routes, and can be filtered for
export at area borders using OSPFv3 area ranges.

Any advertised network prefix must be directly connected to the router, where the stub
network is configured.
Meaning, one of the router's interface addresses must be within the network to be
included in the router LSA.
For OSPFv3, IPv6 Stub hosts may be configured by using a mask length of 128.
This feature also supports advertising a network that can be activated by the local
address of a point-to-point interface. To advertise reachability to such an network, you
must configure an IP address for the network along with a non-zero cost.

R82.10 Gaia Advanced Routing Administration Guide | 343


Configuring IPv6 OSPFv3 Areas in Gaia Portal

Instructions

a. Click Add.
b. In the IPv6 address / Mask Length field, enter the IPv6 address range prefix (for
example, FC00:1::0) and the IPv6 mask length (for example, 64).
c. Optional: In the Cost field, enter the cost associated with the stub network as
reached through this router.
The higher the cost, the less preferred the route.
Range: 1-65535
Default: 1
d. Click OK.

7. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 344


Configuring IPv6 OSPFv3 Areas in Gaia Portal

Configuring a Stub Area


1. From the left navigation tree, click Advanced Routing > OSPF.
2. In the Areas section, click Add.
3. In the Area field, enter the OSPFv3 Area ID.
Description

Enter an ID in one of these formats:


n integer between 0 and 4294967295
n dotted quad form (example: [Link] for area id 1)

4. In the Area Type field, select Stub.


5. In the Cost for Default Route field, enter the routing cost associated with the default
route for this area.
Description

The higher the cost, the less preferred the route.


Range: 1-16777215
Default: 1

6. The Import Summary Routes option controls if this area is Totally-Stubby.


Description

A Totally-Stubby Area does not have Type 4 or Type 5 LSAs. It has only a single Type
3 LSA, which describes a default route.
n When this option is cleared, the area is Totally-Stubby.
n When this option is selected, the area is Not Totally-Stubby.
Range: Selected, or Cleared
Default: Selected

7. In the Address Ranges section, add the applicable IPv4 address ranges to be
advertised into the backbone area.
Description

An IPv6 address range is defined by a prefix and a mask length in CIDR notation
format (for example, FC00:1::0/64).
An area can be configured with any number of address ranges.

R82.10 Gaia Advanced Routing Administration Guide | 345


Configuring IPv6 OSPFv3 Areas in Gaia Portal

These ranges are used to reduce the number of routing entries that an area will emit
into the backbone area (and hence all areas).
If a given prefix aggregates a number of more specific prefixes within an area, then an
address range can be configured and will be the only prefix advertised into the
backbone.

Important - Pay attention when you configure an address range that includes
addresses, which are not contained within the area. If a range is marked as
restricted, then no advertisement is injected into the backbone.

Instructions

a. Click Add.

b. In the IPv6 address / Mask Length field, enter the IPv6 address range prefix (for
example, FC00:1::0) and the IPv6 mask length (for example, 64).
c. Optional: Select the Restrict option to blocks the given address range from
being advertised into the backbone area. Otherwise, the given address range is
advertised.
Range: Selected, or Cleared
Default: Cleared
d. Click OK.

8. In the Stub Networks section, add the applicable stub networks.


Description

An IPv6 address range is defined by a prefix and a mask length in CIDR notation
format (for example, FC00:1::0/64).

OSPFv3 can advertise routes of networks, which are not running OSPFv3 by using a
stub network.
The advertised routes appear as OSPFv3 internal routes, and can be filtered for
export at area borders using OSPFv3 area ranges.
Any advertised network prefix must be directly connected to the router, where the stub
network is configured.
Meaning, one of the router's interface addresses must be within the network to be
included in the router LSA.
For OSPFv3, IPv6 Stub hosts may be configured by using a mask length of 128.

R82.10 Gaia Advanced Routing Administration Guide | 346


Configuring IPv6 OSPFv3 Areas in Gaia Portal

This feature also supports advertising a network that can be activated by the local
address of a point-to-point interface. To advertise reachability to such an network, you
must configure an IP address for the network along with a non-zero cost.

Instructions

a. Click Add.
b. In the IPv6 address / Mask Length field, enter the IPv6 address range prefix (for
example, FC00:1::0) and the IPv6 mask length (for example, 64).
c. Optional: In the Cost field, enter the cost associated with the stub network as
reached through this router.
The higher the cost, the less preferred the route.

Range: 1-65535
Default: 1
d. Click OK.

9. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 347


Configuring IPv6 OSPFv3 Interfaces in Gaia Portal

Configuring IPv6 OSPFv3 Interfaces in Gaia Portal


Important - In a Cluster, you must configure all the Cluster Members in the same way.

1. From the left navigation tree, click Advanced Routing > IPv6 OSPF.
2. In the Interfaces section, click Add.
3. In the Interface field, select the applicable interface.
4. In the Area field, select the area to assign to this interface.

Note - An entry for the Backbone area appears even if it is disabled.

5. In the Hello Interval field, enter the time.


Description

Configures the delay time between Hello packets on this interface.


The OSPFv3 Hello Protocol is responsible for establishing and maintaining
adjacencies (i.e. connections) between neighboring OSPFv3 routers.
For broadcast networks, the Hello is also used to dynamically discover neighbors.

Important - For a given link, this value must be the same for all OSPFv3 routers.

Range: 1-65535 seconds

Default: 10 seconds for broadcast networks, 30 seconds for point-to-point networks

6. In the Router Dead Interval field, enter the time.


Description

Configures the time after receipt of the last Hello packet, at which a neighbor is
declared dead.
Typically this is four times the Hello interval.

Important - For a given link, this value must be the same for all OSPFv3 routers.

Range: 1-65535 seconds


Default: 40 seconds for broadcast networks, 120 seconds for point-to-point networks

7. In the Retransmit Interval field, enter the time.

R82.10 Gaia Advanced Routing Administration Guide | 348


Configuring IPv6 OSPFv3 Interfaces in Gaia Portal

Description

Configures the time between LSA retransmissions for this interface.


This value is also used when retransmitting database description and link state
request packets.
This value should be much higher than the expected round-trip delay between any two
routers on the network.
Being conservative helps avoid unnecessary retransmissions.

Important - For a given link, this value must be the same for all OSPFv3 routers.

Range: 1-65535 seconds

Default: 5 seconds

8. In the Link Cost field, enter the cost of using the given interface for a route.
Description

The higher the cost, the less preferred the interface.


This is overridden by routing policy - Route Redistribution Rules and Route Maps.
Range: 1-65535
Default: 1

9. In the Election Priority field, enter the priority used in the Designated Router (DR)
election on the link.
Description

When two routers attempt to become the DR, the one with the higher priority is
elected.
However, if there is already an elected DR, then it continues as the DR regardless of
priority.
This prevents frequent changes in the DR state.
The priority is only applicable to shared-media like Ethernet.
A DR is not elected on point-to-point interfaces.
A router with priority 0 is not eligible to become the DR.
Range: 0-255
Default: 1

R82.10 Gaia Advanced Routing Administration Guide | 349


Configuring IPv6 OSPFv3 Interfaces in Gaia Portal

10. The Passive option controls the passive mode for this interface.
Description

When passive mode is enabled, the OSPFv3 interface does not send Hello packets.
This means that the link does not form any adjacencies.
Passive mode enables the network associated with the interface to be included in the
intra-area route calculation rather than redistributing the network into OSPFv3 and
having it as an Autonomous System External (ASE) route.
In passive mode, all interface configuration information, with the exception of the
associated area and the cost, is ignored.
Range: Selected, or Cleared

Default: Cleared (The interface sends Hello packets)

11. The Use Virtual Address option controls the VRRP mode for this interface.
Description
Important:
n Configure this option on VRRP Cluster Members when the given

interface is configured as a VRRP interface.


n Do not configure this option on ClusterXL Cluster Members.

When this option is enabled, OSPFv3 uses the VRRP Virtual IP Address associated
with the VRRP interface instead of the physical IP address.

In addition, OSPFv3 only runs when this router is the VRRP Master for the given
interface.
Range: Selected, or Cleared

Default: Cleared

12. The IP Reachability Detection option controls BFD (Bidirectional Forwarding Detection)
for each neighbor, from which it hears on this interface.
Description

Directs OSPFv3 to start BFD (Bidirectional Forwarding Detection) for each neighbor,
from which it hears on this interface.
The BFD session is started only after OSPFv3 transitions to 'Full' state with the
neighbor.
Once the BFD session is up, OSPFv3 responds to changes in BFD state.

R82.10 Gaia Advanced Routing Administration Guide | 350


Configuring IPv6 OSPFv3 Interfaces in Gaia Portal

If a neighbor does not have BFD configured or it does not respond to BFD control
packets, it does not impact OSPFv3 operation. OSPFv3 can operate with both BFD
and non-BFD neighbors on the same interface.
Before you enable this option, see "IP Reachability Detection" on page 243.
n Make sure the Firewall policy allows traffic to the UDP port 3784 in both
directions.
n Make sure the SmartConsole topology is correct (issues with incorrect Firewall
topology can cause anti-spoofing to interfere with BFD traffic).
Range: Selected, or Cleared
Default: Selected

13. In the Security field, select the applicable option.


Description

To use IPsec Routing:


a. In the Security field, select IPsec
b. In the Security Association field, select the applicable Security Association SPI.
See "IPsec Routing" on page 264.
Range: None, or IPsec
Default: None

14. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 351


Configuring IPv6 OSPFv3 in Gaia Clish

Configuring IPv6 OSPFv3 in Gaia Clish


Important:
n In a Cluster, you must configure all the Cluster Members in the same way.
n Start the OSPFv3 configuration from Router ID (see "Configuring IPv6 OSPFv3
Router ID" on page 336).
n Gaia Clish does not have commands for route filtering and redistribution. You
must configure inbound routing policies and redistribution of routes through the
Gaia Portal.
You can configure route maps and route aggregation using Gaia Clish
commands. Route map configuration done through the Gaia Clish takes
precedence over route filtering and redistribution configured in the Gaia Portal.
For example, if OSPFv3 uses route maps for inbound filtering, anything
configured in the Gaia Portal for inbound route filters for OSPFv3 is ignored.
You can still use the Gaia Portal to configure route redistribution into OSPF.
n To see the available "set" commands for IPv6 OSPFv3, enter in Gaia Clish:

set ipv6 ospf3[Esc][Esc]

n To see the available "show" commands for IPv6 OSPFv3, enter in Gaia Clish:

show ipv6 ospf3[Esc][Esc]

n To see the available "restart" commands for IPv6 OSPFv3, enter in Gaia Clish:

restart ospf3[Esc][Esc]

Procedure
1. Connect to the command line.
2. Log in to Gaia Clish.
3. Configure the Router ID.
See "Configuring IPv6 OSPFv3 Router ID" on page 336.
4. Optional: Configure additional OSPF Areas (in addition to the backbone area).
See "Configuring IPv6 OSPFv3 Areas in Gaia Clish" on page 357.
5. Configure the Global Options.
See "Configuring IPv6 OSPFv3 Global Options in Gaia Clish" on page 354.

R82.10 Gaia Advanced Routing Administration Guide | 352


Configuring IPv6 OSPFv3 in Gaia Clish

6. Optional: For each OSPFv3 Area, you can add one or more IPv4 address ranges, if you
want to reduce the number of routing entries that the OSPFv3 Area advertises into the
OSPFv3 backbone.

Note - To prevent an address range from being advertised into the backbone,
select the option Restrict for the address range

7. Configure OSPF Interfaces.


See "Configuring IPv6 OSPFv3 Interfaces in Gaia Clish" on page 362.
8. Optional: Configure the OSPF Instances.
See "Configuring IPv6 OSPFv3 Multiple Instances" on page 366.
9. Save the configuration:

save config

R82.10 Gaia Advanced Routing Administration Guide | 353


Configuring IPv6 OSPFv3 Global Options in Gaia Clish

Configuring IPv6 OSPFv3 Global Options in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

Global settings apply to all configured OSPFv3 areas, including the backbone and stub areas.
Syntax

set ipv6 ospf3 [instance {<1-65535> | default}]


default-ase-cost {<1-6777215> | default}
default-ase-type {1 | 2}
force-hellos
{off | on}
timer {<2-10> | default}
graceful-restart-helper {off | on}
graceful-restart
{off | on}
grace-period {<1-1800> | default}
{off | on}
spf-delay {<1-60> | default}
spf-holdtime {<1-60> | default}

Parameters

Parameter Description

instance {<1- Specifies an OSPFv3 Instance ID to configure.


65535> | default}

instance {<1- Disables (off) or enables (on) the specified OSPFv3


65535> | default} Instance.
{off | on}

default-ase-cost Configures a default cost to use when routes from other


{<1-6777215> | protocols are redistributed into OSPFv3 as Autonomous
default} System External (ASE) routes.
This default is ignored for any redistributed routes, which
already have a cost.
If the route has a cost already specified, that cost takes
precedent.
Range: 1-6777215, or default
Default: 1

R82.10 Gaia Advanced Routing Administration Guide | 354


Configuring IPv6 OSPFv3 Global Options in Gaia Clish

Parameter Description

default-ase-type Configures the default route type to use when routes from
{1 | 2} other protocols are redistributed into OSPFv3 as
Autonomous System External (ASE) routes.
This default is ignored for any redistributed routes, which
already have a type.
If the route has a type already specified, that type takes
precedent.
A type 1 route is internal and its metric can be used directly
by OSPFv3 for comparison.
A type 2 route is external and is assumed to have a greater
cost than any internal route.
Range: 1, or 2
Default: 1

force-hellos Enabling this feature sends out forced Hello packets at the
{<options>} specified interval when the Dynamic Routing Daemon is busy
processing updates or synching data to standby nodes.
These extra Hello packets are in addition to the typical hello
packets in OSPF.
This feature is required to maintain neighbor adjacencies
when processing large number of updates.
Range: off, on, or timer
Default: off

force-hellos timer Configures the time between one forced OSPFv3 Hello
{<2-10> | default} message to the next.
Range: 2-10 seconds
Default: 5 seconds

graceful-restart- Disables (off) or enables (on) the Graceful Restart Helper.


helper {off | on} Graceful Restart enables this router to act as a helper for
other routers when they undergo a graceful restart.
When a grace LSA is received from a neighbor, the neighbor
is kept in the forwarding path with full adjacency till either the
grace-period (advertised in the grace LSA) expires, or there
is a topology change.
The helper functionality is supported for both planned and
unplanned restarts.
Note - Graceful Restart is not compatible with VRRP
Preempt Mode. You must disable VRRP Preempt Mode
before you enable this option.
Range: off, or on
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 355


Configuring IPv6 OSPFv3 Global Options in Gaia Clish

Parameter Description

graceful-restart Configures Graceful Restart for this router.


{off | on | grace-
period {<1-1800> |
n To disable, set it to off.
default}}
n To enable, set it to on.
n To configure the time, set a value between 1 and 1800
seconds. The default grace period is 120 seconds.
The Graceful Restart option causes this router to act as a re-
starting router according to RFC 3623.
The re-starter functionality is supported for both planned and
unplanned restarts for both IPv6 OSPFv3 and IPv6 OSPFv3
when using VRRP and OSPFv3 only when using ClusterXL.
Notes:
n Graceful Restart is not compatible with VRRP
Preempt Mode. You must disable VRRP Preempt
Mode before you enable this option.
n In ClusterXL, the re-starter functionality is
supported for both planned and unplanned restarts
for IPv6 OSPFv3 only.
n In VRRP Cluster, the re-starter functionality is
supported for both planned and unplanned restarts
for both IPv6 OSPFv3 and IPv6 OSPFv3.

spf-delay {<1-60> Configures the time to wait before recalculating the OSPFv3
| default} routing table after a change in the topology.
Range: 1-60 seconds
Default: 2 seconds

spf-holdtime {<1- Configures the minimum time between recalculations of the


60> | default} OSPFv3 routing table.
Range: 1-60 seconds
Default: 5 seconds

R82.10 Gaia Advanced Routing Administration Guide | 356


Configuring IPv6 OSPFv3 Areas in Gaia Clish

Configuring IPv6 OSPFv3 Areas in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

For description of OSPFv3 Areas, see "IPv6 OSPFv3 Types of Areas" on page 375.
The configuration is applicable to OSPFv3 Multiple Instances (see "Configuring IPv6 OSPFv3
Multiple Instances" on page 366).
Description

An OSPFv3 area defines a group of routers, which run OSPFv3 and have complete
topology information for the given area.

An OSPFv3 area uses an Area Border Router (ABR) to exchange routing information with
other areas via the backbone area.
Routes for a given area are summarized into the backbone area.
The backbone area then redistributes this summary information to other areas.
By definition, an ABR has interfaces to more than one area.
One of those areas must be either the backbone or an OSPFv3 Virtual Link to the
backbone.
OSPFv3 forces a hub and spoke area topology, with the backbone area always being the
hub.

Syntax

set ipv6 ospf3 instance {<1-65535> | default} area <OSPFv3 Area


ID>
{off | on}
range <IPv6 Address>/<Mask Length>
{off | on}
restrict {off | on}
stub
default-cost {<1-16777215> | default}
{off | on}
summary {off | on}
stub-network <IPv6 Address>/<Mask Length>
{off | on}
stub-network-cost {<1-65535> | default}

R82.10 Gaia Advanced Routing Administration Guide | 357


Configuring IPv6 OSPFv3 Areas in Gaia Clish

Parameters

Parameter Description

set ospf Specifies an OSPFv3 Area ID (for this OSPFv3 Instance).


[instance {<1- Best Practice - Enter the area ID as a dotted quad. The
65535> | area ID [Link] is reserved for the backbone.
default}] Range:
area <OSPFv3
Area ID> n backbone
(By default, the backbone area is enabled. You can
disable the backbone area if the system does not have
interfaces on the backbone area.)
n integer between 0 and 4294967295
n dotted quad form (example: [Link] for area id 1)
Default: none

set ipv6 ospf3 Removes (off) or creates (on) the area and all related
[instance {<1- configuration.
65535> |
default}]
area <OSPFv3
Area>
{off | on}

set ipv6 ospf3 Configures an OSPFv3 address range for this area.
[instance {<1- An IPv6 address range is defined by a prefix and a mask length
65535> | in CIDR notation format (for example, FC00:1::0/64).
default}] An area can be configured with any number of address ranges.
area <OSPFv3 These ranges are used to reduce the number of routing entries
Area> that an area will emit into the backbone area (and hence all
range <IPv6 areas).
Address>/<Mask If a given prefix aggregates a number of more specific prefixes
Length> within an area, then an address range can be configured and
will be the only prefix advertised into the backbone.
Important - Pay attention when you configure an address
range that includes addresses, which are not contained
within the area. If a range is marked as restricted, then no
advertisement is injected into the backbone.

R82.10 Gaia Advanced Routing Administration Guide | 358


Configuring IPv6 OSPFv3 Areas in Gaia Clish

Parameter Description

range <IPv6 Removes (off), adds (on), or restricts (restrict) the


Address>/<Mask OSPFv3 address range in this area.
Length> {off |
on | restrict
n off - Removes the given address range from the list of
{off | on}} ranges to be advertised into the backbone area.
n on - Configures the given address range to be advertised
into the backbone area.
n restrict - Blocks (off) or allows (on) the given
address range from being advertised into the backbone
area.
Range: off, on, or restrict
Default: none

set ipv6 ospf3 Configures this area as a Stub Area.


[instance {<1- Stub areas do not allow Type 5 LSAs to be propagated into or
65535> | throughout the area and instead depend on default routing for
default}] external destinations.
area <OSPFv3 You can configure an area as a Stub Area to reduce the
Area> stub number of entries in the routing table.
Routes external to the OSPFv3 domain are not added to the
routing table.

Note - The backbone area cannot be a stub area.

stub default- Configures the routing cost associated with the default route for
cost {<1- this area.
16777215> | The higher the cost, the less preferred the route.
default} Range: 1-16777215, or default
Default: 1

stub {off | on} Disables (off) or enables (on) this stub area:
n off - Reconfigures the given area to not be a Stub Area.
n on - Configures the given area to be a Stub Area.
Range: off, or on
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 359


Configuring IPv6 OSPFv3 Areas in Gaia Clish

Parameter Description

stub summary Disables (off) or enables (on) reception of summary LSAs into
{off | on} the area.
A Totally-Stubby Area does not have Type 4 or Type 5 LSAs.
It has only a single Type 3 LSA, which describes a default
route.
n When this option is disabled, the area is Totally-Stubby.
n When this option is enabled, the area is Not Totally-
Stubby.
Range: off, or on
Default: on

set ipv6 ospf3 Configures a Stub Network for this area.


[instance {<1- An IPv6 address range is defined by a prefix and a mask length
65535> | in CIDR notation format (for example, FC00:1::0/64).
default}] OSPFv3 can advertise routes of networks, which are not
area <OSPFv3 running OSPFv3 by using a stub network.
Area> The advertised routes appear as OSPFv3 internal routes, and
stub-network can be filtered for export at area borders using OSPFv3 area
<IPv6 ranges.
Address>/<Mask Any advertised network prefix must be directly connected to the
Length> router, where the stub network is configured.
Meaning, one of the router's interface addresses must be within
the network to be included in the router LSA.
For OSPFv2, IPv4 Stub hosts may be configured by using a
mask length of 32.
For OSPFv3, IPv6 Stub hosts may be configured by using a
mask length of 128.
This feature also supports advertising a network that can be
activated by the local address of a point-to-point interface. To
advertise reachability to such an network, you must configure
an IP address for the network along with a non-zero cost.

stub-network Controls the stub network for this area:


<IPv6
Address>/<Mask
n off - Removes the given stub network from the given
Length> {off | area.
on}
n on - Adds the given stub network to the given area.
Range: off, or on
Default: none

R82.10 Gaia Advanced Routing Administration Guide | 360


Configuring IPv6 OSPFv3 Areas in Gaia Clish

Parameter Description

stub-network Configures the cost associated with the stub network as


<IPv6 reached through this router.
Address>/<Mask The higher the cost, the less preferred the route.
Length> Range: 1-65535, or default
stub-network- Default: 1
cost {<1-65535>
| default}

R82.10 Gaia Advanced Routing Administration Guide | 361


Configuring IPv6 OSPFv3 Interfaces in Gaia Clish

Configuring IPv6 OSPFv3 Interfaces in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

The configuration is applicable to OSPFv3 Multiple Instances (see "Configuring IPv6 OSPFv3
Multiple Instances" on page 366).
Syntax

set ipv6 ospf3 [instance {<1-65535> | default}] interface <Name


of Interface>
area <OSPFv3 Area ID> {off | on}
cost {<1-65535> | default}
dead-interval {<1-65535> | default}
hello-interval {<1-65535> | default}
ip-reachability-detection {off | on}
passive {off | on}
priority {<0-255> | default}
retransmit-interval {<1-65535> | default}
security ipsec {off | spi <SPI>}
virtual-address {off | on}

Parameters

Parameter Description

instance {<1- Specifies the OSPFv3 instance.


65535> |
default}

interface Specifies the name of the interface.


<Name of
Interface>

area <OSPFv3 Disables (off) or enables (on) this OSPFv3 area on the interface.
Area ID> {off
| on}

cost {<1- Configures the cost of using the given interface for a route.
65535> | The higher the cost, the less preferred the interface.
default} This is overridden by routing policy - Route Redistribution Rules
and Route Maps.
Range: 1-65535, or default
Default: 1

R82.10 Gaia Advanced Routing Administration Guide | 362


Configuring IPv6 OSPFv3 Interfaces in Gaia Clish

Parameter Description

dead-interval Configures the time after receipt of the last Hello packet, at which
{<1-65535> | a neighbor is declared dead.
default} Typically this is four times the Hello interval.
Important - For a given link, this value must be the same for
all OSPFv3 routers.
Range: 1-65535 seconds, or default
Default: 40 seconds for broadcast networks, 120 seconds for
point-to-point networks

hello-interval Configures the delay time between Hello packets on this


{<1-65535> | interface.
default} The OSPFv3 Hello Protocol is responsible for establishing and
maintaining adjacencies (i.e. connections) between neighboring
OSPFv3 routers.
For broadcast networks, the Hello is also used to dynamically
discover neighbors.
Important - For a given link, this value must be the same for
all OSPFv3 routers.
Range: 1-65535 seconds, or default
Default: 10 seconds for broadcast networks, 30 seconds for point-
to-point networks

ip- Directs OSPFv3 to start BFD (Bidirectional Forwarding Detection)


reachability- for each neighbor, from which it hears on this interface.
detection {off The BFD session is started only after OSPFv3 transitions to 'Full'
| on} state with the neighbor.
Once the BFD session is up, OSPFv3 responds to changes in
BFD state.
If a neighbor does not have BFD configured or it does not respond
to BFD control packets, it does not impact OSPFv3 operation.
OSPFv3 can operate with both BFD and non-BFD neighbors on
the same interface.
Before you enable this option, see "IP Reachability Detection" on
page 243.
n Make sure the Firewall policy allows traffic to the UDP port
3784 in both directions.
n Make sure the SmartConsole topology is correct (issues
with incorrect Firewall topology can cause anti-spoofing to
interfere with BFD traffic).
Range: off, or on
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 363


Configuring IPv6 OSPFv3 Interfaces in Gaia Clish

Parameter Description

passive {off | Disables (off) or enables (on) passive mode for this interface.
on} When passive mode is enabled, the OSPFv3 interface does not
send Hello packets.
This means that the link does not form any adjacencies.
Passive mode enables the network associated with the interface
to be included in the intra-area route calculation rather than
redistributing the network into OSPFv3 and having it as an
Autonomous System External (ASE) route.
In passive mode, all interface configuration information, with the
exception of the associated area and the cost, is ignored.
Range: off, or on
Default: off (The interface sends Hello packets)

priority {<0- Configures the priority used in the Designated Router (DR)
255> | election on the link.
default} When two routers attempt to become the DR, the one with the
higher priority is elected.
However, if there is already an elected DR, then it continues as
the DR regardless of priority.
This prevents frequent changes in the DR state.
The priority is only applicable to shared-media like Ethernet.
A DR is not elected on point-to-point interfaces.
A router with priority 0 is not eligible to become the DR.
Range: 0-255, or default
Default: 1

retransmit- Configures the time between LSA retransmissions for this


interval {<1- interface.
65535> | This value is also used when retransmitting database description
default} and link state request packets.
This value should be much higher than the expected round-trip
delay between any two routers on the network.
Being conservative helps avoid unnecessary retransmissions.
Important - For a given link, this value must be the same for
all OSPFv3 routers.
Range: 1-65535 seconds, or default
Default: 5 seconds

security ipsec Disables (off) or enables (on) the IPsec for this interface.
{off | spi See "IPsec Routing" on page 264.
<SPI>} Range: off, or one of the configured SPIs
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 364


Configuring IPv6 OSPFv3 Interfaces in Gaia Clish

Parameter Description

virtual- Disables (off) or enables (on) VRRP mode for this interface.
address {off | Important:
on}
n Configure this option on VRRP Cluster Members when
the given interface is configured as a VRRP interface.
n Do not configure this option on ClusterXL Cluster
Members.

When this option is enabled, OSPFv3 uses the VRRP Virtual IP


Address associated with the VRRP interface instead of the
physical IP address.
In addition, OSPFv3 only runs when this router is the VRRP
Master for the given interface.
Range: off, or on
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 365


Configuring IPv6 OSPFv3 Multiple Instances

Configuring IPv6 OSPFv3 Multiple Instances


In This Section:

Introduction 366
Adding a New IPv6 OSPFv3 Instance 367
Deleting an Existing IPv6 OSPFv3 Instance 368
Restarting an IPv6 OSPFv3 Instance 369

Introduction
Multiple OSPFv3 Instances let you separate OSPFv3 into multiple OSPFv3 domains.
Each instance contains a fully independent OSPFv3 database, and routes from one domain
are not automatically advertised to another domain.
You can manually configure route maps to filter and redistribute routes from one domain into
another domain.
The redistributed routes show as OSPFv3 external routes in the routing table of the other
domain.
If two different OSPFv3 instances try to install the same route with equal cost, the route with
the lower next hop IP address is preferred.

If the routes have different costs, the route with the lower cost is selected.
Separate OSPFv3 Instances do not share link state with one another, and will not pass routes
among themselves unless explicitly configured to do so using either Route Redistribution or
Routemaps.

R82.10 Gaia Advanced Routing Administration Guide | 366


Configuring IPv6 OSPFv3 Multiple Instances

Adding a New IPv6 OSPFv3 Instance


Note - To add more instances, the default instance must have at least one OSPFv3
interface configured and running.

To add a new IPv6 OSPFv3 instance in Gaia Portal

1. From the left navigation tree, click Advanced Routing > IPv6 OSPF.
2. In the Instances section, click Add OSPF Instance.
3. In the Instance Number field, enter the Instance number from 1 to 65535.
4. Click OK.

To add a new IPv6 OSPFv3 instance in Gaia Clish

1. Connect to the command line.


2. Log in to Gaia Clish.
3. Add a new instance:

set ipv6 ospf3 instance {<1-65535> | default} on

4. Save the configuration:

save config

R82.10 Gaia Advanced Routing Administration Guide | 367


Configuring IPv6 OSPFv3 Multiple Instances

Deleting an Existing IPv6 OSPFv3 Instance


To delete an IPv6 OSPFv3 instance in Gaia Portal

1. From the left navigation tree, click Advanced Routing > IPv6 OSPF.
2. In the Instances section:
a. Select the instance.
b. Click Delete OSPF Instance.
c. Click OK to confirm.

To delete an IPv6 OSPFv3 instance in Gaia Clish

1. Connect to the command line.


2. Log in to Gaia Clish.
3. Delete the instance:

set ipv6 ospf3 instance {<1-65535> | default} off

4. Save the configuration:

save config

R82.10 Gaia Advanced Routing Administration Guide | 368


Configuring IPv6 OSPFv3 Multiple Instances

Restarting an IPv6 OSPFv3 Instance


Restarting an IPv6 OSPFv3 Instance lets you clear OSPFv3 database and restart OSPFv3
adjacency for an instance without restarting the Gaia RouteD daemon.
Important Notes
n Restarting any part of an OSPFv3 protocol tears down all neighbor
adjacencies and brings them back up.
n The protocol's Graceful Restart mechanism does not take effect.
n Side effects of restarting an OSPFv3 instance include:
l Loss of OSPFv3 routes

l Traffic outage

l Network topology reconvergence

n In a ClusterXL or VRRP Cluster, restart of an OSPFv3 instance does not


trigger a cluster failover.

To restart an IPv6 OSPFv3 instance in Gaia Portal

1. From the left navigation tree, click Advanced Routing > OSPF.
2. In the Instances section:
a. Select the OSPFv3 Instance.
b. Click Restart OSPF Instance.

To restart an IPv6 OSPFv3 instance in Gaia Clish

1. Connect to the command line.


2. Log in to Gaia Clish.
3. Restart the OSPFv3 Instance:

restart ospf3 instance {<OSPFv3 Instance Number> | default}

R82.10 Gaia Advanced Routing Administration Guide | 369


Monitoring IPv6 OSPFv3

Monitoring IPv6 OSPFv3


Monitoring IPv6 OSPFv3 in Gaia Portal
1. From the left navigation tree, click Advanced Routing > IPv6 OSPF.
2. In the top right corner, click Monitoring.
3. In the OSPF3 Monitor section, select an OSPFv3 instance.
4. Click on the Information category.

Note - The page is static. To see the latest values, click Reload.

Monitoring IPv6 OSPFv3 in Gaia Clish

show ipv6 ospf3[Esc][Esc]

Troubleshooting IPv6 OSPFv3


See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 370


ClusterXL Support for IPv6 OSPFv3

ClusterXL Support for IPv6 OSPFv3


ClusterXL R80.20 and higher supports OSPFv3.
OSPFv3 requires support of Link-Local Virtual IP address, because it uses the Virtual IP as the
source IP address in communication with the OSPFv3 neighbors.
An IPv6 Link-Local address is automatically added to each interface when IPv6 is enabled on
Gaia.
You can override the automatic Link-Local address with manual configuration.
Manual and automatic configuration of Link-Local VIP is possible on every interface that has a
global VIP address.

Notes:
n In automatic configuration, when an IPv4 address changes, the IPv6 Link-Local
address changes as well.
n In manual configuration, when the IPV4 address changes, the manually
configured IPv6 address persists.

To configure an IPv6 Link-Local VIP address manually on an interface

1. Set a Link-Local address on the interface.


To manually configure a Link-Local VIP, in the Expert mode, run:
n In Gateway mode:

cphaconf set_link_local <Name of Interface> <Link Local


IPv6 VIP Address>

n In VSX mode:

cphaconf set_link_local -vs <VSID> <Name of Interface>


<Link Local IPv6 VIP Address>

2. Do one of these actions:


n Install the Access Control Policy.
Or
n Run the cpstop command and then run the cpstart command.
3. Check the state of the cluster member interfaces:

R82.10 Gaia Advanced Routing Administration Guide | 371


ClusterXL Support for IPv6 OSPFv3

n In the Expert mode:

chpaprob -a if

n In Gaia Clish:

show cluster interfaces all

4. Enable OSPFv3 on the interface with the Link-Local VIP. In Gaia Clish, run:

set ipv6 ospf3 interface <Name of Interface> area backbone


on
save config

To see the OSPFv3 interfaces

show ipv6 ospf3 interfaces

To back up the IPv6 Link-Local VIP configuration

Save a copy of this file:

$FWDIR/conf/linklocal_local.vip

To remove an IPv6 Link-Local VIP address

Mode Shell Instructions

Gateway Expert cphaconf delete_link_local <Name of


mode Interface> <Cluster IP Address>

Gaia 1. set ipv6 ospf3 interface <Name of


Clish Interface> area backbone off
2. save config

VSX Expert cphaconf delete_link_local -vs <VSID> <Name


mode of Interface> <Cluster IP Address>

Gaia 1. set virtual-system <VSID>


Clish 2. set ipv6 ospf3 interface <Name of
Interface> area backbone off
3. save config

R82.10 Gaia Advanced Routing Administration Guide | 372


VRRPv3 Support for IPv6 OSPFv3

VRRPv3 Support for IPv6 OSPFv3


To use OSPFv3 with VRRPv3, you must enable the option Use Virtual Address on the
applicable interfaces.
If the configured interface is part of the VRRP Master virtual router, then OSPFv3 runs on the
interface.
When you enable the Use Virtual Address option, OSPFv3 uses the VRRPv3 virtual link-local
address for the interface as the source of its control packets. This cannot be the automatically
configured link-local address - that is, you must change the link-local address for the interface
to something other than the default.
VRRP installs the link-local address only on the VRRP Master, so OSPFv3 runs only on that
router. If a VRRP failover occurs, VRRPv3 installs the link-local address on the new Master,
and OSPFv3 starts running on that system. Because OSPFv3 runs on one router at a time,
there is no synchronization of OSPFv3 state between the VRRP group members.

Important - You must configure the same link-local address on all the routers in the
VRRP group.

To configure this option in Gaia Portal:


1. From the left navigation tree, click Advanced Routing > IPv6 OSPF
2. In the Interfaces section, select the interface.
3. Click Edit.

4. Select the Use Virtual Address option.


5. Click Save.

See "Configuring IPv6 OSPFv3 Interfaces in Gaia Portal" on page 348.

To configure this option in Gaia Clish:


1. Connect to the command line.
2. Log in to Gaia Clish.
3. Configure the interface:

set ipv6 ospf3 [instance {<1-65535> | default}] interface


<Name of Interface> virtual-address {off | on}

4. Save the configuration:

save config

R82.10 Gaia Advanced Routing Administration Guide | 373


VRRPv3 Support for IPv6 OSPFv3

See "Configuring IPv6 OSPFv3 Interfaces in Gaia Clish" on page 362.

R82.10 Gaia Advanced Routing Administration Guide | 374


IPv6 OSPFv3 Types of Areas

IPv6 OSPFv3 Types of Areas


Routers using OSPFv3 send packets called Link State Advertisements (LSA) to all routers in
an area.
Areas are smaller groups within the AS that you can design to limit the flooding of an LSA to all
routers.
LSAs do not leave the area from which they originated, thus increasing efficiency and saving
network bandwidth.
You must specify at least one area in your OSPFv3 network - the backbone area, which has
the responsibility to propagate information between areas.

The backbone area has the identifier [Link].


You can designate other areas, depending on your network design, of the following types:

Area
Description
Type

Normal Not a Stub Area.


Allows all LSAs to pass through.
The backbone is always a normal area.

Stub Stub areas do not allow Type 5 LSAs to be propagated into or throughout the
area and instead depend on default routing for external destinations.
You can configure an area as a Stub Area to reduce the number of entries in
the routing table.
Routes external to the OSPFv3 domain are not added to the routing table.

Note - The backbone area cannot be a stub area.

Best Practice - Limit OSPFv3 areas to about 50 routers based on the limitations of
OSPFv3 (traffic overhead, table size, convergence, and so on).

All OSPFv3 areas must be connected to the backbone area. If you have an area that is not
connected to the backbone area, you can connect it by configuring a virtual link, enabling the
backbone area to appear contiguous despite the physical reality.

Note - If you need to connect two networks that both already have backbone areas
and you do not want to reconfigure one to something other than [Link], you can
connect the two backbone areas using a virtual link.

Each router records information about its interfaces when it initializes and builds an LSA
packet. The LSA contains a list of all recently seen routers and their costs. The LSA is
forwarded only within the area it originated in and is flooded to all other routers in the area. The
information is stored in the link-state database, which is identical on all routers in the AS.

R82.10 Gaia Advanced Routing Administration Guide | 375


IS-IS

IS-IS
Intermediate System to Intermediate System (IS-IS) is an Interior Gateway Protocol (IGP)
used to exchange routing information between routers in a single autonomous system (AS).
IS-IS calculates the best path based on true costs. The true costs are based on metrics a
network administrator configures.
IS-IS supports IPv4 and IPv6 routing in a single protocol.

Best Practice - In complex networks that contain many routers with varying IPv4 /
IPv6 support, we recommend to configure IPv6 Multi-Topology.

For more information about the IS-IS protocol, see the standard ISO/IEC 10589:2002, Second
Edition and RFC 7142.

Note - By design, the IS-IS protocol supports interfaces only with a Linux kernel index
value of less than or equal to 255. See sk183529.

IS-IS Terms
This section describes the primary IS-IS terms important to Check Point's implementation of
the IS-IS protocol.

Term Description

Adjacency A part of the local routing information which pertains to the reachability of
a single neighbor Intermediate System (IS) over a single circuit.
Adjacencies are used as input for forming paths through the routing
domain.
A different adjacency is created for each neighbor on a circuit, and for
each level of routing (Level 1 and Level 2) on a broadcast circuit.

Area A routing subdomain which maintains:


n Detailed routing information about its own internal composition.
n Routing information to reach other routing subdomains.
It corresponds to the Level 1 subdomain.

Broadcast A subnetwork which supports an arbitrary number of Intermediate


Subnetwork Systems (ISs) in the same broadcast domain.

CSNP Complete Sequence Number Protocol Data Unit.


Contains the list of LSP IDs along with sequence number and checksum.
This PDU is used to make sure the database contents are the same on
different Intermediate Systems on the same broadcast link.

R82.10 Gaia Advanced Routing Administration Guide | 376


IS-IS

Term Description

DIS Designated Intermediate System.


The Intermediate System on a LAN, which is designated to perform more
duties.
Specifically, it generates Link State PDUs on behalf of the LAN, treating
the LAN as a pseudonode.

Hello Two neighbor IS-IS routers must exchange 'Hello' packets at intervals to
create adjacency.
Based on the negotiation, one of them is be selected as DIS (Designated
IS).
IS-IS routers send the 'Hello' packets separately for Level 1 and Level 2.

Intermediate This is a "router."


System Acronym: "IS."

Level 1 These Intermediate Systems route directly to systems in their own area,
Intermediate and route to a Level 2 Intermediate System (IS) when the destination
Systems system is in a different area.
By default, they only have visibility to routes in their own Level 1
subdomain.

Level 2 Level 2 Intermediate Systems behave similarly to Level 1, but have


Intermediate visibility to network destinations in all IS-IS areas, not only those that they
Systems are a part of.

LSP Link State Protocol Data Unit.


Contains all routing and neighbor information in a single Intermediate
System.

Neighbor Two Intermediate Systems that share an adjacency are referred to as


"neighbors."

PDU Protocol Data Unit (known as a network packet).

PSNP Partial Sequence Number Protocol Data Unit.

Pseudonode Where a broadcast subnetwork has N connected Intermediate systems,


the broadcast subnetwork itself is considered to be a pseudonode.
The pseudonode has links to each of the N Intermediate and End
systems.
Each IS has a single link to the pseudonode (rather than N-1 links to each
of the other Intermediate systems).
Link State PDUs are generated on behalf of the pseudonode by the
Designated IS.

R82.10 Gaia Advanced Routing Administration Guide | 377


IS-IS

Cluster Support for IS-IS


n Gaia supports the IS-IS protocol in ClusterXL and on Scalable Platforms (Quantum
Maestro and Quantum Scalable Chassis). In this configuration, the cluster becomes a
Virtual Router.
n The neighbor routers see the cluster as a single router, where the Cluster Virtual IP
address and virtual MAC identify the router.
n Each Cluster Member runs the IS-IS process, but only the RouteD daemon in the Master
state actively sends and receives routing information to and from the neighbor routers.
n When a cluster failover occurs, the RouteD daemon on a peer Cluster Member becomes
the RouteD Master and starts to send and receive routing information to and from the
neighbor routers. The cluster uses IS-IS Graceful Restart to keep forwarding capabilities.
ClusterXL

n Gaia ClusterXL advertises the Cluster Virtual IP address.


n The Cluster Member that runs the RouteD in the Master state, synchronizes the IS-IS
routes installed in the routing table to all other Cluster Members.
n During a cluster failover, the RouteD daemon on one of the peer cluster members
becomes the new RouteD Master and then continues where the previous RouteD
Master failed.
n During the time that the new RouteD Master is running the Graceful Restart to
synchronize the route database with neighbor routers, the Cluster Member continues
to forward traffic based on the previous kernel routes until IS-IS routes are fully
synchronized and pushed into the kernel.

Important:
n All Cluster Members must have the same configuration.
n You must enable the "VMAC" feature (see the R82.10 ClusterXL
Administration Guide).

Scalable Platforms

n A Security Group on a Scalable Platforms behaves like ClusterXL.


The Security Group Member that runs the RouteD in the Master state makes the
routing decisions.
n Failover between Security Group Members behave like ClusterXL failovers.

R82.10 Gaia Advanced Routing Administration Guide | 378


IS-IS

Important:
n All Security Group Members must have the same configuration.
n You must enable the "Same VMAC" feature. Follow the instructions in
sk165674.

VRRP Cluster

n VRRP is not supported.

R82.10 Gaia Advanced Routing Administration Guide | 379


Configuring IS-IS in Gaia Portal

Configuring IS-IS in Gaia Portal


Important - On Scalable Platforms, you must connect to the Gaia Portal of the
applicable Security Group.

Procedure
1. With a web browser, connect to the Gaia Portal.
2. Log in.
3. From the left navigation tree, click Advanced Routing > IS-IS.
4. Configure the Global Options:

a. Configure the System ID.


Procedure

i. From the left navigation tree, click Advanced Routing > IS-IS.
ii. In the System ID section, enter the System ID.
The System ID of an IS-IS router uniquely identifies the router in the IS-IS
domain.
The System ID on each IS-IS router must be unique in the IS-IS domain.
The System ID is a 6 byte hex string, separated on two-byte boundaries by
a "." (period).

To remove the System ID you configured explicitly, configure the System


ID to the "default" value.

Example System ID: 1a2b.3c4d.5e6f


iii. Click Apply System ID.

Important:
n In ClusterXL, you must configure the same System ID on each

Cluster Member.
n You cannot change the System ID while IS-IS is already

configured and running.


n To change the System ID while IS-IS is running, first you must

stop the IS-IS protocol in one of these ways:


l Remove all IS-IS areas from the configuration.

l Remove all IS-IS interfaces from the configuration.

R82.10 Gaia Advanced Routing Administration Guide | 380


Configuring IS-IS in Gaia Portal

b. Add at least one Area.


Procedure

i. From the left navigation tree, click Advanced Routing > IS-IS.
ii. In the Area Addresses section, click Add.
iii. In the Area Address field, enter the IS-IS area ID.
An area address is a variable-length string ranging from 1 to 13 bytes.
The first byte of the area address can be two digits (from 00 to 99).
The rest of the area address is represented as a hexadecimal string,
separated on two-byte boundaries by a "." (period).

An IS-IS router’s configured areas determine whether to form 'Level 1'


adjacencies with other routers.
An IS-IS router may belong to multiple areas, up to the configured
maximum number of area addresses.
Example area addresses:
n 49
n 12.34
n 99.1a2b.3c4d
n [Link]

iv. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 381


Configuring IS-IS in Gaia Portal

c. Optional: Configure other global options as required in your IS-IS domain.


Procedure

Global settings apply to the IS-IS router as a whole.


i. From the left navigation tree, click Advanced Routing > IS-IS.
ii. Click Edit Global Options.
iii. Configure the applicable settings.
iv. To configure per-level options:
i. Click one of these:
n Edit Level 1
n Edit Level 2
ii. Configure the applicable settings.
iii. Click OK.
v. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 382


Configuring IS-IS in Gaia Portal

Description of options:
Global Options

Option Description

IS Type Configures the IS-IS levels, on which this IS-IS router


works.
n IS-IS 'Level 1' routers form adjacencies only with

other IS-IS neighbors that are configured in the same


area.
n IS-IS 'Level 2' routers form adjacencies with other

directly connected 'Level 2'-capable IS-IS routers,


regardless of area.
n IS-IS 'Level 1-2' routers form 'Level 1' and 'Level 2'

adjacencies, where appropriate.


Best Practice - To conserve resources, configure an
IS-IS router to work only on the level(s) that the IS-IS
topology requires.
Options:
n Level 1 - Uses 'Level 1' only
n Level 2 - Uses 'Level 2' only
n Level 1-2 - Uses 'Level 1' and 'Level 2'

Default:
n Level 1-2

Broadcast Configures how this IS-IS router adds the padding in its
link hello 'Hello' packets.
padding This field controls the padding for broadcast interfaces.
IS-IS does not advertise what its interface MTU is in 'Hello'
packets.
Instead, it uses 'Hello' padding to make sure that neighbors
have a matching MTU before they form an adjacency.
If the MTU between two neighbors does not match, the
router with the lower MTU drops the padded 'Hello' packet
as malformed and does not form an adjacency.
Options:
n Smart - Adds padding in 'Hello' packets when forming

a new adjacency
n Always - Always adds padding in each 'Hello' packet
n Off - Does not add padding in 'Hello' packets

Default:
n Smart

R82.10 Gaia Advanced Routing Administration Guide | 383


Configuring IS-IS in Gaia Portal

Option Description

P2P link Configures how this IS-IS router adds the padding in its
hello 'Hello' packets.
padding This field controls the padding for point to point interfaces.
IS-IS does not advertise what its interface MTU is in 'Hello'
packets.
Instead, it uses 'Hello' padding to make sure that neighbors
have a matching MTU before they form an adjacency.
If the MTU between two neighbors does not match, the
router with the lower MTU drops the padded 'Hello' packet
as malformed and does not form an adjacency.
Options:
n Smart - Adds padding in 'Hello' packets when forming

a new adjacency
n Always - Always adds padding in each 'Hello' packet
n Off - Does not add padding in 'Hello' packets

Default:
n Smart

LSP lifetime Configures how long other IS-IS routers consider the LSP
packets this IS-IS router generated to be valid.
IS-IS routers periodically update the LSP packets they
generate to make sure these LSP packets are still valid.
Without this update, LSP packets eventually time out of
neighbor routers' databases, and the routers remove the
topology information related to these LSP.
The LSP lifetime determines how long an LSP is
considered valid without an update.
Note - You must configure this value to be greater than
the LSP refresh interval. You must configure a value
that gives enough time between the lifetime and
refresh interval to allow the refreshed LSP to
propagate throughout the IS-IS domain before it can
time out from any other router.
Range: 1 - 65535 (seconds)
Default: 1200

R82.10 Gaia Advanced Routing Administration Guide | 384


Configuring IS-IS in Gaia Portal

Option Description

LSP refresh Configures how frequently this IS-IS router sends updates
interval for its LSP packets.
IS-IS routers periodically update the LSP packets they
generate to make sure these LSP packets are still valid.
Without this update, LSP packets eventually time out of
neighbor routers' databases, and the routers remove the
topology information related to these LSP packets.
Note - You must configure this value to be less than
the LSP lifetime. You must configure a value that
gives enough time between the lifetime and refresh
interval. This allows the refreshed LSP to propagate
throughout the IS-IS domain before it can time out
from any other router.
Range: 1 - 65535 (seconds)
Default: 900

LSP MTU Configures the maximum size of an LSP to send over any
link.
Note - You must configure a value that is less than or
equal to the smallest MTU of an interface that runs IS-
IS, minus 8 bytes of overhead:
LSP MTU value <= (Smallest MTU of an
interface that runs IS-IS) - (8 bytes
of overhead)
For a standard Ethernet interface, this value is 1500 - 8
= 1492 bytes.
Range: 128 - 16000 (bytes)
Default: 1492

R82.10 Gaia Advanced Routing Administration Guide | 385


Configuring IS-IS in Gaia Portal

Option Description

Max area Configures the maximum number of configurable areas for


addresses this IS-IS router.
The maximum number of configurable areas serves two
purposes:
Shows to IS-IS neighbor routers (through a field in 'Hello'
packets) the maximum number of areas, to which this IS-IS
router belongs.
Shows the maximum number of configurable area
addresses.
Note - The default value of 3 area addresses is
sufficient to support most area migration scenarios.
Range: 3 - 254
Default: 3

Send Enables (selected) or disables (cleared) the dynamic


hostname hostname mapping for IS-IS System IDs.
It may be difficult to remember an IS-IS System ID as a
string of numbers.
IS-IS supports the sending of the hostname information
between neighbor routers to associate a System ID with a
hostname.
Options:
n Selected - Sends the local hostname and accepts

neighbors' hostnames
n Cleared - Does not send the local hostname and does

not accept neighbors' hostnames


Default:
n Selected

R82.10 Gaia Advanced Routing Administration Guide | 386


Configuring IS-IS in Gaia Portal

Option Description

Adjacency Enables (selected) or disables (cleared) the strict protocol


check checking with IS-IS neighbors.
During the normal operation, IS-IS neighbors should agree
on which IP protocols they run (IPv4 only, IPv6 only, or the
two of them).
In some cases, it may be necessary to run IS-IS between
neighbors that do not run the same protocols (for example,
maintaining adjacencies while migrating an IPv4-only IS-IS
environment to an environment with IPv4 and IPv6).
If you turn off this feature, this IS-IS router forms
adjacencies with neighbors that do not match the list of IP
protocols this IS-IS router uses for IS-IS.
Options:
n Selected - Enforces the strict protocol checking
n Cleared - Does not enforce the strict protocol

checking
Default:
n Selected

Ignore Controls whether this IS-IS router ignores (selected) or not


attached bit (cleared) the attached bits configured by other 'Level 2'-
connected IS-IS routers.
By default, 'Level 1-2' IS-IS routers do not send routes from
'Level 2' to 'Level 1'.
Instead, they configure an "attached bit" in their packets to
'Level 1' areas.
This attached bit shows that 'Level 1' routers should install
a default route to the 'Level 2' router that configured it.
In some cases, it may be necessary to ignore these
attached bits, and not to install a default route to 'Level 1-2'
routers.
Options:
n Selected - Does not install the default route to the

"attached" routers
n Cleared - Installs the default route to the "attached"

neighbors
Default:
n Cleared

R82.10 Gaia Advanced Routing Administration Guide | 387


Configuring IS-IS in Gaia Portal

Option Description

Set overload Configures options related to the overload bit.


bit IS-IS routers may optionally configure an overload bit in
their 'Hello' packets and the LSP packets they send to other
IS-IS routers.
This bit shows that the router should not be used as a
transit router for routing decisions.
You can configure this bit permanently on routers that are
never intended to pass traffic except to directly connected
subnets.
Options:
n Selected - Enables the overload bit
n Cleared - Does not enable the overload bit

Default:
n Cleared

Per-Level Global Options

Option Description

Default Metric Configures the default metric for all IS-IS interfaces.
This IS-IS router uses this default metric, if you do not
configure another metric explicitly.
Range:
n 1 - 16777214 - Uses the wide metric type
n 1 - 63 - Uses the narrow metric type

Default:
n 10

R82.10 Gaia Advanced Routing Administration Guide | 388


Configuring IS-IS in Gaia Portal

Option Description

Metric Type Configures how this IS-IS router sends metric


information to other IS-IS routers.
IS-IS has two metric types:
n Wide - A new style of metric that supports 24 bits

of data. This gives a maximum value of


16777215.
n Narrow - An old style of metric that uses 6 bits to

store the metric value. This gives a maximum


metric of 63, which was considered too
restrictive.
IS-IS supports narrow and wide metrics for
compatibility with older implementations.
If all routers in an IS-IS domain support wide metrics,
then configure wide metrics because they give greater
flexibility.
The router accepts wide and narrow metric types,
regardless of which types it sends.
Options:
n Wide - Sends the wide metric type only
n Narrow - Sends the narrow metric type only
n Transition - Sends the wide and narrow metric

types
Default:
n Wide

R82.10 Gaia Advanced Routing Administration Guide | 389


Configuring IS-IS in Gaia Portal

Option Description

SPF Delay Configures the delay between subsequent SPF


Intervals calculations.
When the information announced by an IS-IS router
changes the topology, all routers in the domain must
run SPF to create the shortest path tree again.
The SPF interval determines how frequently these
shortest path calculations may occur.
This option uses an exponential backoff to determine
the delay between events.
The delay before events after the "Second" period is
the previous delay multiplied by two, up to the
maximum delay.
If an event does not occur for two "Max" periods, the
router restores the delay to the "Initial" value.
Options:
n Max

Specifies the maximum interval between two


events
l Range: 1 - 120 (seconds)

l Default: 10

n Initial

Specifies the initial delay between when an event


is scheduled, and when it actually takes place.
l Range: 50 - 120000 (milliseconds)

l Default: 5500

n Second

Specifies the delay between the first event and


the second event.
l Range: 50 - 120000 (milliseconds)

l Default: 5500

R82.10 Gaia Advanced Routing Administration Guide | 390


Configuring IS-IS in Gaia Portal

Option Description

Partial Route Configures the delay between subsequent Partial


Calculation Route Calculation (PRC) events.
Delay Intervals When the information announced by an IS-IS router
changes, but the overall topology remains the same,
IS-IS does not need to run an entire SPF calculation.
Instead, it may run a PRC to calculate the change in
routes within the same topology.
The PRC interval determines how frequently these
partial route calculations may occur.
This option uses an exponential backoff to determine
the delay between events.
The delay before events after the "Second" period is
the previous delay multiplied by two, up to the
maximum delay.
If an event does not occur for two "Max" periods, the
router restores the delay to the "Initial" value.
Options:
n Max

Specifies the maximum interval between two


events.
l Range: 1 - 120 (seconds)

l Default: 5

n Initial

Specifies the initial delay between when an event


is scheduled, and when it actually takes place.
l Range: 50 - 120000 (milliseconds)

l Default: 2000

n Second

Specifies the delay between the first event and


the second event.
l Range: 50 - 120000 (milliseconds)

l Default: 5000

R82.10 Gaia Advanced Routing Administration Guide | 391


Configuring IS-IS in Gaia Portal

Option Description

Authentication Configures IS-IS authentication for LSP, CSNP, and


PSNP packets.
You can configure IS-IS authentication for 'Hello'
packets with interface authentication.
When you configure an authentication mode, this IS-IS
router authenticates all outgoing LSP, CSNP, and
PSNP packets using the configured mode. By default,
this IS-IS router also authenticates all incoming IS-IS
packets.
You can disable this behavior with the Gaia Clish
command "authentication ignore <Packet
Type> {on | off} [level {1 | 2}]".
n 'Level 1' authentication applies to all 'Level 1' IS-

IS packets - LSP, CSNP, and PSNP.


n 'Level 2' authentication applies to all 'Level 2' IS-

IS packets - LSP, CSNP, and PSNP.


You can configure only one authentication mode per
level at a time.
Configuration of a new authentication mode removes
the previous mode's configuration.
Options:
n None

No authentication.
n Simple

Enables the simple (plaintext) authentication for


IS-IS packets.
This IS-IS router authenticates IS-IS packets
using a plaintext password that is included with
each IS-IS packet.
If neighbor routers detect a mismatch in
authentication, they drop the packets that have a
mismatched authentication.

R82.10 Gaia Advanced Routing Administration Guide | 392


Configuring IS-IS in Gaia Portal

Option Description

n MD5
Enables the HMAC MD5 authentication for IS-IS
packets.
IS-IS packets include an MD5 digest of the
packet, based on a configured secret key
(Password).
You configure this secret on the router. The
router does not send this secret in plaintext.
As a result, this mode is more secure than the
simple authentication.
If neighbor routers detect a mismatch in
authentication, they ignore the packets with a
mismatched authentication.
i. Click Add.
ii. In the Key ID field, enter the required
number between 1 and 255.
iii. In the Secret field, enter the required
authentication secret.
May contain only letters, digits, and these
characters: ! . , / - _ +
By default, this IS-IS router uses the lowest
configured MD5 Key ID to authenticate outgoing
IS-IS packets.
Use the "Active Key" field to change this
behavior.
The router can use any Key ID to authenticate
incoming IS-IS packets.

R82.10 Gaia Advanced Routing Administration Guide | 393


Configuring IS-IS in Gaia Portal

Option Description

n Cryptographic
Enables the cryptographic authentication for IS-
IS packets.
When using cryptographic authentication, each
key-algorithm-secret triplet must match exactly
on other IS-IS routers that are authenticating the
same packets.
i. Click Add.
ii. In the Key ID field, enter the required
number between 1 and 255.
iii. In the Algorithm field, select the required
algorithm:
l HMAC-SHA-1

l HMAC-SHA-256

l HMAC-SHA-384

l HMAC-SHA-512

iv. In the Secret field, enter the required


authentication secret.
May contain only letters, digits, and these
characters: ! . , / - _ +
By default, this IS-IS router uses the lowest
configured Cryptographic key ID to authenticate
outgoing IS-IS packets.
Use the "Active Key" field to change this
behavior.
The router can use any key ID to authenticate
incoming IS-IS packets.

5. Configure IS-IS interfaces:


Procedure

Important - Configure at least one IS-IS interface.

Interface options apply to each logical interface independently.


a. From the left navigation tree, click Advanced Routing > IS-IS.
b. In the Interfaces section, click Add.
c. In the Interface field, select the applicable interface.
d. In the Address Family field, select the applicable address family.

R82.10 Gaia Advanced Routing Administration Guide | 394


Configuring IS-IS in Gaia Portal

e. Configure other applicable settings.


f. To configure per-Level options:
i. Click one of these:
n Edit Level 1
n Edit Level 2
ii. Configure the applicable settings.
iii. Click OK.
g. Click Save.

Description of options:
Interface Options

Option Description

Interface Name of the interface to configure.

Address Configures the address family on the specified IS-IS interface.


Family IS-IS sends and receives reachability information and calculates
routes for the IP protocols that run on the specified interface.
You must configure the address family to run IS-IS on the
specified interface.
Options:
n IPv4 - Uses IPv4 only
n IPv6 - Uses IPv6 only
n IPv4 and IPv6 - Uses IPv4 and IPv6

Default:
n IPv4 and IPv6

R82.10 Gaia Advanced Routing Administration Guide | 395


Configuring IS-IS in Gaia Portal

Option Description

Circuit Type Configures the IS-IS levels on which this IS-IS interface works.
Usually, IS-IS interfaces works on the same levels the IS-IS
router is configured to support.
If the router supports 'Level 1' and 'Level 2', but a link uses only
one of these levels, you can restrict this link to work on a single
level. This decreases the protocol traffic and resource
consumption.
Note - Use this option only if the IS Type option is
configured with the value "Level 1-2" (its default value). If an
interface is configured to run only at 'Level 1', and the IS-IS
instance only runs at 'Level 2' (or the opposite), the interface
does not run IS-IS.
Options:
n Inherit global IS type - Uses the global value configured in

the "IS Type" field


n Level 1 only - Uses 'Level 1' only
n Level 2 only - Uses 'Level 2' only

Default:
n Inherit global IS type

Hello Configures how this IS-IS routers adds the padding in 'Hello'
padding packets on the specified interface.
This configuration overrides the IS-IS instance configuration for
'Hello' padding.
IS-IS does not show what its interface MTU is in IS-IS 'Hello'
packets.
Instead, it uses 'Hello' padding to make sure that neighbors have
a matching MTU before they form an adjacency.
If the MTU between two neighbors does not match, the router
with the lower MTU drops the padded 'Hello' packet as
malformed and does not form an adjacency.
Options:
n Inherit global setting - Uses the 'Hello' padding

configuration from the IS-IS instance


n Smart - Adds padding in 'Hello' packets when a new

adjacency is forming
n Always - Always adds padding in each 'Hello' packet
n Off - Does not add padding in 'Hello' packets

Default:
n Inherit global setting

R82.10 Gaia Advanced Routing Administration Guide | 396


Configuring IS-IS in Gaia Portal

Option Description

LSP interval Configures the minimum delay between LSP packets this IS-IS
router sends on the specified interface.
Note - The lower the configured number, the faster the IS-IS
converges on IS-IS neighbors, but the higher the system
load on this IS-IS router.
Range: 33 - 4294967295 (milliseconds)
Default: 33

Point to Configures a broadcast IS-IS interface to behave as a point-to-


point point IS-IS interface.
In certain topologies, it may be advantageous to make a
broadcast interface behave as if it is point-to-point.
This prevents the overhead present on broadcast interfaces.
Note - Use this option only if this link has exactly two IS-IS
routers (including this one).
Options:
n Selected - This interface behaves as point-to-point
n Cleared - This interface behaves as broadcast

Default:
n Cleared

Passive Enables (selected) or disables (cleared) passive IS-IS operation


Mode on this interface.
When an IS-IS interface runs in passive mode, it does not send
protocol packets from the specified interface, but the IP
connectivity information related to the interface is still included in
LSP packets the IS-IS router sends from other active IS-IS
interfaces.
This mode is ideal for stub networks.
Note - The IS-IS router enables this mode implicitly on
loopback interfaces.
Options:
n Selected - This interface does not send protocol packets
n Cleared - This interface works as a normal IS-IS interface

Default:
n Cleared

R82.10 Gaia Advanced Routing Administration Guide | 397


Configuring IS-IS in Gaia Portal

Option Description

P2P Note - This option is available only when you select "Point
retransmit to point".
interval This option only applies to point-to-point interfaces.
This option does not apply if the specified interface is not
point-to-point, or is not a broadcast interface that behaves
as point-to-point.
Configures the retransmit interval for LSP packets this IS-IS
routers sends over a point-to-point link.
IS-IS requires an IS-IS router to send acknowledgments for LSP
packets it receives from its neighbor over a point-to-point link.
If this router sends an LSP and does not get this
acknowledgment within the configured retransmit interval, this
router sends the LSP again, until it gets an acknowledgment.
Range: 0 - 65535 (seconds)
Default: 5 seconds

P2P Note - This option is available only when you select "Point
retransmit to point".
throttle This option applies only to point-to-point interfaces.
This option does not apply, if the specified interface is not
point-to-point, or is not a broadcast interface that behaves
as point-to-point.
Configures how frequently this IS-IS router retransmits LSP
packets over a point-to-point link to its neighbor when multiple
packets are waiting to be sent.
Range: 0 - 65535 (milliseconds)
Default: The value of the "LSP interval" parameter for this
interface.

R82.10 Gaia Advanced Routing Administration Guide | 398


Configuring IS-IS in Gaia Portal

Option Description

Advertise Enables (selected) or disables (cleared) the advertising of this


prefix interface's IPv4 prefix to this router's IS-IS neighbors.
By default, IS-IS includes all directly connected routes on the IS-
IS interfaces in its Link State PDUs.
However, in some cases, these routes are not necessary (for
example, transit links which are never used as a final
destination).
In this case, it may be advantageous to not send these prefixes
in LSP packets, so the total IS-IS link state database is smaller.
Options:
n Selected - Sends this interface's IPv4 prefix in IS-IS LSP

packets
n Cleared - Does not send this interface's IPv4 prefix in IS-IS

LSP packets
Default:
n Selected

Advertise Note - This option is available only when IPv6 Multi-


IPv6 prefix Topology is enabled (see "Configuring IS-IS IPv6 Multi-
Topology in Gaia Portal" on page 408).
Enables (selected) or disables (cleared) the advertising of this
interface's IPv6 prefix to this router's IS-IS neighbors.
By default, IS-IS includes all directly connected routes on the IS-
IS interfaces in its Link State PDUs.
However, in some cases, these routes are not necessary (for
example, transit links which are never used as a final
destination).
In this case, it may be advantageous to not send these prefixes
in LSP packets, so the total IS-IS link state database is smaller.
Options:
n Selected - Sends this interface's IPv6 prefix in IS-IS LSP

packets
n Cleared - Does not send this interface's IPv6 prefix in IS-IS

LSP packets
Default:
n Selected

R82.10 Gaia Advanced Routing Administration Guide | 399


Configuring IS-IS in Gaia Portal

Option Description

IP-Reach Enables (selected) or disables (cleared) Bidirectional Forwarding


Detection Detection (BFD) on the specified interface.
If you enable this feature, this IS-IS router creates a BFD session
on the specified interface with all IS-IS neighbors that also have
BFD enabled.
While a BFD session is active between two neighbors, the IS-IS
state responds to changes in the BFD state:
n If the BFD state change to 'Down', then the state of that IS-

IS link also changes to 'Down'.


n If one IS-IS neighbor has BFD enabled and the other

neighbor does not, then these neighbors do not create a


BFD session, and BFD does not have an effect on the
adjacency state.
Notes for IPv6 Multi-Topology:
(See "Configuring IS-IS IPv6 Multi-Topology in Gaia Portal" on
page 408.)
n If you did not enable IPv6 Multi-Topology, then this option

tries to enable BFD for all address families (IPv4, IPv6) that
you configured on the specified interface.
n If you enabled IPv6 Multi-Topology, then this option tries to

enable BFD only for IS-IS neighbors that use IPv4.


Options:
n Selected - Enables BFD for this interface
n Cleared - Disables BFD for this interface

Default:
n Cleared

R82.10 Gaia Advanced Routing Administration Guide | 400


Configuring IS-IS in Gaia Portal

Option Description

IPv6 IP- Note - This option is available only when IPv6 Multi-
Reach Topology is enabled.
Detection Enables (selected) or disables (cleared) Bidirectional Forwarding
Detection (BFD) on the specified interface.
If you enable this feature, this IS-IS router creates a BFD session
on the specified interface with all IS-IS neighbors that also have
BFD enabled.
While a BFD session is active between two neighbors, the IS-IS
state responds to changes in the BFD state:
n If the BFD state change to 'Down', then the state of that IS-

IS link also changes to 'Down'.


n If one IS-IS neighbor has BFD enabled and the other

neighbor does not, then these neighbors do not create a


BFD session, and BFD does not have an effect on the
adjacency state.
Notes for IPv6 Multi-Topology:
(See "Configuring IS-IS IPv6 Multi-Topology in Gaia Portal" on
page 408.)
n If you did not enable IPv6 Multi-Topology, then this option

tries to enable BFD for the IPv6 address you configured on


the specified interface.
n If you enabled IPv6 Multi-Topology, then this option tries to

enable BFD only for IS-IS neighbors that use IPv6.


Options:
n Selected - Enables BFD for this interface
n Cleared - Disables BFD for this interface

Default:
n Cleared

R82.10 Gaia Advanced Routing Administration Guide | 401


Configuring IS-IS in Gaia Portal

Option Description

Mesh group Configures the specified interface as a member of a mesh group.


Usually, when an IS-IS router receives an LSP on one interface,
the router automatically sends this LSP from all other interfaces.
When several IS-IS routers are connected in a tight mesh, LSP
packets are flooded more than is necessary to send database
updates to all IS-IS routers in the domain.
Configuring router interfaces as members of mesh groups
causes routers to send LSP packets more selectively.
This can reduce network traffic.
Options:
n "Blocked"

Does not send LSP packets from this interface.


Warning - Use this option carefully. If enough
interfaces in a mesh are blocked, some routers may
not receive each LSP. As a result, these routers will
have an inconsistent link state database and make
routing errors.
n An integer from 1 to 4294967295

Configures this interface as a member of a mesh group.


When an interface is a member of a mesh group, this IS-IS
router sends LSP packets only from interfaces that are not
members of the same mesh group as the interface on
which the router received this LSP.
Warning - Use this option carefully. If enough
interfaces in a mesh change their state to 'Down', LSP
packets do not get to all members of the domain. As a
result, the database becomes inconsistent, which
leads to routing errors.
n Blank (empty)

Disables mesh grouping for this interface.


This IS-IS router sends all LSP packets it received on other
interfaces from this interface.
This is the default behavior.

R82.10 Gaia Advanced Routing Administration Guide | 402


Configuring IS-IS in Gaia Portal

Per-Level Interface Options

Option Description

Hello Interval Configures how frequently this IS-IS router sends 'Hello'
packets on the specified interface.
This interval need not match other IS-IS routers on the link.
Range:
n 1 - 65535 (seconds)

Default: One of these:


n 10 (if you did not configure the 'Hello' hold time)
n The configured 'Hello' hold time divided by 3 and

rounded down

Hello Holdtime Configures the 'Hello' hold time for the specified interface.
The hold time determines how long other IS-IS routers wait
without receiving a 'Hello' packet from this IS-IS router
before they consider this router as down.
Range:
n 3 - 65535 (seconds)

Default: One of these:


n 30 (if you did not configure the 'Hello' interval)
n The configured 'Hello' interval multiplied by 3

(maximum of 65535)

Metric Configures the metric (cost) related to the specified


interface.
The metric of each link in an IS-IS topology determines the
total cost of a given route to a destination.
Configure a metric on each IS-IS interface on an IS-IS router
based on how much traffic you expect this interface to pass
compared to other IS-IS interfaces.
Options:
n The word Maximum (or maximum) - The SPF

algorithm uses an infinite cost for this interface


n 1 - 16777214 - Uses the wide metric type
n 1 - 63 - Uses the narrow metric type

Default:
n The value configured as the default-metric in the IS-IS

instance configuration.

R82.10 Gaia Advanced Routing Administration Guide | 403


Configuring IS-IS in Gaia Portal

Option Description

Priority Configures the Designated Intermediate System (DIS)


priority for the specified broadcast interface.
On broadcast IS-IS interfaces, the IS-IS router with the
highest priority is automatically elected to be the DIS.
Configure the priority value to get the desired DIS on each
IS-IS link.
Range: 0 - 127
Default: 64

CSNP Interval
Note - This option applies only to broadcast interfaces.

Configures how frequently this IS-IS router sends a CSNP


from the specified interface, if this router is the Designated
Intermediate System (DIS) for this link.
Range: 0 - 65535 (seconds)
Note - The value 0 means this router does not send
CSNP packets
Default: 10

R82.10 Gaia Advanced Routing Administration Guide | 404


Configuring IS-IS in Gaia Portal

Option Description

Authentication Configures IS-IS authentication for 'Hello' packets this


interface sends.
When you configure the authentication, this IS-IS routers
authenticates all 'Hello' packets using the configured
method.
By default, this IS-IS router also authenticates all incoming
'Hello' packets.
You can disable this behavior with the Gaia Clish command
"authentication ignore <Packet Type> {on |
off} [level {1 | 2}]" for the IS-IS instance.
n 'Level 1' authentication applies to all 'Level 1' IS-IS

'Hello' packets sent or received on this interface.


n 'Level 2' authentication applies to all 'Level 2' IS-IS

'Hello' packets sent or received on this interface.


You can configure only one authentication mode per level at
a time.
Configuration of a new authentication mode removes the
previous mode's configuration.
Options:
n None

No authentication.
n Simple

Enables the simple (plaintext) authentication for IS-IS


packets.
This IS-IS router authenticates IS-IS packets using a
plaintext password that is included with each IS-IS
packet.
If neighbor routers detect a mismatch in
authentication, they drop the packets that have a
mismatched authentication.

R82.10 Gaia Advanced Routing Administration Guide | 405


Configuring IS-IS in Gaia Portal

Option Description

n MD5
Enables the HMAC MD5 authentication for IS-IS
packets.
IS-IS packets include an MD5 digest of the packet,
based on a configured secret key (Password).
You configure this secret on the router. The router
does not send this secret in plaintext.
As a result, this mode is more secure than the simple
authentication.
If neighbor routers detect a mismatch in
authentication, they ignore the packets with a
mismatched authentication.
a. Click Add.
b. In the Key ID field, enter the required number
between 1 and 255.
c. In the Secret field, enter the required
authentication secret.
May contain only letters, digits, and these
characters: ! . , / - _ +
By default, this IS-IS router uses the lowest configured
MD5 Key ID to authenticate outgoing IS-IS packets.
Use the "Active Key" field to change this behavior.
The router can use any Key ID to authenticate
incoming IS-IS packets.

R82.10 Gaia Advanced Routing Administration Guide | 406


Configuring IS-IS in Gaia Portal

Option Description

n Cryptographic
Enables the cryptographic authentication for IS-IS
packets.
When using cryptographic authentication, each key-
algorithm-secret triplet must match exactly on other IS-
IS routers that are authenticating the same packets.
a. Click Add.
b. In the Key ID field, enter the required number
between 1 and 255.
c. In the Algorithm field, select the required
algorithm:
l HMAC-SHA-1

l HMAC-SHA-256

l HMAC-SHA-384

l HMAC-SHA-512

d. In the Secret field, enter the required


authentication secret.
May contain only letters, digits, and these
characters: ! . , / - _ +
By default, this IS-IS router uses the lowest configured
Cryptographic key ID to authenticate outgoing IS-IS
packets.
Use the "Active Key" field to change this behavior.
The router can use any key ID to authenticate
incoming IS-IS packets.

R82.10 Gaia Advanced Routing Administration Guide | 407


Configuring IS-IS in Gaia Portal

Configuring IS-IS IPv6 Multi-Topology in Gaia Portal


The IPv6 Multi-Topology configuration allows an IS-IS router to consider IPv4 and IPv6 as
separate routing domains. As a result, it is safer and easier to configure networks that have
mixed support for both IPv4 and IPv6.

Important - IPv6 options in IS-IS only apply when you enable IPv6 Multi-Topology. If
IPv6 Multi-Topology is disabled, IPv6 settings get their values from the non-IPv6
versions of these options, and the IPv6 options do not apply.

1. From the left navigation tree, click Advanced Routing > IS-IS.
2. Click Edit IPv6 Options.
3. In the IPv6 Multi-topology field, select the applicable value.

4. If you selected Transition or On, configure other applicable settings.


5. To configure per-Level options:
a. Click one of these:
n Edit Level 1
n Edit Level 2
b. Configure the applicable settings.
c. Click OK.
6. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 408


Configuring IS-IS in Gaia Portal

Description of options:
IPv6 Options

Option Description

IPv6 Multi- Configures Multi-Topology for IPv6 unicast.


topology Multi-Topology maintains separate topologies for each Multi-Topology, on
which it is enabled.
As a result, IS-IS runs SPF and calculates routes separately for IPv4 and
IPv6.
In addition, adjacencies form as long as there is at least one common
address family supported.
If you enable this feature, this IS-IS router ignores the "adjacency-check"
option (as if it "off").
Options:
n Off
Disables Multi-Topology for IPv6.
This IS-IS router sends only Single-Topology TLVs in LSP packets,
and does not work with other routers that run in the Multi-Topology
mode.
n Transition
Enables the Multi-Topology mode for IPv6.
This IS-IS router sends the Single-Topology and Multi-Topology
TLVs in LSP packets.
The router creates adjacencies with Single-Topology and Multi-
Topology routers, but continues to work in the Single-Topology
mode.
n On
Enables the Multi-Topology mode for IPv6.
This IS-IS router sends only Multi-Topology TLVs in LSP packets.
All IS-IS routers in the area must support Multi-Topology to install
IPv6 routes correctly.
Default:
n Off

R82.10 Gaia Advanced Routing Administration Guide | 409


Configuring IS-IS in Gaia Portal

Option Description

Ignore Use this option to ignore attached bits set by level-2-connected IS-IS IPv6
attached routers.
bit By default, 'Level 1-2' IS-IS routers do not send routes from 'Level 2' to
'Level 1'.
Instead, they configure an "attached bit" in the packets they send to 'Level
1' areas.
This attached bit shows that 'Level 1' routers should install a default route
to the 'Level 2' router that configured it.
In some cases, it may be necessary to ignore these attached bits, and not
install a default route on 'Level 1-2' routers.
Options:
n Selected - Does not install the default route on "attached" routers
n Cleared - Installs the default route on "attached" neighbors
Default:
n Cleared

Set Enables (selected) or disables (cleared) the settings related to the


overload overload bit for IPv6.
bit IS-IS routers may optionally configure an overload bit in the 'Hello' packets
and LSP packets they send to other IS-IS routers.
This bit shows that the router should not be used as a transit router for
routing decisions.
You can configure this bit permanently on routers that are never intended
to pass traffic, except to directly connected subnets.
Options:
n Selected - Enables the overload bit
n Cleared - Does not enable the overload bit
Default:
n Cleared

R82.10 Gaia Advanced Routing Administration Guide | 410


Configuring IS-IS in Gaia Portal

Per-Level IPv6 Options

Option Description

Default Metric Configures the default metric for all IPv6 IS-IS interfaces. The
interface uses this metric if you do not configure another IPv6 metric
explicitly.
Note - The IPv6 metric takes effect only if in the "IPv6 Multi-
topology" field, you selected "On".
Range:
n 1 - 16777214 - Uses the wide metric type
n 1 - 63 - Uses the narrow metric type
Default:
n 10

R82.10 Gaia Advanced Routing Administration Guide | 411


Configuring IS-IS in Gaia Portal

Option Description

SPF Delay Configures the delay between subsequent SPF calculations.


Intervals When the information announced by an IS-IS router changes the
topology, all routers in the domain must run SPF to re-create the
shortest path tree.
The SPF interval determines how frequently these shortest path
calculations may occur.
Note - The IPv6 SPF interval takes effect only if in the "IPv6
Multi-topology" field, you selected "On".
This option uses exponential backoff to determine the delay
between events.
The delay before events after the "Second" period is the previous
delay multiplied by two, up to the maximum delay.
If an event does not occur for two "Max" periods, the router restores
the delay to the "Initial" value.
Options:
n Max
Specifies the maximum interval between two events.
l Range: 1 - 120 (seconds)

l Default: 10

n Initial
Specifies the initial delay between when an event is
scheduled, and when it actually takes place.
l Range: 50 - 120000 (milliseconds)

l Default: 5500

n Second
Specifies the delay between the first event and the second
event.
l Range: 50 - 120000 (milliseconds)

l Default: 5500

R82.10 Gaia Advanced Routing Administration Guide | 412


Configuring IS-IS in Gaia Portal

Option Description

Partial Route Configures the delay between subsequent Partial Route Calculation
Calculation (PRC) events for IPv6.
Delay Intervals This option uses an exponential backoff to determine the delay
between events.
The delay before events after the "Second" period is the previous
delay multiplied by two, up to the maximum delay.
If an event does not occur for two "Max" periods, the router restores
the delay to the "Initial" value.
Options:
n Max
Specifies the maximum interval between two events.
l Range: 1 - 120 (seconds)

l Default: 5

n Initial
Specifies the initial delay between when an event is
scheduled, and when it actually takes place.
l Range: 50 - 120000 (milliseconds)

l Default: 2000

n Second
Specifies the delay between the first event and the second
event.
l Range: 50 - 120000 (milliseconds)

l Default: 5000

R82.10 Gaia Advanced Routing Administration Guide | 413


Configuring IS-IS in Gaia Portal

Restarting IS-IS
1. From the left navigation tree, click Advanced Routing > IS-IS.
2. In the Global Options section, click Restart IS-IS.
3. Click OK to confirm.

R82.10 Gaia Advanced Routing Administration Guide | 414


Configuring IS-IS in Gaia Clish

Configuring IS-IS in Gaia Clish


Important - On Scalable Platforms, you must run the applicable commands in Gaia
gClish of the applicable Security Group.
n To see the available "set" commands for IS-IS, enter in Gaia Clish:

set isis[Esc][Esc]

n To see the available "show" commands for IS-IS, enter in Gaia Clish:

show isis[Esc][Esc]

n To see the available "restart" commands for IS-IS, enter in Gaia Clish:

restart isis[Esc][Esc]

Workflow
1. Connect to the command line.
2. Log into Gaia Clish.
3. Configure the Global Options:
a. Configure the System ID.
b. Add at least one Area.

c. Optional: Configure other global options as required in your IS-IS domain.


See "Configuring IS-IS Global Options" below.

4. Configure IS-IS interfaces:


a. Configure at least one interface with an IS-IS address family.
b. Optional: Configure other interface options as required in your IS-IS domain.
See "Configuring IS-IS Interfaces" on page 441.
5. Save the configuration.

Configuring IS-IS Global Options


Global settings apply to the IS-IS router as a whole.
Some options may be configured for each IS-IS level separately.
By default, if you do not specify the level, the configuration applies to 'Level 1' and 'Level 2'.
If you specify the IS-IS level, the configuration applies only to that level.

R82.10 Gaia Advanced Routing Administration Guide | 415


Configuring IS-IS in Gaia Clish

The output of the "show configuration" command shows the configuration for each IS-IS
level.

R82.10 Gaia Advanced Routing Administration Guide | 416


Configuring IS-IS in Gaia Clish

Syntax

R82.10 Gaia Advanced Routing Administration Guide | 417


Configuring IS-IS in Gaia Clish

set isis
adjacency-check {on | off | default}
area <IS-IS area ID> {on | off}
authentication ignore <Packet Type> {on | off} [level {1 |
2}]
authentication mode
cryptographic
active-key <1-255> [level {1 | 2}]
key <1-255> algorithm <Algorithm>
encrypted-secret <Password Encrypted by
Gaia> [level {1 | 2}]
secret <Clear Text Password> [level {1 |
2}]
md5
active-key <1-255> [level {1 | 2}]
key <1-255>
encrypted-secret <Password Encrypted by
Gaia> [level {1 | 2}]
secret <Clear Text Password> [level {1 |
2}]
none
simple
encrypted-secret <Password Encrypted by Gaia>
[level {1 | 2}]
secret <Clear Text Password> [level {1 | 2}]
default-metric {<1-16777214> | default} [level {1 | 2}]
dynamic-hostname {on | off | default}
export-routemap <Name of Routemap>
off [level {1 | 2}]
preference <1-65535>
family {inet | inet6 | inet-and-inet6} on
[level {1 | 2}]
on [level {1 | 2}]
hello padding {always | off | smart} [interface-type
{broadcast | point-to-point}]
ignore-attached-bit {on | off | default}
is-type {level-1 | level-2 | level-1-2}
lsp
gen-interval max {<1-120> | default} initial {<50-
120000> | default} second {<50-120000> | default} [level {1 |
2}]
lifetime {<1-65535> | default}
mtu {<128-16000> | default}
refresh-interval {<1-65535> | default}

R82.10 Gaia Advanced Routing Administration Guide | 418


Configuring IS-IS in Gaia Clish

max-areas {<3-254> | default}


metric-type {wide | narrow | transition} [level {1 | 2}]
overload-bit {on | off}
prc-interval max {<1-120> | default} initial {<50-120000>
| default} second {<50-120000> | default} [level {1 | 2}]
spf interval max {<1-120> | default} initial {<50-120000>
| default} second {<50-120000> | default} [level {1 | 2}]
system-id <ISO System ID>

Parameters

Parameter Description

adjacency-check {on | Enables (on) or disables (off) the strict protocol


off | default} checking with IS-IS neighbors.
During the normal operation, IS-IS neighbors should
agree on which IP protocols they run (IPv4 only, IPv6
only, or the two of them).
In some cases, it may be necessary to run IS-IS
between neighbors that do not run the same
protocols (for example, maintaining adjacencies
while migrating an IPv4-only IS-IS environment to an
environment with IPv4 and IPv6).
If you turn off this feature, this IS-IS router forms
adjacencies with neighbors that do not match the list
of IP protocols this IS-IS router uses for IS-IS.
Options:
n on - Enforces the strict protocol checking
n off - Does not enforce the strict protocol
checking
Default:
n on

R82.10 Gaia Advanced Routing Administration Guide | 419


Configuring IS-IS in Gaia Clish

Parameter Description

area <IS-IS area ID> {on Adds (on) or removes (off) an ISO area address for
| off} this IS-IS router.
An area address is a variable-length string ranging
from 1 to 13 bytes.
The first byte of the area address can be two digits
(00 to 99).
The rest of the area address is represented as a hex
string, separated on two-byte boundaries by a "."
(period).
An IS-IS router's configured areas determine
whether to form 'Level 1' adjacencies with other
routers.
An IS-IS router may belong to multiple areas, up to
the configured maximum number of area addresses.
Example area addresses:
n 49
n 12.34
n 99.1a2b.3c4d
n [Link]

R82.10 Gaia Advanced Routing Administration Guide | 420


Configuring IS-IS in Gaia Clish

Parameter Description

authentication ignore Controls whether this IS-IS router ignores (on) or not
<Packet Type> {on | off} (off) the authentication of specific types of the
[level {1 | 2}] incoming IS-IS packets. If this IS-IS router ignores
the authentication for a packet type, then this IS-IS
router accepts the packets regardless of any
authentication parameters.
Packet Types:
n all - Controls whether to ignore authentication
of all IS-IS packets
n csnp - Controls whether to ignore
authentication of CSNP packets
n hello - Controls whether to ignore
authentication of Hello packets
n lsp - Controls whether to ignore authentication
of LSP packets
n none - Resets the ignore configuration
(authenticates all packets)
n psnp - Controls whether to ignore
authentication of PSNP packets
Options:
n on - Ignores authentication for the specified
packet type
n off - Does not ignore authentication for the
specified packet type
Default:
n off

Note - If you configured "on" for the specific


packet types, and then it is necessary to
configure "off" for those specific packet types,
then you must do so explicitly for each packet
type.
Configuring "off" for the packet type "all"
does not restore the "off" setting for those
specific packet types.
To restore the "off" setting for all packet types,
use this command:
set isis authentication ignore none
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.

R82.10 Gaia Advanced Routing Administration Guide | 421


Configuring IS-IS in Gaia Clish

Parameter Description

Without this parameter, this command applies to


'Level 1' and 'Level 2' configuration.

authentication mode Configures IS-IS authentication for the incoming and


<Mode> <options> [level outgoing LSP, CSNP, and PSNP packets.
{1 | 2}] You can configure IS-IS authentication for 'Hello'
packets with interface authentication.
When you configure an authentication mode, this IS-
IS router authenticates all outgoing LSP, CSNP, and
PSNP packets using the configured mode.
Level authentication:
n 'Level 1' authentication applies to all 'Level 1'
IS-IS packets - LSP, CSNP, and PSNP.
n 'Level 2' authentication applies to all 'Level 2'
IS-IS packets - LSP, CSNP, and PSNP.

Important:
n You can configure only one authentication
mode per level at a time.
n Configuration of a new authentication
mode removes the previous mode's
configuration.

Note - By default, this IS-IS router also


authenticates all incoming IS-IS packets.
You can disable this behavior with this Gaia
Clish command:
set isis authentication ignore
<Packet Type> {on | off} [level
{1 | 2}]
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 422


Configuring IS-IS in Gaia Clish

Parameter Description

authentication mode Enables the simple (plaintext) authentication for IS-


simple secret <Clear IS packets.
Text Password> [level {1 This IS-IS router authenticates IS-IS packets using a
| 2}] plaintext password that is included with each IS-IS
packet.
If neighbor routers detect a mismatch in
authentication, they drop the packets that have
mismatched authentication.
This command encrypts the specified password and
saves it in the Gaia database.
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

authentication mode Enables the simple (plaintext) authentication for IS-


simple encrypted-secret IS packets.
<Password Encrypted by Important - You must enter the encrypted
Gaia> [level {1 | 2}] authentication secret that Gaia saved in its
database after you ran this command:
set isis authentication mode
simple secret <Clear Text
Password> [level {1 | 2}]
To see the encrypted authentication secret in
the Gaia database, run:
show configuration isis
This IS-IS router authenticates IS-IS packets using a
plaintext password that is included with each IS-IS
packet.
If neighbor routers detect a mismatch in
authentication, they drop the packets that have
mismatched authentication.
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 423


Configuring IS-IS in Gaia Clish

Parameter Description

authentication mode md5 Enables the HMAC MD5 authentication for IS-IS
key <1-255> secret packets.
<Clear Text Password> IS-IS packets include an MD5 digest of the packet,
[level {1 | 2}] based on a configured secret key.
You configure this secret on the router. The router
does not send this secret in plaintext.
As a result, this mode is more secure than the simple
authentication.
This command encrypts the specified password and
saves it in the Gaia database.
If neighbor routers detect a mismatch in
authentication, they ignore the packets with a
mismatched authentication.
Note - By default, this IS-IS router uses the
lowest configured MD5 Key ID to authenticate
outgoing IS-IS packets.
Use this command to change this behavior:
set isis authentication mode md5
active-key <1-255> [level {1 |
2}
If you remove the configured Active Key from
the list of IS-IS authentication keys, the IS-IS
router returns to the default behavior.
The router can use any key ID to authenticate
incoming IS-IS packets.
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 424


Configuring IS-IS in Gaia Clish

Parameter Description

authentication mode md5 Enables the HMAC MD5 authentication for IS-IS
key <1-255> encrypted- packets.
secret <Password Important - You must enter the encrypted
Encrypted by Gaia> authentication secret that Gaia saved in its
[level {1 | 2}] database after you ran this command:
set isis authentication mode md5
key <1-255> secret <Clear Text
Password> [level {1 | 2}]
To see the encrypted authentication secret in
the Gaia database, run:
show configuration isis
You configure this secret on the router. The router
does not send this secret in plaintext.
As a result, this mode is more secure than the simple
authentication.
If neighbor routers detect a mismatch in
authentication, they ignore the packets with a
mismatched authentication.
Note - By default, this IS-IS router uses the
lowest configured MD5 Key ID to authenticate
outgoing IS-IS packets.
Use this command to change this behavior:
set isis authentication mode md5
active-key <1-255> [level {1 |
2}
If you remove the configured Active Key from
the list of IS-IS authentication keys, the IS-IS
router returns to the default behavior.
The router can use any key ID to authenticate
incoming IS-IS packets.
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 425


Configuring IS-IS in Gaia Clish

Parameter Description

authentication mode Enables the cryptographic authentication for IS-IS


cryptographic key <1- packets.
255> algorithm When using cryptographic authentication, each key-
<Algorithm> secret algorithm-secret triplet must match exactly on other
<Clear Text Password> IS-IS routers that are authenticating the same
[level {1 | 2}] packets.
Supported Cryptographic Algorithms:
n hmac-sha-1
n hmac-sha-256
n hmac-sha-384
n hmac-sha-512

This command encrypts the specified password and


saves it in the Gaia database.
Note - By default, this IS-IS router uses the
lowest configured Cryptographic key ID to
authenticate outgoing IS-IS packets.
Use this command to change this behavior:
set isis authentication mode
cryptographic active-key <1-255>
[level {1 | 2}]
If you remove the configured Active Key from
the list of IS-IS authentication keys, the IS-IS
router returns to the default behavior.
The router can use any key ID to authenticate
incoming IS-IS packets.
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 426


Configuring IS-IS in Gaia Clish

Parameter Description

authentication mode Enables the cryptographic authentication for IS-IS


cryptographic key <1- packets.
255> algorithm Important - You must enter the encrypted
<Algorithm> encrypted- authentication secret that Gaia saved in its
secret <Password database after you ran this command:
Encrypted by Gaia>
authentication mode
[level {1 | 2}]
cryptographic key <1-255>
algorithm <Algorithm> secret
<Clear Text Password> [level {1
| 2}]
To see the encrypted authentication secret in
the Gaia database, run:
show configuration isis
When using cryptographic authentication, each key-
algorithm-secret triplet must match exactly on other
IS-IS routers that are authenticating the same
packets.
Supported Cryptographic Algorithms:
n hmac-sha-1
n hmac-sha-256
n hmac-sha-384
n hmac-sha-512

Note - By default, this IS-IS router uses the


lowest configured Cryptographic key ID to
authenticate outgoing IS-IS packets.
Use this command to change this behavior:
set isis authentication mode
cryptographic active-key <1-255>
[level {1 | 2}]
If you remove the configured Active Key from
the list of IS-IS authentication keys, the IS-IS
router returns to the default behavior.
The router can use any key ID to authenticate
incoming IS-IS packets.
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 427


Configuring IS-IS in Gaia Clish

Parameter Description

authentication mode none Disables authentication for IS-IS packets.


[level {1 | 2}] Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

default-metric {<1- Configures the default metric for all IS-IS interfaces.
16777214> | default} This IS-IS router uses this default metric, if you do
[level {1 | 2}] not configure another metric explicitly.
Range:
n 1 - 16777214 - Uses the wide metric type
n 1 - 63 - Uses the narrow metric type
Default:
n 10
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

dynamic-hostname {on | Enables (on) or disables (off) the dynamic


off | default} hostname mapping for IS-IS System IDs.
It may be difficult to remember an IS-IS System ID as
a string of numbers.
IS-IS supports the sending of the hostname
information between neighbor routers to associate a
System ID with a hostname.
Options:
n on - Sends the local hostname and accepts
neighbors' hostnames
n off - Does not send the local hostname and
does not accept neighbors' hostnames
Default:
n on

R82.10 Gaia Advanced Routing Administration Guide | 428


Configuring IS-IS in Gaia Clish

Parameter Description

export-routemap Controls the export of routes into IS-IS.


{<options>} For more details on how to use Gaia Clish to
configure routemaps, refer to sk100501.
Route Maps determine which routes are exported
and optionally modify various properties of the routes
as they are exported.
Route Maps control which routes are accepted
and/or announced.
Similar to Route Redistribution Rules, Route Maps
can export routes from one or more protocols.
However, Route Maps have additional capabilities
and provide finer-grained control.
Important - If Route Maps are configured for IS-
IS, all Route Redistribution Rules related to IS-
IS are disabled automatically.

export-routemap <Name of Disables the export of routes into IS-IS for the
Routemap> off [level {1 specified routemap.
| 2}] Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

export-routemap <Name of Enables the export of routes for the specific IP


Routemap> preference <1- address family into IS-IS for the specified routemap.
65535> family {inet | For more details on how to use Gaia Clish to
inet6 | inet-and-inet6} configure routemaps, refer to sk100501.
on [level {1 | 2}] Options:
n inet - For IPv4 routes only
n inet6 - For IPv6 routes only
n inet-and-inet6 - For IPv4 and IPv6 routes
Default:
n inet-and-inet6

Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 429


Configuring IS-IS in Gaia Clish

Parameter Description

export-routemap <Name of Enables the export of routes into IS-IS for the
Routemap> preference <1- specified routemap.
65535> on [level {1 | For more details on how to use Gaia Clish to
2}] configure routemaps, refer to sk100501.
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

hello padding {always | Configures how this IS-IS router adds the padding in
off | smart} [interface- its 'Hello' packets.
type {broadcast | point- IS-IS does not advertise what its interface MTU is in
to-point}] 'Hello' packets.
Instead, it uses 'Hello' padding to make sure that
neighbors have a matching MTU before they form an
adjacency.
If the MTU between two neighbors does not match,
the router with the lower MTU drops the padded
'Hello' packet as malformed and does not form an
adjacency.
Options:
n always - Always adds padding in each 'Hello'
packet
n off - Does not add padding in 'Hello' packets
n smart - Adds padding in 'Hello' packets when
forming a new adjacency

Default:
n smart

Optional:
Use the additional "interface-type" parameter
to apply the 'Hello' packet padding to a specific
interface type.
If you do not use this parameter, the padding of
'Hello' packets applies to all interface types.
n interface-type broadcast - Applies to
broadcast interfaces only
n interface-type point-to-point -
Applies to point-to-point interfaces only

R82.10 Gaia Advanced Routing Administration Guide | 430


Configuring IS-IS in Gaia Clish

Parameter Description

ignore-attached-bit {on Controls whether this IS-IS router ignores (on) or not
| off | default} (off) the attached bits configured by other 'Level 2'-
connected IS-IS routers.
By default, 'Level 1-2' IS-IS routers do not send
routes from 'Level 2' to 'Level 1'.
Instead, they configure an "attached bit" in their
packets to 'Level 1' areas.
This attached bit shows that 'Level 1' routers should
install a default route to the 'Level 2' router that
configured it.
In some cases, it may be necessary to ignore these
attached bits, and not to install a default route to
'Level 1-2' routers.
Options:
n on - Does not install the default route to the
"attached" routers
n off - Installs the default route to the "attached"
neighbors
Default:
n off

R82.10 Gaia Advanced Routing Administration Guide | 431


Configuring IS-IS in Gaia Clish

Parameter Description

is-type {level-1 | Configures the IS-IS levels, on which this IS-IS


level-2 | level-1-2} router works.
IS-IS 'Level 1' routers form adjacencies only with
other IS-IS neighbors that are configured in the same
area.
IS-IS 'Level 2' routers form adjacencies with other
directly connected 'Level 2'-capable IS-IS routers,
regardless of area.
IS-IS 'Level 1-2' routers form 'Level 1' and 'Level 2'
adjacencies, where appropriate.
Best Practice - To conserve resources,
configure an IS-IS router to work only on the
level(s) that the IS-IS topology requires.
Options:
n level-1 - Uses 'Level 1' only
n level-2 - Uses 'Level 2' only
n level-1-2 - Uses 'Level 1' and 'Level 2'
Default:
n level-1-2

R82.10 Gaia Advanced Routing Administration Guide | 432


Configuring IS-IS in Gaia Clish

Parameter Description

lsp gen-interval max Configures the delay before this IS-IS router
{<1-120> | default} generates an LSP packet again.
initial {<50-120000> | When an LSP must be generated again, it is delayed
default} second {<50- by a specified time period to prevent flooding the
120000> | default} same LSP in rapid succession.
[level {1 | 2}] This configuration option determines how to
calculate this delay.
This option uses an exponential backoff to determine
the delay between events.
The delay before events after the "second" period is
the previous delay multiplied by two, up to the
maximum delay.
If an event does not occur for two "max" periods, the
router restores the delay to the "initial" value.
n The "max" option:
Specifies the maximum interval between two
events
l Range: 1 - 120 (seconds)

l Default: 5

n The "initial" option:


Specifies the initial delay between when an
event is scheduled, and when it actually takes
place.
l Range: 50 - 120000 (milliseconds)

l Default: 50

n The "second" option:


Specifies the delay between the first event and
the second event.
l Range: 50 - 120000 (milliseconds)

l Default: 5000

Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 433


Configuring IS-IS in Gaia Clish

Parameter Description

lsp lifetime {<1-65535> Configures how long other IS-IS routers consider the
| default} LSP packets this IS-IS router generated to be valid.
IS-IS routers periodically update the LSP packets
they generate to make sure these LSP packets are
still valid.
Without this update, LSP packets eventually time out
of neighbor routers' databases, and the routers
remove the topology information related to these
LSP.
The LSP lifetime determines how long an LSP is
considered valid without an update.
Note - You must configure this value to be
greater than the "lsp refresh-interval".
You must configure a value that gives enough
time between the lifetime and refresh interval to
allow the refreshed LSP to propagate
throughout the IS-IS domain before it can time
out from any other router.
Range: 1 - 65535 (seconds)
Default: 1200

lsp mtu {<128-16000> | Configures the maximum size of an LSP to send


default} over any link.
Note - You must configure a value that is less
than or equal to the smallest MTU of an
interface that runs IS-IS, minus 8 bytes of
overhead:
LSP MTU value <= (Smallest MTU
of an interface that runs IS-IS)
- (8 bytes of overhead)
For a standard Ethernet interface, this value is
1500 - 8 = 1492 bytes.
Range: 128 - 16000 (bytes)
Default: 1492

R82.10 Gaia Advanced Routing Administration Guide | 434


Configuring IS-IS in Gaia Clish

Parameter Description

lsp refresh-interval Configures how frequently this IS-IS router sends


{<1-65535> | default} updates for its LSP packets.
IS-IS routers periodically update the LSP packets
they generate to make sure these LSP packets are
still valid.
Without this update, LSP packets eventually time out
of neighbor routers' databases, and the routers
remove the topology information related to these
LSP.
Note - You must configure this value to be less
than the "lsp lifetime". You must configure
a value that gives enough time between the
lifetime and refresh interval. This allows the
refreshed LSP to propagate throughout the IS-
IS domain before it can time out from any other
router.
Range: 1 - 65535 (seconds)
Default: 900

max-areas {<3-254> | Configures the maximum number of configurable


default} areas for this IS-IS router.
The maximum number of configurable areas serves
two purposes:
Shows to IS-IS neighbor routers (through a field in
'Hello' packets) the maximum number of areas, to
which this IS-IS router belongs.
Shows the maximum number of configurable area
addresses.
Note - The default value of 3 area addresses is
sufficient to support most area migration
scenarios.
Range: 3 - 254
Default: 3

R82.10 Gaia Advanced Routing Administration Guide | 435


Configuring IS-IS in Gaia Clish

Parameter Description

metric-type {wide | Configures how this IS-IS router sends metric


narrow | transition} information to other IS-IS routers.
[level {1 | 2}] IS-IS has two metric types:
n Wide - A new style of metric that supports 24
bits of data. This gives a maximum value of
16777215.
n Narrow - An old style of metric that uses 6 bits
to store the metric value. This gives a
maximum metric of 63, which was considered
too restrictive.

IS-IS supports narrow and wide metrics for


compatibility with older implementations.
If all routers in an IS-IS domain support wide metrics,
then configure wide metrics because they give
greater flexibility.
The router accepts wide and narrow metric types,
regardless of which types it sends.
Options:
n wide - Sends the wide metric type only
n narrow - Sends the narrow metric type only
n transition - Sends the wide and narrow
metric types

Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 436


Configuring IS-IS in Gaia Clish

Parameter Description

overload-bit {on | off} Enables (on) or disables (off) the settings related to
the overload bit for IPv6.
IS-IS routers may optionally configure an overload
bit in the 'Hello' packets and LSP packets they send
to other IS-IS routers.
This bit shows that the router should not be used as
a transit router for routing decisions.
You can configure this bit permanently on routers
that are never intended to pass traffic, except to
directly connected subnets.
Options:
n on - Enables the overload bit
n off - Does not enable the overload bit
Default:
n off

R82.10 Gaia Advanced Routing Administration Guide | 437


Configuring IS-IS in Gaia Clish

Parameter Description

prc-interval {<options>} Configures the delay between subsequent Partial


Route Calculation (PRC) events for IPv6.
This option uses an exponential backoff to determine
the delay between events.
The delay before events after the "second" period is
the previous delay multiplied by two, up to the
maximum delay.
If an event does not occur for two "max" periods, the
router restores the delay to the "initial" value.
Options:
n The "max" option:
Specifies the maximum interval between two
events.
l Range: 1 - 120 (seconds)

l Default: 5

n The "initial" option:


Specifies the initial delay between when an
event is scheduled, and when it actually takes
place.
l Range: 50 - 120000 (milliseconds)

l Default: 2000

n The "second" option:


Specifies the delay between the first event and
the second event.
l Range: 50 - 120000 (milliseconds)

l Default: 5000

Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 438


Configuring IS-IS in Gaia Clish

Parameter Description

spf interval {<options>} Configures the delay between subsequent SPF


calculations.
When the information announced by an IS-IS router
changes the topology, all routers in the domain must
run SPF to re-create the shortest path tree.
The SPF interval determines how frequently these
shortest path calculations may occur.
This option uses exponential backoff to determine
the delay between events.
The delay before events after the "second" period is
the previous delay multiplied by two, up to the
maximum delay.
If an event does not occur for two "max" periods, the
router restores the delay to the "initial" value.
Options:
n The "max" option:
Specifies the maximum interval between two
events.
l Range: 1 - 120 (seconds)

l Default: 10

n The "initial" option:


Specifies the initial delay between when an
event is scheduled, and when it actually takes
place.
l Range: 50 - 120000 (milliseconds)

l Default: 5500

n The "second" option:


Specifies the delay between the first event and
the second event.
l Range: 50 - 120000 (milliseconds)

l Default: 5500

Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 439


Configuring IS-IS in Gaia Clish

Parameter Description

system-id <ISO System Configures the System ID for this IS-IS router.
ID> The System ID of an IS-IS router uniquely identifies
the router in the IS-IS domain. This System ID on
each IS-IS router must be unique in the IS-IS
domain.
In ClusterXL, and Scalable Platform, you must
configure the same System ID on each Cluster
Member and Security Group Member.
You cannot change the System ID while IS-IS is
already configured and running.
To change the System ID while IS-IS is running, first
you must stop the IS-IS protocol in one of these
ways:
n Remove all IS-IS areas from the configuration
n Remove all IS-IS interfaces from the
configuration
The System ID is a 6 byte hex string, separated on
two-byte boundaries by a "." (period). To remove the
System ID you configured explicitly, configure the
System ID to the "default" value.
Example System ID:
1a2b.3c4d.5e6f

R82.10 Gaia Advanced Routing Administration Guide | 440


Configuring IS-IS in Gaia Clish

Configuring IS-IS Interfaces


Interface options apply to each logical interface independently.
You must configure the address family on an interface before it can run IS-IS.

R82.10 Gaia Advanced Routing Administration Guide | 441


Configuring IS-IS in Gaia Clish

Syntax

set isis interface <Name of Interface>


address-family {ipv4 | ipv6 | ipv4-and-ipv6}
advertise {on | off | default}
authentication
cryptographic
active-key <1-255> [level {1 | 2}]
key <1-255> algorithm <Algorithm>
encrypted-secret <Password Encrypted by
Gaia> [level {1 | 2}]
secret <Clear Text Password> [level {1 |
2}]
md5
active-key <1-255> [level {1 | 2}]
key <1-255>
encrypted-secret <Password Encrypted by
Gaia> [level {1 | 2}]
secret <Clear Text Password> [level {1 |
2}]
none
simple
encrypted-secret <Password Encrypted by Gaia>
[level {1 | 2}]
secret <Clear Text Password> [level {1 | 2}]
circuit-type {level-1 | level-2 | level-1-2}
csnp-interval {<0-65535> | default} [level {1 | 2}]
hello
holdtime {<3-65535> | default} [level {1 | 2}]
interval {<1-65535> | default} [level {1 | 2}]
padding {always | global | off | smart}
ip-reachability-detection {on | off | default}
lsp-interval {<33-4294967295> | default}
mesh-group
blocked
group <1-4294967295>
off
metric {<1-16777214> | default | maximum} [level {1 | 2}]
off
passive-mode {on | off | default}
point-to-point
{on | off}
retransmit-interval {<0-65535> | default}
retransmit-throttle-interval {<0-65535> | default}
priority {<0-127> | default} [level {1 | 2}]

R82.10 Gaia Advanced Routing Administration Guide | 442


Configuring IS-IS in Gaia Clish

Parameters

Parameter Description

address-family {ipv4 | Configures the address family on the specified IS-IS


ipv6 | ipv4-and-ipv6} interface.
IS-IS sends and receives reachability information
and calculates routes for the IP protocols that run on
the specified interface.
You must configure the address family to run IS-IS
on the specified interface.
Options:
n ipv4 - Uses IPv4 only
n ipv6 - Uses IPv6 only
n ipv4-and-ipv6 - Uses IPv4 and IPv6
Default:
n ipv4-and-ipv6

advertise {on | off | Enables (on) or disables (off) the advertising of


default} this interface's IPv4 prefix to this router's IS-IS
neighbors.
By default, IS-IS includes all directly connected
routes on the IS-IS interfaces in its Link State PDUs.
However, in some cases, these routes are not
necessary (for example, transit links which are
never used as a final destination).
In this case, it may be advantageous to not send
these prefixes in LSP packets, so the total IS-IS link
state database is smaller.
Options:
n on - Sends this interface's IPv4 prefix in IS-IS
LSP packets
n off - Does not send this interface's IPv4
prefix in IS-IS LSP packets
Default:
n on

R82.10 Gaia Advanced Routing Administration Guide | 443


Configuring IS-IS in Gaia Clish

Parameter Description

authentication <Mode> Configures IS-IS authentication for the incoming


<options> [level {1 | 2}] and outgoing LSP, CSNP, and PSNP packets.
You can configure IS-IS authentication for 'Hello'
packets with interface authentication.
When you configure an authentication mode, this
IS-IS router authenticates all outgoing LSP, CSNP,
and PSNP packets using the configured mode.
Level authentication:
n 'Level 1' authentication applies to all 'Level 1'
IS-IS packets - LSP, CSNP, and PSNP.
n 'Level 2' authentication applies to all 'Level 2'
IS-IS packets - LSP, CSNP, and PSNP.

Important:
n You can configure only one
authentication mode per level at a time.
n Configuration of a new authentication
mode removes the previous mode's
configuration.

Note - By default, this IS-IS router also


authenticates all incoming IS-IS packets.
You can disable this behavior with this Gaia
Clish command:
set isis authentication ignore
<Packet Type> {on | off} [level
{1 | 2}]
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 444


Configuring IS-IS in Gaia Clish

Parameter Description

authentication simple Enables the simple (plaintext) authentication for IS-


secret <Clear Text IS packets.
Password> [level {1 | 2}] This IS-IS router authenticates IS-IS packets using
a plaintext password that is included with each IS-IS
packet.
If neighbor routers detect a mismatch in
authentication, they drop the packets that have
mismatched authentication.
This command encrypts the specified password and
saves it in the Gaia database.
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

authentication simple Enables the simple (plaintext) authentication for IS-


encrypted-secret IS packets.
<Password Encrypted by Important - You must enter the encrypted
Gaia> [level {1 | 2}] authentication secret that Gaia saved in its
database after you ran this command:
set isis authentication mode
simple secret <Clear Text
Password> [level {1 | 2}]
To see the encrypted authentication secret in
the Gaia database, run:
show configuration isis
This IS-IS router authenticates IS-IS packets using
a plaintext password that is included with each IS-IS
packet.
If neighbor routers detect a mismatch in
authentication, they drop the packets that have
mismatched authentication.
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 445


Configuring IS-IS in Gaia Clish

Parameter Description

authentication md5 key Enables the HMAC MD5 authentication for IS-IS
<1-255> secret <Clear packets.
Text Password> [level {1 IS-IS packets include an MD5 digest of the packet,
| 2}] based on a configured secret key.
You configure this secret on the router. The router
does not send this secret in plaintext.
As a result, this mode is more secure than the
simple authentication.
This command encrypts the specified password and
saves it in the Gaia database.
If neighbor routers detect a mismatch in
authentication, they ignore the packets with a
mismatched authentication.
Note - By default, this IS-IS router uses the
lowest configured MD5 Key ID to authenticate
outgoing IS-IS packets.
Use this command to change this behavior:
set isis authentication mode md5
active-key <1-255> [level {1 |
2}
If you remove the configured Active Key from
the list of IS-IS authentication keys, the IS-IS
router returns to the default behavior.
The router can use any key ID to authenticate
incoming IS-IS packets.
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 446


Configuring IS-IS in Gaia Clish

Parameter Description

authentication md5 key Enables the HMAC MD5 authentication for IS-IS
<1-255> encrypted-secret packets.
<Password Encrypted by Important - You must enter the encrypted
Gaia> [level {1 | 2}] authentication secret that Gaia saved in its
database after you ran this command:
set isis authentication mode md5
key <1-255> secret <Clear Text
Password> [level {1 | 2}]
To see the encrypted authentication secret in
the Gaia database, run:
show configuration isis
You configure this secret on the router. The router
does not send this secret in plaintext.
As a result, this mode is more secure than the
simple authentication.
If neighbor routers detect a mismatch in
authentication, they ignore the packets with a
mismatched authentication.
Note - By default, this IS-IS router uses the
lowest configured MD5 Key ID to authenticate
outgoing IS-IS packets.
Use this command to change this behavior:
set isis authentication mode md5
active-key <1-255> [level {1 |
2}
If you remove the configured Active Key from
the list of IS-IS authentication keys, the IS-IS
router returns to the default behavior.
The router can use any key ID to authenticate
incoming IS-IS packets.
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 447


Configuring IS-IS in Gaia Clish

Parameter Description

authentication Enables the cryptographic authentication for IS-IS


cryptographic key <1-255> packets.
algorithm <Algorithm> When using cryptographic authentication, each key-
secret <Clear Text algorithm-secret triplet must match exactly on other
Password> [level {1 | 2}] IS-IS routers that are authenticating the same
packets.
Supported Cryptographic Algorithms:
n hmac-sha-1
n hmac-sha-256
n hmac-sha-384
n hmac-sha-512

This command encrypts the specified password and


saves it in the Gaia database.
Note - By default, this IS-IS router uses the
lowest configured Cryptographic key ID to
authenticate outgoing IS-IS packets.
Use this command to change this behavior:
set isis authentication mode
cryptographic active-key <1-255>
[level {1 | 2}]
If you remove the configured Active Key from
the list of IS-IS authentication keys, the IS-IS
router returns to the default behavior.
The router can use any key ID to authenticate
incoming IS-IS packets.
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 448


Configuring IS-IS in Gaia Clish

Parameter Description

authentication Enables the cryptographic authentication for IS-IS


cryptographic key <1-255> packets.
algorithm <Algorithm> Important - You must enter the encrypted
encrypted-secret authentication secret that Gaia saved in its
<Password Encrypted by database after you ran this command:
Gaia> [level {1 | 2}]
authentication mode
cryptographic key <1-255>
algorithm <Algorithm> secret
<Clear Text Password> [level {1
| 2}]
To see the encrypted authentication secret in
the Gaia database, run:
show configuration isis
When using cryptographic authentication, each key-
algorithm-secret triplet must match exactly on other
IS-IS routers that are authenticating the same
packets.
Supported Cryptographic Algorithms:
n hmac-sha-1
n hmac-sha-256
n hmac-sha-384
n hmac-sha-512

Note - By default, this IS-IS router uses the


lowest configured Cryptographic key ID to
authenticate outgoing IS-IS packets.
Use this command to change this behavior:
set isis authentication mode
cryptographic active-key <1-255>
[level {1 | 2}]
If you remove the configured Active Key from
the list of IS-IS authentication keys, the IS-IS
router returns to the default behavior.
The router can use any key ID to authenticate
incoming IS-IS packets.
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 449


Configuring IS-IS in Gaia Clish

Parameter Description

authentication none Disables authentication for IS-IS packets.


[level {1 | 2}] Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

circuit-type {level-1 | Configures the IS-IS levels on which this IS-IS


level-2 | level-1-2} interface works.
Usually, IS-IS interfaces works on the same levels
the IS-IS router is configured to support.
If the router supports 'Level 1' and 'Level 2', but a
link uses only one of these levels, you can restrict
this link to work on a single level.
This decreases the protocol traffic and resource
consumption.
Note - Use this command only if the IS-IS "is-
type" option is configured with the value
"level-1-2" (its default value). If an interface
is configured to run only at 'Level 1', and the IS-
IS instance only runs at 'Level 2' (or the
opposite), the interface does not run IS-IS.

csnp-interval {<0-65535> Note - This command applies only to broadcast


| default} [level {1 | interfaces.
2}] Configures how frequently this IS-IS router sends a
CSNP from the specified interface, if this router is
the Designated Intermediate System (DIS) for this
link.
Range:
n 0 - 65535 (seconds)
Note - The value 0 means this router
does not send CSNP packets.

Default:
n 10
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 450


Configuring IS-IS in Gaia Clish

Parameter Description

hello holdtime {<3-65535> Configures the 'Hello' hold time for the specified
| default} [level {1 | interface.
2}] The hold time determines how long other IS-IS
routers wait without receiving a 'Hello' packet from
this IS-IS router before they consider this router as
down.
Range:
n 3 - 65535 (seconds)
Default: One of these:
n 30 (if you did not configure the 'Hello' interval)
n The configured 'Hello' interval multiplied by 3
(maximum of 65535)
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

hello interval {<1-65535> Configures how frequently this IS-IS router sends
| default} [level {1 | 'Hello' packets on the specified interface.
2}] This interval need not match other IS-IS routers on
the link.
Range:
n 1 - 65535 (seconds)

Default: One of these:


n 10 (if you did not configure the 'Hello' hold
time)
n The configured 'Hello' hold time divided by 3
(rounded down)
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 451


Configuring IS-IS in Gaia Clish

Parameter Description

hello padding {always | Configures how this IS-IS routers adds the padding
global | off | smart} in 'Hello' packets on the specified interface.
This configuration overrides the IS-IS instance
configuration for 'Hello' padding.
IS-IS does not show what its interface MTU is in IS-
IS 'Hello' packets.
Instead, it uses 'Hello' padding to make sure that
neighbors have a matching MTU before they form
an adjacency.
If the MTU between two neighbors does not match,
the router with the lower MTU drops the padded
'Hello' packet as malformed and does not form an
adjacency.
Options:
n always - Always adds padding in each 'Hello'
packet
n global - Uses the 'Hello' padding
configuration from the IS-IS instance
n off - Does not add padding in 'Hello' packets
n smart - Adds padding in 'Hello' packets when
a new adjacency is forming
Default:
n global

R82.10 Gaia Advanced Routing Administration Guide | 452


Configuring IS-IS in Gaia Clish

Parameter Description

ip-reachability-detection Enables (on) or disables (off) Bidirectional


{on | off | default} Forwarding Detection (BFD) on the specified
interface.
If you enable this feature, this IS-IS router creates a
BFD session on the specified interface with all IS-IS
neighbors that also have BFD enabled.
While a BFD session is active between two
neighbors, the IS-IS state responds to changes in
the BFD state:
n If the BFD state change to 'Down', then the
state of that IS-IS link also changes to 'Down'.
n If one IS-IS neighbor has BFD enabled and
the other neighbor does not, then these
neighbors do not create a BFD session, and
BFD does not have an effect on the adjacency
state.
Notes for IPv6 Multi-Topology:
n If you did not enable IPv6 Multi-Topology,
then this command tries to enable BFD for all
address families (IPv4, IPv6) that you
configured on the specified interface.
n If you enabled IPv6 Multi-Topology, then this
command tries to enable BFD only for IS-IS
neighbors that use IPv4.
Options:
n on - Enables BFD for this interface
n off - Disables BFD for this interface
Default:
n off

lsp-interval {<33- Configures the minimum delay between LSP


4294967295> | default} packets this IS-IS router sends on the specified
interface.
Note - The lower the configured number, the
faster the IS-IS converges on IS-IS neighbors,
but the higher the system load on this IS-IS
router.
Range: 33 - 4294967295 (milliseconds)
Default: 33

R82.10 Gaia Advanced Routing Administration Guide | 453


Configuring IS-IS in Gaia Clish

Parameter Description

mesh-group {<options>} Configures the specified interface as a member of a


mesh group.
Usually, when an IS-IS router receives an LSP on
one interface, the router automatically sends this
LSP from all other interfaces.
When several IS-IS routers are connected in a tight
mesh, LSP packets are flooded more than is
necessary to send database updates to all IS-IS
routers in the domain.
Configuring router interfaces as members of mesh
groups causes routers to send LSP packets more
selectively.
This can reduce network traffic.
Options:
n blocked
Does not send LSP packets from this
interface.
Warning - Use this option carefully. If
enough interfaces in a mesh are blocked,
some routers may not receive each LSP.
As a result, these routers will have an
inconsistent link state database and
make routing errors.
n group <1-4294967295>
Configures this interface as a member of a
mesh group.
When an interface is a member of a mesh
group, this IS-IS router sends LSP packets
only from interfaces that are not members of
the same mesh group as the interface on
which the router received this LSP.
Warning - Use this option carefully. If
enough interfaces in a mesh change their
state to 'Down', LSP packets do not get to
all members of the domain. As a result,
the database becomes inconsistent,
which leads to routing errors.
n off
Disables mesh grouping for this interface.
This IS-IS router sends all LSP packets it
received on other interfaces from this
interface.

R82.10 Gaia Advanced Routing Administration Guide | 454


Configuring IS-IS in Gaia Clish

Parameter Description

This is the default behavior.


Range: 1 - 4294967295
Default: No mesh group

metric {<1-16777214> | Configures the metric (cost) related to the specified


default | maximum} [level interface.
{1 | 2}] The metric of each link in an IS-IS topology
determines the total cost of a given route to a
destination.
Configure a metric on each IS-IS interface on an IS-
IS router based on how much traffic you expect this
interface to pass compared to other IS-IS
interfaces.
Supported Values:
n "maximum" - The SPF algorithm uses an
infinite cost for this interface
n 1 - 16777214 - Uses the wide metric type
n 1 - 63 - Uses the narrow metric type
Default:
n The value configured as the default-metric in
the IS-IS instance configuration.

Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

off Disables the IS-IS operation on the specified


interface.
The router immediately removes IS-IS protocol
state and the configuration related to this interface.

R82.10 Gaia Advanced Routing Administration Guide | 455


Configuring IS-IS in Gaia Clish

Parameter Description

passive-mode {on | off | Enables (on) or disables (off) passive IS-IS


default} operation on this interface.
When an IS-IS interface runs in passive mode, it
does not send protocol packets from the specified
interface, but the IP connectivity information related
to the interface is still included in LSP packets the
IS-IS router sends from other active IS-IS
interfaces.
This mode is ideal for stub networks.
Note - The IS-IS router enables this mode
implicitly on loopback interfaces.
Options:
n on - This interface does not send protocol
packets
n off - This interface works as a normal IS-IS
interface
Default:
n off

point-to-point {on | off} Configures a broadcast IS-IS interface to behave as


a point-to-point IS-IS interface.
In certain topologies, it may be advantageous to
make a broadcast interface behave as if it is point-
to-point.
This prevents the overhead present on broadcast
interfaces.
Note - Use this option only if this link has
exactly two IS-IS routers (including this one).
Options:
n on - This interface behaves as point-to-point
n off - This interface behaves as broadcast
Default:
n off

R82.10 Gaia Advanced Routing Administration Guide | 456


Configuring IS-IS in Gaia Clish

Parameter Description

point-to-point Note - This command only applies to point-to-


retransmit-interval {<0- point interfaces.
65535> | default} This command does not apply if the specified
interface is not point-to-point, or is not a
broadcast interface that behaves as point-to-
point.
Configures the retransmit interval for LSP packets
this IS-IS routers sends over a point-to-point link.
IS-IS requires an IS-IS router to send
acknowledgments for LSP packets it receives from
its neighbor over a point-to-point link.
If this router sends an LSP and does not get this
acknowledgment within the configured retransmit
interval, this router sends the LSP again, until it gets
an acknowledgment.
Range: 0 - 65535 (seconds)
Default: 5 seconds

point-to-point Note - This command only applies to point-to-


retransmit-throttle- point interfaces.
interval {<0-65535> | This command does not apply if the specified
default} interface is not point-to-point, or is not a
broadcast interface that behaves as point-to-
point.
Configures how frequently this IS-IS router
retransmits LSP packets over a point-to-point link to
its neighbor when multiple packets are waiting to be
sent.
Range: 0 - 65535 (milliseconds)
Default: The value of the "lsp-interval"
parameter for this interface.

R82.10 Gaia Advanced Routing Administration Guide | 457


Configuring IS-IS in Gaia Clish

Parameter Description

priority {<0-127> | Configures the Designated Intermediate System


default} [level {1 | 2}] (DIS) priority for the specified broadcast interface.
On broadcast IS-IS interfaces, the IS-IS router with
the highest priority is automatically elected to be the
DIS.
Configure the priority value to get the desired DIS
on each IS-IS link.
Range: 0 - 127
Default: 64
Optional:
Specify an additional "level" parameter to apply
this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 458


Configuring IS-IS in Gaia Clish

Configuring IS-IS IPv6 Multi-Topology Options


The IPv6 Multi-Topology configuration allows an IS-IS router to consider IPv4 and IPv6 as
separate routing domains.
As a result, it is safer and easier to configure networks that have mixed support for both IPv4
and IPv6.

Important - IPv6 options in IS-IS apply only after you enable IPv6 Multi-Topology.
If IPv6 Multi-Topology is disabled, IPv6 settings get their values from the non-IPv6
versions of these commands, and the IPv6 commands do not apply.

Syntax

set isis ipv6


default-metric {<1-16777214> | default} [level {1 | 2}]
ignore-attached-bit {on | off | default}
multi-topology {on | off | transition}
overload-bit {on | off}
prc-interval max {<1-120> | default} initial {<50-120000>
| default} second {<50-120000> | default} [level {1 | 2}]
spf interval max {<1-120> | default} initial {<50-120000>
| default} second {<50-120000> | default} [level {1 | 2}]
set isis interface <Name of Interface> ipv6
advertise {on | off | default}
ip-reachability-detection {on | off | default}
metric {<1-16777214> | default | maximum} [level {1 | 2}]

R82.10 Gaia Advanced Routing Administration Guide | 459


Configuring IS-IS in Gaia Clish

Parameters

Parameter Description

ipv6 default-metric {<1- Configures the default metric for all IPv6 IS-IS
16777214> | default} [level interfaces. The interface uses this metric if you
{1 | 2}] do not configure another IPv6 metric explicitly.
Note - The IPv6 metric takes effect only if
you ran this command:
set isis multi-topology on
Range:
n 1 - 16777214 - Uses the wide metric type
n 1 - 63 - Uses the narrow metric type
Default:
n 10
Optional:
Specify an additional "level" parameter to
apply this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

ipv6 ignore-attached-bit Use this option to ignore attached bits set by


{on | off | default} level-2-connected IS-IS IPv6 routers.
By default, 'Level 1-2' IS-IS routers do not send
routes from 'Level 2' to 'Level 1'.
Instead, they configure an "attached bit" in the
packets they send to 'Level 1' areas.
This attached bit shows that 'Level 1' routers
should install a default route to the 'Level 2'
router that configured it.
In some cases, it may be necessary to ignore
these attached bits, and not install a default
route on 'Level 1-2' routers.
Options:
n on - Does not install the default route on
"attached" routers
n off - Installs the default route on
"attached" neighbors
Default:
n off

R82.10 Gaia Advanced Routing Administration Guide | 460


Configuring IS-IS in Gaia Clish

Parameter Description

ipv6 multi-topology {on | Configures Multi-Topology for IPv6 unicast.


off | transition} Multi-Topology maintains separate topologies
for each Multi-Topology, on which it is enabled.
As a result, IS-IS runs SPF and calculates routes
separately for IPv4 and IPv6.
In addition, adjacencies form as long as there is
at least one common address family supported.
If you enable this feature, this IS-IS router
ignores the "adjacency-check" option (as if it
"off").
Options:
n on
Enables Multi-Topology for IPv6.
This IS-IS router sends only Multi-
Topology TLVs in LSP packets.
All IS-IS routers in the area must support
Multi-Topology to install IPv6 routes
correctly.
n transition
Enables Multi-Topology mode for IPv6.
This IS-IS router sends the Single-
Topology and Multi-Topology TLVs in LSP
packets.
The router creates adjacencies with
Single-Topology and Multi-Topology
routers, but continues to work in Single-
Topology mode.
n off
Disables Multi-Topology for IPv6.
This IS-IS router sends only Single-
Topology TLVs in LSP packets, and does
not work with other routers that run in Multi-
Topology mode.
Default:
n off

R82.10 Gaia Advanced Routing Administration Guide | 461


Configuring IS-IS in Gaia Clish

Parameter Description

ipv6 overload-bit {on | Enables (on) or disables (off) the settings


off} related to the overload bit for IPv6.
IS-IS routers may optionally configure an
overload bit in the 'Hello' packets and LSP
packets they send to other IS-IS routers. This bit
shows that the router should not be used as a
transit router for routing decisions.
You can configure this bit permanently on
routers that are never intended to pass traffic,
except to directly connected subnets.
Options:
n on - Enables the overload bit for IPv6
n off - Disables the overload bit for IPv6
Default:
n off

R82.10 Gaia Advanced Routing Administration Guide | 462


Configuring IS-IS in Gaia Clish

Parameter Description

ipv6 prc-interval max {<1- Configures the delay between subsequent


120> | default} initial Partial Route Calculation (PRC) events for IPv6.
{<50-120000> | default} This option uses an exponential backoff to
second {<50-120000> | determine the delay between events.
default} [level {1 | 2}] The delay before events after the "second"
period is the previous delay multiplied by two, up
to the maximum delay.
If an event does not occur for two "max" periods,
the router restores the delay to the "initial"
value.
Options:
n max:
l Range: 1 - 120 (seconds)
l Default: 5
n initial:
l Range: 50 - 120000 (milliseconds)

l Default: 2000

n second:
l Range: 50 - 120000 (milliseconds)

l Default: 5000

Optional:
Specify an additional "level" parameter to
apply this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 463


Configuring IS-IS in Gaia Clish

Parameter Description

ipv6 spf interval max {<1- Use this command to configure the delay
120> | default} initial between subsequent SPF calculations.
{<50-120000> | default} When the information announced by an IS-IS
second {<50-120000> | router changes the topology, all routers in the
default} [level {1 | 2}] domain must run SPF to re-create the shortest
path tree.
The SPF interval determines how frequently
these shortest path calculations may occur.
This option uses exponential backoff to
determine the delay between events.
Note - You must enable IPv6 Multi-
Topology with this command:
set isis multi-topology on
The delay before events after the "second"
period is the previous delay multiplied by two, up
to the maximum delay.
If an event does not occur for two "max" periods,
the router restores the delay to the "initial"
value.
Options:
n The "max" option:
Specifies the maximum interval between
two events.
l Range: 1 - 120 (seconds)

l Default: 10

n The "initial" option:


Specifies the initial delay between when an
event is scheduled, and when it actually
takes place.
l Range: 50 - 120000 (milliseconds)

l Default: 5500

n The "second" option:


Specifies the delay between the first event
and the second event.
l Range: 50 - 120000 (milliseconds)

l Default: 5500

Optional:
Specify an additional "level" parameter to
apply this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 464


Configuring IS-IS in Gaia Clish

Parameter Description

interface <Name of Enables (on) or disables (off) the advertising of


Interface> ipv6 advertise this interface's IPv6 prefix to this router's IS-IS
{on | off | default} neighbors.
By default, IS-IS includes all directly connected
routes on the IS-IS interfaces in its Link State
PDUs.
However, in some cases, these routes are not
necessary (for example, transit links which are
never used as a final destination).
In this case, it may be advantageous to not send
these prefixes in LSP packets, so the total IS-IS
link state database is smaller.
Options:
n on - Sends this interface's IPv6 prefix in IS-
IS LSP packets
n off - Does not send this interface's IPv6
prefix in IS-IS LSP packets
Default:
n on

R82.10 Gaia Advanced Routing Administration Guide | 465


Configuring IS-IS in Gaia Clish

Parameter Description

interface <Name of Enables (on) or disables (off) Bidirectional


Interface> ipv6 ip- Forwarding Detection (BFD) on the specified
reachability-detection {on interface.
| off | default} If you enable this feature, this IS-IS router
creates a BFD session on the specified interface
with all IS-IS neighbors that also have BFD
enabled.
While a BFD session is active between two
neighbors, the IS-IS state responds to changes
in the BFD state:
n If the BFD state change to 'Down', then the
state of that IS-IS link also changes to
'Down'.
n If one IS-IS neighbor has BFD enabled and
the other neighbor does not, then these
neighbors do not create a BFD session,
and BFD does not have an effect on the
adjacency state.
Notes for IPv6 Multi-Topology:
n If you did not enable IPv6 Multi-Topology,
then this option tries to enable BFD for the
IPv6 address you configured on the
specified interface.
n If you enabled IPv6 Multi-Topology, then
this option tries to enable BFD only for IS-
IS neighbors that use IPv6.

Options:
n on - Enables BFD for this interface
n off - Disables BFD for this interface
Default:
n off

R82.10 Gaia Advanced Routing Administration Guide | 466


Configuring IS-IS in Gaia Clish

Parameter Description

interface <Name of Configures the metric (cost) related to the


Interface> ipv6 metric {<1- specified interface.
16777214> | default | The metric of each link in an IS-IS topology
maximum} [level {1 | 2}] determines the total cost of a given route to a
destination.
Configure a metric on each IS-IS interface on an
IS-IS router based on how much traffic you
expect this interface to pass compared to other
IS-IS interfaces.
Options:
n "maximum" - The SPF algorithm uses an
infinite cost for this interface
n 1 - 16777214 - Uses the wide metric type
n 1 - 63 - Uses the narrow metric type
Default:
n The value configured as the default-metric
in the IS-IS instance configuration.
Optional:
Specify an additional "level" parameter to
apply this command to 'Level 1' or 'Level 2' only.
Without this parameter, this command applies to
'Level 1' and 'Level 2' configuration.

R82.10 Gaia Advanced Routing Administration Guide | 467


Monitoring IS-IS

Monitoring IS-IS
Monitoring IS-IS in Gaia Portal
1. From the left navigation tree, click Advanced Routing > IS-IS.
2. In the top right corner, click Monitoring.
3. In the IS-IS Monitor section, click the Information category.

Monitoring IS-IS in Gaia Clish

Syntax

show isis
database [detailed] [level {1 | 2}] [lsp-type {node |
pseudonode}] [system-id <IS-IS System ID>]
errors [<Error Types>]
export-routemap [level {1 | 2}]
hostnames
interface <Name of Interface> [detailed]
interfaces [detailed]
ipv6 topology
neighbor <Neighbor System ID> [detailed]
neighbors [detailed]
packets
summary
topology

R82.10 Gaia Advanced Routing Administration Guide | 468


Monitoring IS-IS

Parameters

Parameter Description

show isis database [detailed] Shows the contents of the IS-IS


[level {1 | 2}] [lsp-type {node | database.
pseudonode}] [system-id <IS-IS You can use these options in any
System ID>] combination or order to control the
output:
n detailed
Shows the detailed output of each
LSP in the IS-IS database.
Output includes each known TLV
included in each LSP.
n level {1 | 2}
Shows the IS-IS database
information only for the specified
level.
n lsp-type {node |
pseudonode}
Shows LSP packets only of the
specified type.
Each IS-IS router in the network
sends Node LSP packets.
Only the Designated Intermediate
System (DIS) on each link sends
Pseudonode LSP packets and
represents the link as a whole.
n system-id <IS-IS System
ID>
Shows only LSP packets that the
IS-IS router with the specified
System ID created.
Press the Tab key to see the
available System IDs.

R82.10 Gaia Advanced Routing Administration Guide | 469


Monitoring IS-IS

Parameter Description

show isis errors [<Error Types>] Shows a list of each IS-IS error recorded.
By default, this command shows each
error type.
You can specify one of more of these
error types:
n csnp - Shows only IS-IS CSNP
errors
n global - Shows only IS-IS global
errors
n hello - Shows only IS-IS 'Hello'
errors
n lsp - Shows only IS-IS LSP errors
n protocol - Shows only IS-IS
protocol errors
n psnp - Shows only IS-IS PSNP
errors

export-routemap [level {1 | 2}] Shows all routemaps for IS-IS export


policy.
See "Route Maps - Export and Import" on
page 637.
n level {1 | 2}
Shows the IS-IS database
information only for the specified
level.

show isis hostnames Shows the database with the mapping


between System IDs and Hostnames.

show isis interfaces [detailed] Shows the state of the IS-IS interfaces on
show isis interface <Name of the router.
Interface> [detailed] By default, the output shows a table with
commonly-referenced information.
If you specify the "detailed" option, the
output shows all information for the IS-IS
interfaces.

R82.10 Gaia Advanced Routing Administration Guide | 470


Monitoring IS-IS

Parameter Description

show isis neighbors [detailed] Shows the state of the IS-IS neighbors
show isis neighbor <Neighbor known to the router.
System ID> [detailed] By default, the output shows a table with
commonly-referenced information.
If you specify the "detailed" option, the
output shows all information for the
neighbors.

show isis packets Shows a summary of IS-IS packets this


IS-IS routers sent, received, and
dropped. The output is sorted by the
packet type.

show isis summary Shows a brief summary of the current


running state of the IS-IS router.

show isis topology Shows the Shortest Path First tree that
show isis ipv6 topology IS-IS calculated for each router in the IS-
IS network.
When the IPv6 Multi-Topology is
enabled, use the IPv6 version of this
command to see the IPv6 SPF tree.

R82.10 Gaia Advanced Routing Administration Guide | 471


Route Aggregation

Route Aggregation
Route aggregation is used to combine a set of more specific routes into a single more general
route.
This reduces the number of routes advertised by a given protocol.
Example:
n A router has many stub interface routes subnetted from a Class C network.
n A router runs RIPv2 on another interface.
n In this case, these interface routes can be combined into a single aggregate route (for
example, the Class C network).
This single aggregate route can be redistributed into RIPv2, instead of the large list of
individual routes.

Important - Be careful when aggregating if there are gaps in the route that is aggregated.

The interface that originates the aggregate routes does not use them to forward packets. Only
the router that receives the routes uses them.
A router that receives a packet that does not match one of the component routes, should
respond with an ICMP "Network Unreachable" message.
This prevents packets for unknown component routes from following a default route into
another network.
In this situation, they might be continually forwarded back to the border router until their TTL
expires.

To create an aggregate route, first specify the network address and subnet mask, followed by
the set of contributing routes.
Define the contributing routes by specifying a source, such as a routing protocol or a static
route, followed by a route filter, which is either a prefix or the keyword "all IPv4 routes".
An aggregate route can have many contributing routes. However, at least one of the routes
must be already present to generate the aggregate.

R82.10 Gaia Advanced Routing Administration Guide | 472


Configuring Route Aggregation in Gaia Portal

Configuring Route Aggregation in Gaia Portal


Important - In a Cluster, you must configure all the Cluster Members in the same way.

Adding an IPv4 Aggregate Route

1. From the left navigation tree, click Advanced Routing > Route Aggregation.
2. In the Route Aggregation section, click Add and select IPv4.
3. In the IPv4 address field, enter the IPv4 address of the new contributing route.
Description

This activates the aggregate route, if contributed by the protocol.


The IPv4 address and subnet mask correspond to a single routing table entry.
Range: Dotted-quad ([0-255].[0-255].[0-255].[0-255])
Default: No default

4. In the Subnet mask field, , enter the IPv4 subnet mask of the new contributing route.
Description

This activates the aggregate route, if contributed by the protocol.


The IPv4 address and subnet mask correspond to a single routing table entry.

Range: Dotted-quad ([0-255].[0-255].[0-255].[0-255])


Default: No default

5. In the Rank field, enter the rank of the new contributing route.
Description

The routing system uses rank when there are routes from different protocols to the
same destination.
For each route, the route from the protocol with the lowest rank is used.
See "Protocol Rank" on page 657.
Range: 0-255
Default: 130

6. In the Weight field, enter the weight of the new contributing route.

R82.10 Gaia Advanced Routing Administration Guide | 473


Configuring Route Aggregation in Gaia Portal

Description

This weight is a second tie breaker after the rank.


It selects routes going to the same destination.
The route with the highest weight is an active route and is installed in the kernel
forwarding table and redistributed to other routing protocols.
Range: 0-65535
Default: 0

7. The option AS Path Truncate controls the Autonomous System (AS) path truncation
mode.
Description

When this option is enabled, the AS path is truncated to the longest common AS
path.
When this option is disabled, the AS path consists of sets and sequences of all
contributing AS paths.
Range: Selected, or Cleared
Default: Cleared

8. In the Contributing Routes section, click Add.


9. In the Protocol field, select the contributing protocols, whose routes should be
included in the aggregate route.
Description

Protocol Included Routes

All From all protocols.

Direct Only routes associated with local interfaces.

Static Only static routes.

Aggregate Only other (more specific) aggregate routes.

OSPF2 Only IPv4 OSPFv2 routes.

OSPF2ASE Only IPv4 OSPFv2 External routes.

RIP Only IPv4 RIP routes.

R82.10 Gaia Advanced Routing Administration Guide | 474


Configuring Route Aggregation in Gaia Portal

Protocol Included Routes

BGP Only IPv4 BGP routes.

10. The option Contribute All IPv4 Routes controls the whether to let any routes
contributed by the protocol to activate the aggregate route.
Description

Range: Selected, or Cleared


Default: Cleared

11. In the IPv4 address field, enter the IPv4 address of the route, which the specified
protocol contributes to the aggregate route.
Description

An aggregate route does not activate, until one or more contributing routes exist.
Range: Dotted-quad ([0-255].[0-255].[0-255].[0-255])
Default: No default

12. In the Subnet mask field, , enter the IPv4 subnet mask of the route, which the
specified protocol contributes to the aggregate route.
Description

An aggregate route does not activate, until one or more contributing routes exist.
Range: Dotted-quad ([0-255].[0-255].[0-255].[0-255])
Default: No default

13. The option Match Type controls how to match routes.


Description

The routes are filtered for the Address and Subnet mask.
These are the ways to compare other routes:

Protocol Description

None Matches any route that equals the specified route, or is more
specific than the specified route.

Refines Matches a route, only if it is more specific than the specified route.

R82.10 Gaia Advanced Routing Administration Guide | 475


Configuring Route Aggregation in Gaia Portal

Protocol Description

Exact Matches a route, only if it equals the From Address and Subnet
mask of the specified route.

Default: None

14. Click OK.


15. Click Save.

Adding an IPv6 Aggregate Route

1. From the left navigation tree, click Advanced Routing > Route Aggregation.

2. In the Route Aggregation section, click Add and select IPv6.


3. In the IPv6 address / Mask length field, enter the IPv6 address and mask length of
the new contributing route.
Description

This activates the aggregate route, if contributed by the protocol.


The IPv6 address and mask length correspond to a single routing table entry.
Default: No default

4. In the Rank field, enter the rank of the new contributing route.
Description

The routing system uses rank when there are routes from different protocols to the
same destination.

For each route, the route from the protocol with the lowest rank is used.
See "Protocol Rank" on page 657.
Range: 0-255
Default: 130

5. In the Weight field, enter the weight of the new contributing route.
Description

This weight is a second tie breaker after the rank.


It selects routes going to the same destination.

R82.10 Gaia Advanced Routing Administration Guide | 476


Configuring Route Aggregation in Gaia Portal

The route with the highest weight is an active route and is installed in the kernel
forwarding table and redistributed to other routing protocols.
Range: 0-65535
Default: 0

6. The option AS Path Truncate controls the Autonomous System (AS) path truncation
mode.
Description

When this option is enabled, the AS path is truncated to the longest common AS
path.
When this option is disabled, the AS path consists of sets and sequences of all
contributing AS paths.
Range: Selected, or Cleared
Default: Cleared

7. In the Contributing Routes section, click Add.


8. In the Protocol field, select the contributing protocols, whose routes should be
included in the aggregate route.
Description

Protocol Included Routes

All From all protocols.

Direct Only routes associated with local interfaces.

Static Only static routes.

Aggregate Only other (more specific) aggregate routes.

OSPF3 Only IPv6 OSPFv3 routes.

OSPF3ASE Only IPv6 OSPFv3 External routes.

RIPng Only IPv6 RIPng routes.

BGP Only IPv6 BGP routes.

9. The option Contribute All IPv6 Routes controls the whether to let any routes
contributed by the protocol to activate the aggregate route.

R82.10 Gaia Advanced Routing Administration Guide | 477


Configuring Route Aggregation in Gaia Portal

Description

Range: Selected, or Cleared


Default: Cleared

10. In the IPv6 address / Mask length field, enter the IPv6 address and the mask length
of the route, which the specified protocol contributes to the aggregate route.
Description

An aggregate route does not activate, until one or more contributing routes exist.
Default: No default

11. The option Match Type controls how to match routes.


Description

The routes are filtered for the Address and Subnet mask.
These are the ways to compare other routes:

Protocol Description

None Matches any route that equals the specified route, or is more
specific than the specified route.

Refines Matches a route, only if it is more specific than the specified route.

Exact Matches a route, only if it equals the From Address and Subnet
mask of the specified route.

Default: None

12. Click OK.


13. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 478


Configuring Route Aggregation in Gaia Clish

Configuring Route Aggregation in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

n To see the available "set" commands for Route Aggregation, enter in Gaia Clish:

set aggregate[Esc][Esc]

n There are no "show" commands for Route Aggregation in Gaia Clish.


Syntax for IPv4

set aggregate <IPv4 Address>/<IPv4 Mask Length>


aspath-truncate {off | on}
contributing-protocol <Protocol>
contributing-route <IPv4 Address>/<IPv4 Mask Length>
exact on
{off | on}
refines on
off
off
rank {<0-255> | default}
weight {<0-255> | default}

Syntax for IPv6

set ipv6 aggregate <IPv6 Address>/<IPv6 Mask Length>


aspath-truncate {off | on}
contributing-protocol <Protocol>
contributing-route <IPv6 Address>/<IPv6 Mask Length>
exact on
{off | on}
refines on
off
off
rank {<0-255> | default}
weight {<0-255> | default}

R82.10 Gaia Advanced Routing Administration Guide | 479


Configuring Route Aggregation in Gaia Clish

Parameters

Parameter Description

set aggregate <IPv4 Configures the route that activates the aggregate route, if
Address>/<IPv4 Mask contributed by the protocol.
Length> The IPv4 address and Mask Length correspond to a single
routing table entry.
n <IPv4 Address>
Range: Dotted-quad ([0-255].[0-255].[0-255].[0-255])
Default: No default
n <IPv4 Mask Length>
Range: 1-32
Default: No default

set ipv6 aggregate Configures the route that activates the aggregate route, if
<IPv6 contributed by the protocol.
Address>/<IPv6 Mask The IPv6 address and Mask Length correspond to a single
Length> routing table entry.
n <IPv6 Address>
Range: ([0000-FFFF]:[0000-FFFFF]:[0000-FFFFF]:
[0000-FFFFF]:[0000-FFFFF]:[0000-FFFFF]:[0000-
FFFFF]:[0000-FFFFF])
Default: No default
n <IPv6 Mask Length>
Range: 1-128
Default: No default

aspath-truncate Configures the Autonomous System (AS) path truncation


{off | on} mode.
When this option is enabled, the AS path is truncated to the
longest common AS path.
When this option is disabled, the AS path consists of sets
and sequences of all contributing AS paths.
Range: off, or on
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 480


Configuring Route Aggregation in Gaia Clish

Parameter Description

contributing- Configures the contributing protocols, whose routes should


protocol <Protocol> be included in the aggregate route.
n all - From all protocols.
n aggregate - Only other (more specific) aggregate
routes.
n bgp - Only IPv4 BGP or IPv6 BGP routes.
n direct - Only routes associated with local
interfaces.
n ospf2 - Only IPv4 OSPFv2 routes.
n ospf2ase - Only IPv4 OSPFv2 External routes.
n ospf3 - Only IPv6 OSPFv3 routes.
n ospf3ase - Only IPv6 OSPFv3 External routes.
n rip - Only IPv4 RIP routes.
n ripng - Only IPv6 RIPng routes.
n static - Only static routes.

contributing-route Configures a route, which the specified protocol


<IPv4 contributes to the aggregate route.
Address>/<IPv4 Mask An aggregate route does not activate, until one or more
Length> contributing routes exist.
The value all-ipv4-routes lets any routes contributed
by the protocol to activate the aggregate route.
Range: Dotted-quad ([0-255].[0-255].[0-255].[0-255]) / [1-
32], or "all-ipv4-routes"
Default: none

contributing-route Configures a route, which the specified protocol


<IPv6 contributes to the aggregate route.
Address>/<IPv6 Mask An aggregate route does not activate, until one or more
Length> contributing routes exist.
The value all-ipv6-routes lets any routes contributed
by the protocol to activate the aggregate route.
Range: ([0000-FFFF]:[0000-FFFFF]:[0000-FFFFF]:[0000-
FFFFF]:[0000-FFFFF]:[0000-FFFFF]:[0000-FFFFF]:[0000-
FFFFF]) / [1-128], or "all-ipv6-routes"
Default: none

R82.10 Gaia Advanced Routing Administration Guide | 481


Configuring Route Aggregation in Gaia Clish

Parameter Description

contributing-route Matches a route, only if it equals the From Address and


<IP Address>/<Mask Subnet mask of the specified route.
Length> exact on The routes that are filtered for the Address and Subnet
mask.
If neither "exact on", nor "refines on" is configured,
then matches any route that equals the specified route, or
is more specific than the specified route.

contributing-route Removes (off) or adds (on) the contributing route from or


<IP Address>/<Mask to the aggregate route.
Length> {off | on} Range: off, or on
Default: none

contributing-route Matches a route, only if it is more specific than the


<IP Address>/<Mask specified route.
Length> refines on The routes are filtered for the Address and Subnet mask.
If neither "exact on", nor "refines on" is configured,
then matches any route that equals the specified route, or
is more specific than the specified route.

contributing- Removes the contributing protocol.


protocol <Protocol>
off

set aggregate <IPv4 Removes this IPv4 aggregate route.


Address>/<IPv4 Mask
Length> off

set ipv6 aggregate Removes this IPv6 aggregate route.


<IPv6
Address>/<IPv6 Mask
Length> off

rank {<0-255> | Configures the rank of the new contributing route.


default} The routing system uses rank when there are routes from
different protocols to the same destination.
For each route, the route from the protocol with the lowest
rank is used.
See "Protocol Rank" on page 657.
Range: 0-255
Default: 130

R82.10 Gaia Advanced Routing Administration Guide | 482


Configuring Route Aggregation in Gaia Clish

Parameter Description

weight {<0-255> | Configures the weight of the new contributing route.


default} This weight is a second tie breaker after the rank.
It selects routes going to the same destination.
The route with the highest weight is an active route and is
installed in the kernel forwarding table and redistributed to
other routing protocols.
Range: 0-65535
Default: 0

R82.10 Gaia Advanced Routing Administration Guide | 483


Routing Policy Configuration

Routing Policy Configuration


You can configure routing policy for RIP, OSPFv2 and BGP in these ways:

Routing Policy
Configured In Description
Configuration

Inbound Route Gaia Portal, Define filters for routes accepted by a given routing
Filters or protocol.
Gaia Clish Inbound Route filters are similar to route maps for an
import policy.

Route Gaia Portal, Redistribute routes learned from one routing protocol
Redistribution or into another routing protocol.
Gaia Clish It is also useful for advertising static routes, such as the
default route, or aggregate routes.
Route Redistribution is similar to route maps for an
export policy.

Routemaps Gaia Clish Control which routes are accepted and announced.
Used to configure inbound route filters, outbound route
filters, and to redistribute routes from one protocol to
another.
Route maps offer more configuration options than the
Portal options.
However, they are not functionally equivalent.
Routemaps assigned to a protocol for import or export
override corresponding filters and route redistribution
rules.

Inbound Route Filters let you define which external to a routing protocol routes are accepted
by that protocol.
By default, all routes, external to RIP, OSPFv2 (IPv4), and OSPFv3 (IPv6), are accepted by
these protocols.
To narrow down the selection of accepted routes, you can edit the default policies and
configure new policies.
When you configure Inbound Route Filters, to specify precision with which the network
addresses are matched, use the same Match Type criteria rules as for route redistribution:
n The prefix and the mask length are matched exactly.
n The prefix is matched exactly, and the mask length is greater than the one specified.

R82.10 Gaia Advanced Routing Administration Guide | 484


Routing Policy Configuration

For example, if the network address [Link]/8 is specified in the filter, then any route
with the prefix 10 and the mask length greater than 8 is matched, but those with the mask
length of exactly 8 are not matched.
n The prefix is matched exactly, and the mask length is equal to or greater than the one
specified.
For example, if the network address [Link]/8 is specified in the filter, then any route
with the prefix 10 and the mask length equal to or greater than 8 is matched.
n The prefix is matched exactly, and the mask length is within the specified range of
masks. The mask range values must be equal to or greater than the network mask.
For example, if the network address [Link]/8 and the mask range 16 to 8 are specified
in the filter, then any route with the prefix 10 and the mask length between 8 and 16 is
matched.

Notes:
n The Routemap import configuration overrides the Inbound Route Filters
configuration.
n By default, BGP does not accept any routes. You must configure explicit
policies for BGP to accept routes.
n BGP policy can also import IPv6, if IPv6 is enabled on the Security Gateway.
You can specify IPv6 prefixes in addition to IPv4 prefixes.

R82.10 Gaia Advanced Routing Administration Guide | 485


Configuring Inbound Route Filters in Gaia Portal

Configuring Inbound Route Filters in Gaia Portal


In This Section:

Procedure 486
Configuring the "Add BGP Policy Filter (Based on AS-PATH)" 487
Configuring the "Add BGP Policy Filter (Based on AS)" 495
Configuring the "Add Individual IPv4 Route Filter" 501
Configuring the "Add Individual IPv6 Route Filter" 505

Important - In a Cluster, you must configure all the Cluster Members in the same way.

Procedure
1. From the left navigation tree, click Advanced Routing > Inbound Route Filters.
2. In the Inbound Route Filters section, click Add and select the type of the Route Filter:
n Add BGP Policy Filter (Based on AS-PATH) - To filter BGP routes based on the
AS-PATH attribute.
n Add BGP Policy Filter (Based on AS) - To filter BGP routes based on the AS
attribute.
n Add Individual IPv4 Route Filter - To filter IPv4 routes.
n Add Individual IPv6 Route Filter - To filter IPv6 routes.

Note - For BGP, no routes are accepted from a peer by default. You must
configure an explicit Inbound BGP Route Filter to accept a BGP route from a
peer.

3. Configure the applicable settings.


See the sections below.
4. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 486


Configuring Inbound Route Filters in Gaia Portal

Configuring the "Add BGP Policy Filter (Based on AS-


PATH)"
Configures a new policy to import BGP routes, whose AS-PATH matches a particular regular
expression.
1. From the left navigation tree, click Advanced Routing > Inbound Route Filters.
2. Click the Add button.
3. From the drop down menu, select Add BGP Policy Filter (Based on AS Path).
4. In the Policy Filter section, in the Add BGP Policy fields:
a. In left field, enter the unique identifier from 1 to 511.
Description

An autonomous system can control BGP import.


BGP supports propagation control through the use of AS-PATH regular
expressions.
BGPv4 supports the propagation of any destination along a contiguous network
mask.
Range: 1-511
Default: None

b. In the middle field, enter the AS_PATH Regular Expression.


Description

A valid AS_PATH regular expression contains only digits and these special
characters:

Operator Description

. The period character matches any single character.

\ The backslash character matches the character right after the


backslash.
For pattern recall, match the pattern indicated by the digit
following the backslash.

^ The circumflex character matches the characters or null string


at the beginning of the AS path.

R82.10 Gaia Advanced Routing Administration Guide | 487


Configuring Inbound Route Filters in Gaia Portal

Operator Description

$ The dollar character matches the characters or null string at the


end of the AS path.

? The question mark matches zero or one occurrence of the


pattern before "?".

* The asterisk character matches zero or more occurrences of


the pattern before "*".

+ The plus character matches one or more occurrences of the


pattern before "+".

| The pipeline (vertical line) character matches one of the


patterns on either side of the "|" character.

_ The underscore character matches comma (,), left brace ({),


right brace (}), beginning of ASPath (^), end of ASPath ($), or
a whitespace (space or tabulation).

[] The square brackets match the set of characters or range of


characters separated by a hyphen (-) within the brackets.

() The round brackets group one or more patterns into a single


pattern.

{m n} Matches at least "m" and at most "n" repetitions of the pattern


before {m,n}.
Both "m" and "n" are positive integers, and "m" is less than or
equal to "n".

{m} Matches exactly "m" repetitions of the pattern before {m}.


The "m" is a positive integer.

{m,} Matches "m" or more repetitions of the pattern before {m}.


The "m" is a positive integer.

R82.10 Gaia Advanced Routing Administration Guide | 488


Configuring Inbound Route Filters in Gaia Portal

c. In the right field, select the route origin.


Description

n Any - A route was learned from any protocol and the path is probably
complete.
n IGP - A route was learned from an interior routing protocol and the path is
probably complete.
n EGP - A route was learned from an exterior routing protocol that does not
support AS-PATH, and the path is probably incomplete.
n Incomplete - The route path information is incomplete.

5. In the Extended Communities to Match section:

R82.10 Gaia Advanced Routing Administration Guide | 489


Configuring Inbound Route Filters in Gaia Portal

a. Click Add.

Note - You can configure a maximum of 25 Extended Communities.

R82.10 Gaia Advanced Routing Administration Guide | 490


Configuring Inbound Route Filters in Gaia Portal

b. Configure the applicable settings.


Description

Type Required Settings

Transitive Two Octet AS i. In the AS field, enter a value 1 - 65535.


ii. In the Value, enter a value 0 -
4294967295.
iii. In the Subtype, select the applicable
option:
n Route Target
n Route Origin
n OSPF Domain Identifier
n BGP Data Collection
n L2VPN Identifier
n Cisco VPN Distinguisher
n Source AS

Non-Transitive Two Octet i. In the AS field, enter a value 1 - 65535.


AS ii. In the Value, enter a value 0 -
4294967295.
iii. In the Subtype, select Link Bandwidth.

Transitive Four Octet AS i. In the AS field, enter a value 65536 -


4294967295.
ii. In the Value, enter a value 0 - 65535.
iii. In the Subtype, select the applicable
option:
n Route Target
n Route Origin
n OSPF Domain Identifier
n BGP Data Collection
n Generic
n Cisco VPN Distinguisher
n Source AS

Non-Transitive Four Octet i. In the AS field, enter a value 65536 -


AS 4294967295.
ii. In the Value, enter a value 0 - 65535.
iii. In the Subtype, select Generic.

R82.10 Gaia Advanced Routing Administration Guide | 491


Configuring Inbound Route Filters in Gaia Portal

Type Required Settings

Transitive IPv4 Address i. In the IPv4 field, enter an IPv4 address.


ii. In the Value, enter a value 0 - 65535.
iii. In the Subtype, select the applicable
option:
n Route Target
n Route Origin
n OSPF Domain Identifier
n OSPF Route ID
n L2VPN Identifier
n Cisco VPN Distinguisher
n VRF Route Import

c. Click OK.
6. In the Large Communities to Match section:
a. Click Add.
b. Configure the applicable settings:

Note - You can configure a maximum of 25 Large Communities.

n Global Admin
n Local Data 1
n Local Data 2
c. Click OK.

7. In the Policy Filter section, in the Action field, select which routes to accept or reject.
Description

Action Description

Accept IPv4 Accepts all IPv4 and IPv6 routes that match this filter, except those
& IPv6 route that are explicitly restricted by a more specific rule.
Accepting routes is the default behavior, unless the "restrict" option
is configured.

Restrict IPv4 Rejects all IPv4 and IPv6 routes that match this filter, except those
& IPv6 that match a more specific filter that is set to "accept".

R82.10 Gaia Advanced Routing Administration Guide | 492


Configuring Inbound Route Filters in Gaia Portal

Action Description

Accept IPv4, Rejects all IPv6 routes that match this filter, except those that
Restrict IPv6 match a more specific filter that is set to "accept".
Accepts all IPv4 routes.

Restrict Rejects all IPv4 routes that match this filter, except those that
IPv4, Accept match a more specific filter that is set to "accept".
IPv6 Accepts all IPv6 routes.

8. In the Policy Default Modifiers section, in the Local Preference field, enter the default
local preference for the route.
Description

Assigns a BGP local preference to all routes that match this filter, except those that
match a more specific filter with a different local preference value configured.
The local preference value is sent automatically when redistributing external BGP
routes to an internal BGP route.
The local preference parameter is ignored if used on internal BGP import statements.
greater values are preferred by the routing system when it selects between competing
BGP routes.

Best Practice - The local preference configuration is the recommended way


to bias the preference for BGP routes.

Important - Do not use the local preference parameter when importing BGP.

Note - The local preference cannot be configured in a policy rule that is set to
"restrict".

Range: 0-4294967295
Default: None

9. In the Policy Default Modifiers section, in the Weight field, enter the default route
weight.
Description

Assigns a BGP weight to all routes that match this filter, except those that match a
more specific filter with a different weight value configured.
BGP stores any routes that are rejected by not mentioning them in a route filter.

R82.10 Gaia Advanced Routing Administration Guide | 493


Configuring Inbound Route Filters in Gaia Portal

BGP explicitly mentions these rejected routes in the routing table and assigns them a
"restrict" keyword with a negative weight.
A negative weight prevents a route from becoming active, which means that it is not
installed in the forwarding table or exported to other protocols.
This feature eliminates the need to break and re-establish a session upon
reconfiguration if import policy is changed.

Note - The route weight cannot be configured in a policy rule that is set to
"restrict".

Range: 0-65535
Default: None

10. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 494


Configuring Inbound Route Filters in Gaia Portal

Configuring the "Add BGP Policy Filter (Based on AS)"


Configures a new policy to import BGP routes from a particular peer Autonomous System.
1. From the left navigation tree, click Advanced Routing > Inbound Route Filters.
2. Click the Add button.
3. From the drop down menu, select Add BGP Policy Filter (Based on AS).
4. In the Policy Filter section, in the Add BGP Policy fields:
a. In the left field, enter the unique identifier from 512 to 1024.
Description

An autonomous system can control BGP import.


BGP can accept routes from different BGP peers based on the peer AS number.
Range: 512-1024
Default: None

b. In the right-most field, select the peer BGP AS number.


Description

Enter a valid ASPLAIN number or ASDOT number that specifies the BGP
Autonomous System (AS), to which this BGP import policy is applied.
Range: 1 - 4294967295 (ASPLAIN), or 0.1 - 65535.6553 (ASDOT)

Default: None

5. In the Extended Communities to Match section:

R82.10 Gaia Advanced Routing Administration Guide | 495


Configuring Inbound Route Filters in Gaia Portal

a. Click Add.

Note - You can configure a maximum of 25 Extended Communities.

R82.10 Gaia Advanced Routing Administration Guide | 496


Configuring Inbound Route Filters in Gaia Portal

b. Configure the applicable settings.


Description

Type Required Settings

Transitive Two Octet AS i. In the AS field, enter a value 1 - 65535.


ii. In the Value, enter a value 0 -
4294967295.
iii. In the Subtype, select the applicable
option:
n Route Target
n Route Origin
n OSPF Domain Identifier
n BGP Data Collection
n L2VPN Identifier
n Cisco VPN Distinguisher
n Source AS

Non-Transitive Two Octet i. In the AS field, enter a value 1 - 65535.


AS ii. In the Value, enter a value 0 -
4294967295.
iii. In the Subtype, select Link Bandwidth.

Transitive Four Octet AS i. In the AS field, enter a value 65536 -


4294967295.
ii. In the Value, enter a value 0 - 65535.
iii. In the Subtype, select the applicable
option:
n Route Target
n Route Origin
n OSPF Domain Identifier
n BGP Data Collection
n Generic
n Cisco VPN Distinguisher
n Source AS

Non-Transitive Four Octet i. In the AS field, enter a value 65536 -


AS 4294967295.
ii. In the Value, enter a value 0 - 65535.
iii. In the Subtype, select Generic.

R82.10 Gaia Advanced Routing Administration Guide | 497


Configuring Inbound Route Filters in Gaia Portal

Type Required Settings

Transitive IPv4 Address i. In the IPv4 field, enter an IPv4 address.


ii. In the Value, enter a value 0 - 65535.
iii. In the Subtype, select the applicable
option:
n Route Target
n Route Origin
n OSPF Domain Identifier
n OSPF Route ID
n L2VPN Identifier
n Cisco VPN Distinguisher
n VRF Route Import

c. Click OK.
6. In the Large Communities to Match section:
a. Click Add.
b. Configure the applicable settings:

Note - You can configure a maximum of 25 Large Communities.

n Global Admin
n Local Data 1
n Local Data 2
c. Click OK.

7. In the Policy Filter section, in the Action field, select which routes to accept or reject.
Description

Action Description

Accept IPv4 Accepts all IPv4 and IPv6 routes that match this filter, except those
& IPv6 route that are explicitly restricted by a more specific rule.
Accepting routes is the default behavior, unless the "restrict" option
is configured.

Restrict IPv4 Rejects all IPv4 and IPv6 routes that match this filter, except those
& IPv6 that match a more specific filter that is set to "accept".

R82.10 Gaia Advanced Routing Administration Guide | 498


Configuring Inbound Route Filters in Gaia Portal

Action Description

Accept IPv4, Rejects all IPv6 routes that match this filter, except those that
Restrict IPv6 match a more specific filter that is set to "accept".
Accepts all IPv4 routes.

Restrict Rejects all IPv4 routes that match this filter, except those that
IPv4, Accept match a more specific filter that is set to "accept".
IPv6 Accepts all IPv6 routes.

8. In the Policy Default Modifiers section, in the Local Preference field, enter the default
local preference for the route.
Description

Assigns a BGP local preference to all routes that match this filter, except those that
match a more specific filter with a different local preference value configured.
The local preference value is sent automatically when redistributing external BGP
routes to an internal BGP route.
The local preference parameter is ignored if used on internal BGP import statements.
greater values are preferred by the routing system when it selects between competing
BGP routes.

Best Practice - The local preference configuration is the recommended way


to bias the preference for BGP routes.

Important - Do not use the local preference parameter when importing BGP.

Note - The local preference cannot be configured in a policy rule that is set to
"restrict".

Range: 0-4294967295
Default: None

9. In the Policy Default Modifiers section, in the Weight field, enter the default route
weight.
Description

Assigns a BGP weight to all routes that match this filter, except those that match a
more specific filter with a different weight value configured.
BGP stores any routes that are rejected by not mentioning them in a route filter.

R82.10 Gaia Advanced Routing Administration Guide | 499


Configuring Inbound Route Filters in Gaia Portal

BGP explicitly mentions these rejected routes in the routing table and assigns them a
"restrict" keyword with a negative weight.
A negative weight prevents a route from becoming active, which means that it is not
installed in the forwarding table or exported to other protocols.
This feature eliminates the need to break and re-establish a session upon
reconfiguration if import policy is changed.

Note - The route weight cannot be configured in a policy rule that is set to
"restrict".

Range: 0-65535
Default: None

10. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 500


Configuring Inbound Route Filters in Gaia Portal

Configuring the "Add Individual IPv4 Route Filter"


1. In the Route Filter section, in the Import From field, select the protocol.
Description

Protocol Description

OSPFv2 Configures inbound filtering of IPv4 routes learned from OSPFv2.


OSPF inbound route filters only apply to OSPF ASE routes.
Intra-area and inter-area OSPF routes are always installed.
The default behavior is to accept all OSPF ASE routes.

RIP Configures inbound filtering of IPv4 routes learned from RIP.

BGP Configures inbound filtering of IPv4 routes learned from BGP.


Policy This menu shows the BGP Policy Filters you configured "Based on
<ID> AS-PATH" or "Based on AS". See the sections above.

2. In the Route Filter section, in the Route field, enter the IPv4 address and the Mask
length of the address range.
Description

Configures policy for importing routes from the given protocol that match a specific
address range in CIDR notation.
Range: Dotted-quad ([0-255].[0-255].[0-255].[0-255]) / [0-32]

Default: None

3. In the Route Filter section, in the Match Type field, select how to match the routes.
Description

There are different mechanisms, by which routes can be matched against the
configured subnet.
A match type must be configured following the subnet.
The different match types are:

Step Instructions

Exact Matches only routes with prefix and mask length exactly equal to the
specified network.

Normal Matches any route contained within the specified network.

R82.10 Gaia Advanced Routing Administration Guide | 501


Configuring Inbound Route Filters in Gaia Portal

Step Instructions

Refines Matches only routes that are contained within, but more specific than,
the specified network.
For example, with a greater mask length.

Range Matches any route with prefix equal to the specified network, whose
mask length falls within a particular range.
Range: 1-32

4. In the Route Filter section, in the Action field, select whether to accept or reject this
route.
Description

Action Description

Accept Accepts this route.

Restrict Rejects this route.

5. In the Policy Modifiers section, configure the applicable settings.


n If in the Import From field you selected OSPFv2 or RIP:
In the Rank field, enter the default route rank.
Description

Assigns a rank to all incoming routes matching this filter, except those that match
a more specific rule with a different rank configured.

The routing system uses rank when there are routes from different protocols to
the same destination.
For each route, the route from the protocol with the lowest rank number is used.
See "Protocol Rank" on page 657.

Note - The route rank cannot be configured in a policy rule that is set to
"restrict".

Range: 0-255
Default: For OSPFv2 - The protocol rank configured for "OSPFASE". For RIP -
The protocol rank configured for "RIP".

R82.10 Gaia Advanced Routing Administration Guide | 502


Configuring Inbound Route Filters in Gaia Portal

n If in the Import From field you selected BGP Policy <ID>:


l In the Local Preference field, enter the route local preference.
Description

Assigns a BGP local preference to all routes that match this filter, except
those that match a more specific filter with a different local preference
value configured.
The local preference value is sent automatically when redistributing
external BGP routes to an internal BGP route.
The local preference parameter is ignored if used on internal BGP import
statements.

greater values are preferred by the routing system when it selects between
competing BGP routes.

Best Practice - The local preference configuration is the


recommended way to bias the preference for BGP routes.
Important - Do not use the local preference parameter when
importing BGP.
Note - The local preference cannot be configured in a policy rule
that is set to "restrict".

Range: 0-4294967295
Default: None

R82.10 Gaia Advanced Routing Administration Guide | 503


Configuring Inbound Route Filters in Gaia Portal

l In the Weight field, enter the route weight.


Description

Assigns a BGP weight to all routes that match this filter, except those that
match a more specific filter with a different weight value configured.
BGP stores any routes that are rejected by not mentioning them in a route
filter.
BGP explicitly mentions these rejected routes in the routing table and
assigns them a "restrict" keyword with a negative weight.
A negative weight prevents a route from becoming active, which means
that it is not installed in the forwarding table or exported to other protocols.

This feature eliminates the need to break and re-establish a session upon
reconfiguration if import policy is changed.

Note - The route weight cannot be configured in a policy rule that


is set to "restrict".

Range: 0-65535
Default: None

6. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 504


Configuring Inbound Route Filters in Gaia Portal

Configuring the "Add Individual IPv6 Route Filter"


1. In the Route Filter section, in the Import From field, select the protocol.
Description

Protocol Description

OSPFv3 Configures inbound filtering of IPv6 routes learned from OSPFv3.

BGP Configures inbound filtering of IPv6 routes learned from BGP.


Policy This menu shows the BGP Policy Filters you configured "Based on
<ID> AS-PATH" or "Based on AS". See the sections above.

2. In the Route Filter section, in the Route field, enter the IPv6 address and the Mask
length of the address range.
Description

Configures policy for importing routes from the given protocol that match a specific
address range in CIDR notation.
Range: Dotted-quad ([0-F]:[0-F]:...:[0-F]) / [0-128]
Default: None

3. In the Route Filter section, in the Match Type field, select how to match the routes.
Description

There are different mechanisms, by which routes can be matched against the
configured subnet.

A match type must be configured following the subnet.


The different match types are:

Step Instructions

Exact Matches only routes with prefix and mask length exactly equal to the
specified network.

Normal Matches any route contained within the specified network.

Refines Matches only routes that are contained within, but more specific than,
the specified network.
For example, with a greater mask length.

R82.10 Gaia Advanced Routing Administration Guide | 505


Configuring Inbound Route Filters in Gaia Portal

Step Instructions

Range Matches any route with prefix equal to the specified network, whose
mask length falls within a particular range.
Range: 1-32

4. In the Route Filter section, in the Action field, select whether to accept or reject this
route.
Description

Action Description

Accept Accepts this route.

Restrict Rejects this route.

5. In the Policy Modifiers section, configure the applicable settings.


If in the Import From field you selected OSPFv3:
n In the Rank field, enter the default route rank.
Description

Assigns a rank to all incoming routes matching this filter, except those that match
a more specific rule with a different rank configured.

The routing system uses rank when there are routes from different protocols to
the same destination.
For each route, the route from the protocol with the lowest rank number is used.

See "Protocol Rank" on page 657.

Note - The route rank cannot be configured in a policy rule that is set to
"restrict".

Range: 0-255
Default: For OSPFv2 - The protocol rank configured for "OSPFASE". For RIP -
The protocol rank configured for "RIP".

If in the Import From field you selected BGP Policy <ID>:

R82.10 Gaia Advanced Routing Administration Guide | 506


Configuring Inbound Route Filters in Gaia Portal

n In the Local Preference field, enter the route local preference.


Description

Assigns a BGP local preference to all routes that match this filter, except those
that match a more specific filter with a different local preference value
configured.
The local preference value is sent automatically when redistributing external
BGP routes to an internal BGP route.
The local preference parameter is ignored if used on internal BGP import
statements.
greater values are preferred by the routing system when it selects between
competing BGP routes.

Best Practice - The local preference configuration is the recommended


way to bias the preference for BGP routes.
Important - Do not use the local preference parameter when importing
BGP.
Note - The local preference cannot be configured in a policy rule that is
set to "restrict".

Range: 0-4294967295
Default: None

R82.10 Gaia Advanced Routing Administration Guide | 507


Configuring Inbound Route Filters in Gaia Portal

n In the Weight field, enter the route weight.


Description

Assigns a BGP weight to all routes that match this filter, except those that match
a more specific filter with a different weight value configured.
BGP stores any routes that are rejected by not mentioning them in a route filter.
BGP explicitly mentions these rejected routes in the routing table and assigns
them a "restrict" keyword with a negative weight.
A negative weight prevents a route from becoming active, which means that it is
not installed in the forwarding table or exported to other protocols.
This feature eliminates the need to break and re-establish a session upon
reconfiguration if import policy is changed.

Note - The route weight cannot be configured in a policy rule that is set
to "restrict".

Range: 0-65535
Default: None

6. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 508


Configuring Inbound Route Filters for IPv4 BGP in Gaia Clish

Configuring Inbound Route Filters for IPv4 BGP


in Gaia Clish
Important - In a Cluster, you must configure all the Cluster Members in the same way.

n To see the available "set" commands for IPv4 Inbound Route Filters, enter in Gaia
Clish:

set inbound-route-filter[Esc][Esc]

n To see the configured IPv4 Inbound Route Filters, enter in Gaia Clish:

show configuration inbound-route-filter

R82.10 Gaia Advanced Routing Administration Guide | 509


Configuring Inbound Route Filters for IPv4 BGP in Gaia Clish

Syntax

R82.10 Gaia Advanced Routing Administration Guide | 510


Configuring Inbound Route Filters for IPv4 BGP in Gaia Clish

set inbound-route-filter bgp-policy <BGP Import Policy ID>


accept-all-ipv4
accept-all-ipv6
based-on-as as <AS Number> on
based-on-aspath aspath-regex {<Regular Expression> |
empty} origin {any | egp | igp | incomplete} on
community-match <1-65535> as <1-65535> {off | on}
default-localpref {0-4294967295 | default}
default-weight {0-65535 | default}
extcommunity-match
type transitive-two-octet-as
subtype {bgp-data-collect | cisco-vpn-dist |
l2vpn-id | ospf-domain-id | route-origin | route-target |
source-as} value <1-65535>:<0-4294967295> {on | off}
type non-transitive-two-octet-as
subtype link-bandwidth value <1-65535>:<0-
4294967295> {on | off}
type transitive-four-octet-as
subtype {bgp-data-collect | cisco-vpn-dist |
generic | ospf-domain-id | route-origin | route-target | source-
as} value <65536-4294967295>:<0-65535> {on | off}
type non-transitive-four-octet-as
subtype generic value <65536-4294967295>:<0-
65535> {on | off}
type transitive-ipv4-address
subtype {cisco-vpn-dist | l2vpn-id | ospf-
domain-id | ospf-route-id | route-origin | route-target | vrf-
route-import} value <IPv4 Address>:<0-65535> {on | off}
off
restrict-all-ipv4
restrict-all-ipv6
route <IPv4 or IPv6 Address>/<Mask Length>
accept
between <Start IPv4 Mask Length> and <End IPv4 Mask
Length> on
between <Start IPv4 Mask Length> and <End IPv4 Mask
Length> restrict on
exact on
exact restrict on
localpref {0-4294967295 | default}
normal on
normal restrict on
off
refines on

R82.10 Gaia Advanced Routing Administration Guide | 511


Configuring Inbound Route Filters for IPv4 BGP in Gaia Clish

refines restrict on
weight {0-65535 | default}

Parameters

Parameter Description

set inbound-route- Configures the ID for the BGP Import Policy.


filter bgp-policy The <BGP Import Policy ID> is:
<BGP Import Policy
ID>
n From 1 to 511 for import based on the AS-PATH
attribute.
n From 512 to 1024 for import based on the AS
Number attribute.

accept-all-ipv4 Accepts all IPv4 routes that match this filter, except those
route that are explicitly restricted by a more specific rule.
Accepting routes is the default behavior, unless the
"restrict" option is configured.

accept-all-ipv6 Accepts all IPv6 routes that match this filter, except those
route that are explicitly restricted by a more specific rule.
Accepting routes is the default behavior, unless the
"restrict" option is configured.

based-on-as as <AS Configures a new policy to import BGP routes from a


Number> on particular peer Autonomous System.

based-on-aspath Configures a new policy to import BGP routes, whose AS-


aspath-regex PATH matches a particular regular expression.
{<Regular
Expression> | empty}
origin {any | egp |
igp | incomplete} on

R82.10 Gaia Advanced Routing Administration Guide | 512


Configuring Inbound Route Filters for IPv4 BGP in Gaia Clish

Parameter Description

A valid AS_PATH regular expression contains only digits


and these special characters:
n . - The period character matches any single
character.
n \ - The backslash character matches the character
right after the backslash. For pattern recall, match
the pattern indicated by the digit following the
backslash. To enter the backslash character, enter
two backslash characters (\\ - the first backslash
character escapes the second backslash character).
n ^ - The circumflex character matches the characters
or null string at the beginning of the AS path.
n $ - The dollar character matches the characters or
null string at the end of the AS path.
n ? - The question mark matches zero or one
occurrence of the pattern before "?". To enter the
question mark, press the CTRL V keys and then
press the SHISFT ? keys.
n * - The asterisk character matches zero or more
occurrences of the pattern before "*".
n + - The plus character matches one or more
occurrences of the pattern before "+".
n | - The pipeline (vertical line) character matches one
of the patterns on either side of the "|" character.
n _ - The underscore character matches comma (,),
left brace ({), right brace (}), beginning of ASPath
(^), end of ASPath ($), or a whitespace (space or
tabulation).
n [ ] - The square brackets match the set of characters
or range of characters separated by a hyphen (-)
within the brackets.
n ( ) - The round brackets group one or more patterns
into a single pattern.
n {m n} - Matches at least "m" and at most "n"
repetitions of the pattern before "{m,n}". Both "m"
and "n" are positive integers, and "m" is less than or
equal to "n".
n {m} - Matches exactly "m" repetitions of the pattern
before "{m}". The "m" is a positive integer.
n {m,} - Matches "m" or more repetitions of the pattern
before "{m}". The "m" is a positive integer.
To generate an empty regular expression, use "empty".

R82.10 Gaia Advanced Routing Administration Guide | 513


Configuring Inbound Route Filters for IPv4 BGP in Gaia Clish

Parameter Description

Route origins are:


n any - A route was learned from any protocol and the
path is probably complete.
n egp - A route was learned from an exterior routing
protocol that does not support AS-PATH, and the
path is probably incomplete.
n igp - A route was learned from an interior routing
protocol and the path is probably complete.
n incomplete - The route path information is
incomplete.

community-match <1- Matches routes containing a given Community in the BGP


65535> as <1-65535> Community attribute.
{off | on} Each Community is identified by a Community ID and an
Autonomous System number.
n off - Removes this Community filter from this BGP
import policy
n on - Adds this Community match filter to this BGP
import policy

default-localpref Assigns a BGP local preference to all routes that match


{0-4294967295 | this filter, except those that match a more specific filter
default} with a different local preference value configured.
The local preference value is sent automatically when
redistributing external BGP routes to an internal BGP
route.
The local preference parameter is ignored if used on
internal BGP import statements.
greater values are preferred by the routing system when it
selects between competing BGP routes.
Best Practice - The local preference configuration is
the recommended way to bias the preference for
BGP routes.
Important - Do not use the local preference
parameter when importing BGP.
Note - The local preference cannot be configured in a
policy rule that is set to "restrict".
Range: 0-4294967295
Default: No local preference

R82.10 Gaia Advanced Routing Administration Guide | 514


Configuring Inbound Route Filters for IPv4 BGP in Gaia Clish

Parameter Description

default-weight {0- Assigns a BGP weight to all routes that match this filter,
65535 | default} except those that match a more specific filter with a
different weight value configured.
BGP stores any routes that are rejected by not mentioning
them in a route filter.
BGP explicitly mentions these rejected routes in the
routing table and assigns them a "restrict" keyword with a
negative weight.
A negative weight prevents a route from becoming active,
which means that it is not installed in the forwarding table
or exported to other protocols.
This feature eliminates the need to break and re-establish
a session upon reconfiguration if import policy is changed.
Note - The route weight cannot be configured in a
policy rule that is set to "restrict".
Range: 0-65535
Default: No weight

extcommunity-match Matches routes that contain the specified Extended


type <Type> subtype Community in the BGP Extended Community attribute.
<Subtype> value Note - You can configure a maximum of 25 Extended
<Value> {on | off} Communities.

n type <Type>
Configures the BGP Extended Community type,
which determines the format of the BGP Extended
Community value, and whether it is transitive across
ASes.
You can use Transitive types for eBGP.
You can use Non-Transitive types only for iBGP.
For more information, see RFC 4360.
Supported types:
l transitive-two-octet-as - Transitive

Two Octet AS
l non-transitive-two-octet-as - Non-

Transitive Two Octet AS


l transitive-four-octet-as - Transitive

Four Octet AS
l non-transitive-four-octet-as - Non-

Transitive Four Octet AS


l transitive-ipv4-address - Transitive

IPv4 Address

R82.10 Gaia Advanced Routing Administration Guide | 515


Configuring Inbound Route Filters for IPv4 BGP in Gaia Clish

Parameter Description

n subtype <Subtype>
Configures the Subtype for a BGP Extended
Community.
Supported subtypes (depend on the "Type"):
l bgp-data-collect - BGP Data Collection

l cisco-vpn-dist - Cisco VPN Distinguisher

l generic - Generic

l l2vpn-id - L2VPN Identifier

l link-bandwidth - Link Bandwidth

l ospf-domain-id - OSPF Domain Identifier

l ospf-route-id - OSPF Route ID

l route-origin - Route Origin

l route-target - Route Target

l source-as - Source AS

l vrf-route-import - VRF Route Import

R82.10 Gaia Advanced Routing Administration Guide | 516


Configuring Inbound Route Filters for IPv4 BGP in Gaia Clish

Parameter Description

n value <Value>
Supported values (depend on the "Type"):
l For the Type "transitive-two-octet-

as":
Format: <Two-Octet AS>:<Four-Octet
Value>
Valid values: <1-65535>:<0-4294967295>
l For the Type "non-transitive-two-

octet-as":
Format: <Two-Octet AS>:<Four-Octet
Value>
Valid values: <1-65535>:<0-4294967295>
l For the Type "transitive-four-octet-

as":
Format: <Four-Octet AS>:<Two-Octet
Value>
Valid values: <65536-4294967295>:<0-
65535>
l For the Type "non-transitive-four-

octet-as":
Format: <Four-Octet AS>:<Two-Octet
Value>
Valid values: <65536-4294967295>:<0-
65535>
l For the Type "transitive-ipv4-

address":
Format: <IPv4 Address>:<Two-Octet
Value>
Valid values: <IPv4 Address>:<0-65535>

set inbound-route- Deletes this BGP import policy from the configuration.
filter bgp-policy
<BGP Import Policy
ID> off

restrict-all-ipv4 Rejects all IPv4 routes that match this filter, except those
that match a more specific filter that is set to "accept".

restrict-all-ipv6 Rejects all IPv6 routes that match this filter, except those
that match a more specific filter that is set to "accept".

R82.10 Gaia Advanced Routing Administration Guide | 517


Configuring Inbound Route Filters for IPv4 BGP in Gaia Clish

Parameter Description

route <IPv4 or IPv6 Configures import policy for a specific network.


Address>/<Mask Range: For IPv4 - Dotted-quad ([0-255].[0-255].[0-255].
Length> [0-255]) / [0-32]
Range: For IPv6 - Dotted-octet ([0-F]:[0-F]:[0-F]:[0-F]:[0-
F]:[0-F]:[0-F]:[0-F]) / [0-128]
Default: None

route <IPv4 or IPv6 Accepts this route.


Address>/<Mask
Length> accept

route <IPv4 There are different mechanisms, by which routes can be


Address>/<IPv4 Mask matched against the configured subnet. A match type
Length> between must be configured following the subnet.
<Start IPv4 Mask Accepts any route with prefix equal to the specified
Length> and <End network, whose mask length falls within a particular
IPv4 Mask Length> on range.

route <IPv4 There are different mechanisms, by which routes can be


Address>/<IPv4 Mask matched against the configured subnet. A match type
Length> between must be configured following the subnet.
<Start IPv4 Mask Rejects all routes that match this policy rule, except those
Length> and <End that match a more specific filter that is set to "accept".
IPv4 Mask Length>
restrict on

route <IPv4 or IPv6 There are different mechanisms, by which routes can be
Address>/<Mask matched against the configured subnet. A match type
Length> exact on must be configured following the subnet.
Accepts only routes with prefix and mask length exactly
equal to the specified network.

route <IPv4 or IPv6 There are different mechanisms, by which routes can be
Address>/<Mask matched against the configured subnet. A match type
Length> exact must be configured following the subnet.
restrict on Rejects all routes that match this policy rule, except those
that match a more specific filter that is set to "accept".

R82.10 Gaia Advanced Routing Administration Guide | 518


Configuring Inbound Route Filters for IPv4 BGP in Gaia Clish

Parameter Description

route <IPv4 or IPv6 Assigns a BGP local preference to all routes that match
Address>/<Mask this filter, except those that match a more specific filter
Length> localpref with a different local preference value configured.
{0-4294967295 | The local preference value is sent automatically when
default} redistributing external BGP routes to an internal BGP
route.
The local preference parameter is ignored if used on
internal BGP import statements.
greater values are preferred by the routing system when it
selects between competing BGP routes.
Best Practice - The local preference configuration is
the recommended way to bias the preference for
BGP routes.
Important - Do not use the local preference
parameter when importing BGP.
Note - The local preference cannot be configured in a
policy rule that is set to "restrict".
Range: 0-4294967295
Default: No local preference

route <IPv4 or IPv6 There are different mechanisms, by which routes can be
Address>/<Mask matched against the configured subnet. A match type
Length> normal on must be configured following the subnet.
Accepts any route equal to or contained within the
specified network.

route <IPv4 or IPv6 There are different mechanisms, by which routes can be
Address>/<Mask matched against the configured subnet. A match type
Length> normal must be configured following the subnet.
restrict on Rejects all routes that match this policy rule, except those
that match a more specific filter that is set to "accept".

route <IPv4 or IPv6 Removes this address filter from this import policy.
Address>/<Mask
Length> off

route <IPv4 or IPv6 There are different mechanisms, by which routes can be
Address>/<Mask matched against the configured subnet. A match type
Length> refines on must be configured following the subnet.
Matches routes contained within the specified network,
but only more specific (for example, with a greater mask
length).

R82.10 Gaia Advanced Routing Administration Guide | 519


Configuring Inbound Route Filters for IPv4 BGP in Gaia Clish

Parameter Description

route <IPv4 or IPv6 There are different mechanisms, by which routes can be
Address>/<Mask matched against the configured subnet. A match type
Length> refines must be configured following the subnet.
restrict on Rejects all routes that match this policy rule, except those
that match a more specific filter that is set to "accept".

route <IPv4 or IPv6 Assigns a BGP weight to all routes that match this filter,
Address>/<Mask except those that match a more specific filter with a
Length> weight {0- different weight value configured.
65535 | default} BGP stores any routes that are rejected by not mentioning
them in a route filter.
BGP explicitly mentions these rejected routes in the
routing table and assigns them a "restrict" keyword with a
negative weight.
A negative weight prevents a route from becoming active,
which means that it is not installed in the forwarding table
or exported to other protocols.
This feature eliminates the need to break and re-establish
a session upon reconfiguration if import policy is changed.
Note - The route weight cannot be configured in a
policy rule that is set to "restrict".
Range: 0-65535
Default: No weight

Example 1

Accept all IPv4 and IPv6 routes received from AS 4.

set inbound-route-filter bgp-policy 512 based-on-as as 4 on


set inbound-route-filter bgp-policy 512 accept-all-ipv4
set inbound-route-filter bgp-policy 512 accept-all-ipv6

R82.10 Gaia Advanced Routing Administration Guide | 520


Configuring Inbound Route Filters for IPv4 BGP in Gaia Clish

Example 2

Accept only routes that are subnets of [Link]/8,


or the exact route 1234::/64 from AS 22,
and assign a default local preference.

set inbound-route-filter bgp-policy 1000 based-on-as as 22 on


set inbound-route-filter bgp-policy 1000 restrict-all-ipv4
set inbound-route-filter bgp-policy 1000 restrict-all-ipv6
set inbound-route-filter bgp-policy 1000 route [Link]/8 normal
on
set inbound-route-filter bgp-policy 1000 route 1234::/64 exact
on
set inbound-route-filter bgp-policy 1000 default-localpref 1000

R82.10 Gaia Advanced Routing Administration Guide | 521


Configuring Inbound Route Filters for IPv4 OSPFv2 in Gaia Clish

Configuring Inbound Route Filters for IPv4


OSPFv2 in Gaia Clish
Important - In a Cluster, you must configure all the Cluster Members in the same way.

OSPF inbound route filters only apply to OSPF ASE routes.


Intra-area and inter-area OSPF routes are always installed.
The default behavior is to accept all OSPF ASE routes.
n To see the available "set" commands for IPv4 Inbound Route Filters, enter in Gaia
Clish:

set inbound-route-filter[Esc][Esc]

n To see the configured IPv4 Inbound Route Filters, enter in Gaia Clish:

show configuration inbound-route-filter

Syntax

set inbound-route-filter ospf2 [instance <OSPF Instance Number>]


accept-all-ipv4
rank {<0-255> | default}
restrict-all-ipv4
route <IPv4 Address>/<Mask Length>
accept
between <Start IPv4 Mask Length> and <End IPv4 Mask
Length> on
between <Start IPv4 Mask Length> and <End IPv4 Mask
Length> restrict on
exact on
exact restrict on
normal on
normal restrict on
off
rank {<0-255> | default}
refines on
refines restrict on

R82.10 Gaia Advanced Routing Administration Guide | 522


Configuring Inbound Route Filters for IPv4 OSPFv2 in Gaia Clish

Parameters

Parameter Description

set inbound-route-filter ospf2 Configures the IPv4 OSPFv2 Import Policy


[instance <OSPF Instance (for the specified OSPF instance).
Number>]

accept-all-ipv4 Accepts all IPv4 routes that match this


filter, except those route that are explicitly
restricted by a more specific rule.
Accepting routes is the default behavior,
unless the "restrict" option is configured.

rank {<0-255> | default} Assigns a rank to all incoming routes that


match this filter, except those that match a
more specific rule with a different rank
configured.
Range: 0-255, or default
Default: The protocol rank configured for
"OSPFASE". Run the "show protocol-
rank" command.

restrict-all-ipv4 Rejects all IPv4 routes that match this


filter, except those that match a more
specific filter that is set to "accept".

route <IPv4 Address>/<Mask Configures import policy for a specific


Length> network.
Range: Dotted-quad ([0-255].[0-255].[0-
255].[0-255]) / [0-32]
Default: None

route <IPv4 Address>/<Mask Accepts this route.


Length> accept

route <IPv4 Address>/<IPv4 Mask There are different mechanisms, by which


Length> between <Start IPv4 routes can be matched against the
Mask Length> and <End IPv4 Mask configured subnet. A match type must be
Length> on configured following the subnet.
Accepts any route with prefix equal to the
specified network, whose mask length falls
within a particular range.

R82.10 Gaia Advanced Routing Administration Guide | 523


Configuring Inbound Route Filters for IPv4 OSPFv2 in Gaia Clish

Parameter Description

route <IPv4 Address>/<IPv4 Mask There are different mechanisms, by which


Length> between <Start IPv4 routes can be matched against the
Mask Length> and <End IPv4 Mask configured subnet. A match type must be
Length> restrict on configured following the subnet.
Rejects all routes that match this policy
rule, except those that match a more
specific filter that is set to "accept".

route <IPv4 Address>/<Mask There are different mechanisms, by which


Length> exact on routes can be matched against the
configured subnet. A match type must be
configured following the subnet.
Accepts only routes with prefix and mask
length exactly equal to the specified
network.

route <IPv4 Address>/<Mask There are different mechanisms, by which


Length> exact restrict on routes can be matched against the
configured subnet. A match type must be
configured following the subnet.
Rejects all routes that match this policy
rule, except those that match a more
specific filter that is set to "accept".

route <IPv4 Address>/<Mask There are different mechanisms, by which


Length> normal on routes can be matched against the
configured subnet. A match type must be
configured following the subnet.
Accepts any route equal to or contained
within the specified network.

route <IPv4 Address>/<Mask There are different mechanisms, by which


Length> normal restrict on routes can be matched against the
configured subnet. A match type must be
configured following the subnet.
Rejects all routes that match this policy
rule, except those that match a more
specific filter that is set to "accept".

route <IPv4 Address>/<Mask Removes this address filter from this


Length> off import policy.

R82.10 Gaia Advanced Routing Administration Guide | 524


Configuring Inbound Route Filters for IPv4 OSPFv2 in Gaia Clish

Parameter Description

route <IPv4 Address>/<Mask Assigns a rank to all incoming routes that


Length> rank {<0-255> | match this filter, except those that match a
default} more specific rule with a different rank
configured.
Range: 0-255, or default
Default: The protocol rank configured for
"OSPFASE". Run the "show protocol-
rank" command.

route <IPv4 Address>/<Mask There are different mechanisms, by which


Length> refines on routes can be matched against the
configured subnet. A match type must be
configured following the subnet.
Matches routes contained within the
specified network, but only more specific
(for example, with a greater mask length).

route <IPv4 Address>/<Mask There are different mechanisms, by which


Length> refines restrict on routes can be matched against the
configured subnet. A match type must be
configured following the subnet.
Rejects all routes that match this policy
rule, except those that match a more
specific filter that is set to "accept".

Example

Only accept subnets of [Link]/16, but do not accept the exact route itself.

set inbound-route-filter ospf2 restrict-all-ipv4


set inbound-route-filter ospf2 route [Link]/16 refines on

R82.10 Gaia Advanced Routing Administration Guide | 525


Configuring Inbound Route Filters for IPv4 RIP in Gaia Clish

Configuring Inbound Route Filters for IPv4 RIP


in Gaia Clish
Important - In a Cluster, you must configure all the Cluster Members in the same way.

The default behavior is to accept all RIP routes.


n To see the available "set" commands for IPv4 Inbound Route Filters, enter in Gaia
Clish:

set inbound-route-filter[Esc][Esc]

n To see the configured IPv4 Inbound Route Filters, enter in Gaia Clish:

show configuration inbound-route-filter

Syntax

set inbound-route-filter rip


accept-all-ipv4
rank {<0-255> | default}
restrict-all-ipv4
route <IPv4 Address>/<Mask Length>
accept
between <Start Mask Length> and <End Mask Length> on
between <Start Mask Length> and <End Mask Length>
restrict on
exact on
exact restrict on
normal on
normal restrict on
off
route <IP Address>/<Mask Length> rank {<0-255> |
default}
refines on
refines restrict on

Parameters

Parameter Description

set inbound-route-filter rip Configures the IPv4 RIP Import Policy

R82.10 Gaia Advanced Routing Administration Guide | 526


Configuring Inbound Route Filters for IPv4 RIP in Gaia Clish

Parameter Description

accept-all-ipv4 Accepts all IPv4 routes that match this


filter, except those route that are explicitly
restricted by a more specific rule.
Accepting routes is the default behavior,
unless the "restrict" option is configured.

rank {<0-255> | default} Assigns a rank to all incoming routes that


match this filter, except those that match a
more specific rule with a different rank
configured.
Range: 0-255, or default
Default: The protocol rank configured for
"RIP". Run the "show protocol-rank"
command.

restrict-all-ipv4 Rejects all IPv4 routes that match this


filter, except those that match a more
specific filter that is set to "accept".

route <IPv4 Address>/<Mask Configures import policy for a specific


Length> network.
Range: Dotted-quad ([0-255].[0-255].[0-
255].[0-255]) / [0-32]
Default: None

route <IPv4 Address>/<Mask Accepts this route.


Length> accept

route <IPv4 Address>/<IPv4 Mask There are different mechanisms, by which


Length> between <Start IPv4 routes can be matched against the
Mask Length> and <End IPv4 Mask configured subnet. A match type must be
Length> on configured following the subnet.
Accepts any route with prefix equal to the
specified network, whose mask length falls
within a particular range.

route <IPv4 Address>/<IPv4 Mask There are different mechanisms, by which


Length> between <Start IPv4 routes can be matched against the
Mask Length> and <End IPv4 Mask configured subnet. A match type must be
Length> restrict on configured following the subnet.
Rejects all routes that match this policy
rule, except those that match a more
specific filter that is set to "accept".

R82.10 Gaia Advanced Routing Administration Guide | 527


Configuring Inbound Route Filters for IPv4 RIP in Gaia Clish

Parameter Description

route <IPv4 Address>/<Mask There are different mechanisms, by which


Length> exact on routes can be matched against the
configured subnet. A match type must be
configured following the subnet.
Accepts only routes with prefix and mask
length exactly equal to the specified
network.

route <IPv4 Address>/<Mask There are different mechanisms, by which


Length> exact restrict on routes can be matched against the
configured subnet. A match type must be
configured following the subnet.
Rejects all routes that match this policy
rule, except those that match a more
specific filter that is set to "accept".

route <IPv4 Address>/<Mask There are different mechanisms, by which


Length> normal on routes can be matched against the
configured subnet. A match type must be
configured following the subnet.
Accepts any route equal to or contained
within the specified network.

route <IPv4 Address>/<Mask There are different mechanisms, by which


Length> normal restrict on routes can be matched against the
configured subnet. A match type must be
configured following the subnet.
Rejects all routes that match this policy
rule, except those that match a more
specific filter that is set to "accept".

route <IPv4 Address>/<Mask Removes this address filter from this


Length> off import policy.

route <IPv4 Address>/<Mask Assigns a rank to all incoming routes that


Length> rank {<0-255> | match this filter, except those that match a
default} more specific rule with a different rank
configured.
Range: 0-255, or default
Default: The protocol rank configured for
"RIP". Run the "show protocol-rank"
command.

R82.10 Gaia Advanced Routing Administration Guide | 528


Configuring Inbound Route Filters for IPv4 RIP in Gaia Clish

Parameter Description

route <IPv4 Address>/<Mask There are different mechanisms, by which


Length> refines on routes can be matched against the
configured subnet. A match type must be
configured following the subnet.
Matches routes contained within the
specified network, but only more specific
(for example, with a greater mask length).

route <IPv4 Address>/<Mask There are different mechanisms, by which


Length> refines restrict on routes can be matched against the
configured subnet. A match type must be
configured following the subnet.
Rejects all routes that match this policy
rule, except those that match a more
specific filter that is set to "accept".

Example

Accept all IPv4 routes except for [Link]/16 and its subnets.

set inbound-route-filter rip accept-all-ipv4


set inbound-route-filter rip route [Link]/16 normal restrict
on

R82.10 Gaia Advanced Routing Administration Guide | 529


Configuring Inbound Route Filters for IPv6 OSPFv3 in Gaia Clish

Configuring Inbound Route Filters for IPv6


OSPFv3 in Gaia Clish
Important - In a Cluster, you must configure all the Cluster Members in the same way.

OSPFv3 inbound route filters only apply to OSPFv3 ASE routes.


Intra-area and inter-area OSPFv3 routes are always installed.
The default behavior is to accept all OSPFv3 ASE routes.
n To see the available "set" commands for IPv6 Inbound Route Filters, enter in Gaia
Clish:

set ipv6 inbound-route-filter[Esc][Esc]

n To see the configured IPv6 Inbound Route Filters, enter in Gaia Clish:

show configuration ipv6 inbound-route-filter

Syntax

set ipv6 inbound-route-filter ospf3 [instance {<1-65535> |


default}]
accept-all-ipv6
rank {<0-255> | default}
restrict-all-ipv6
route <IPv6 Address>/<Mask Length>
accept
exact on
exact restrict on
normal on
normal restrict on
off
rank {<0-255> | default}
refines on
refines restrict on

R82.10 Gaia Advanced Routing Administration Guide | 530


Configuring Inbound Route Filters for IPv6 OSPFv3 in Gaia Clish

Parameters

Parameter Description

set ipv6 inbound-route- Configures the IPv6 OSPFv3 Import Policy (for the
filter ospf3 [instance specified OSPF instance).
{<1-65535> | default}]

accept-all-ipv6 Accepts all IPv6 routes that match this filter, except
those route that are explicitly restricted by a more
specific rule.
Accepting routes is the default behavior, unless the
"restrict" option is configured.

rank {<0-255> | Assigns a rank to all incoming routes that match this
default} filter, except those that match a more specific rule
with a different rank configured.
Range: 0-255, or default
Default: The protocol rank configured for
"OSPF3ASE". Run the "show protocol-rank"
command.

restrict-all-ipv6 Rejects all IPv6 routes that match this filter, except
those that match a more specific filter that is set to
"accept".

route <IPv6 Configures import policy for a specific network.


Address>/<Mask Length> Range: Dotted-octet ([0-F]:[0-F]:[0-F]:[0-F]:[0-F]:[0-
F]:[0-F]:[0-F]) / [0-128]
Default: None

route <IPv6 Accepts this route.


Address>/<Mask Length>
accept

route <IPv6 There are different mechanisms, by which routes can


Address>/<Mask Length> be matched against the configured subnet. A match
exact on type must be configured following the subnet.
Accepts only routes with prefix and mask length
exactly equal to the specified network.

route <IPv6 There are different mechanisms, by which routes can


Address>/<Mask Length> be matched against the configured subnet. A match
exact restrict on type must be configured following the subnet.
Rejects all routes that match this policy rule, except
those that match a more specific filter that is set to
"accept".

R82.10 Gaia Advanced Routing Administration Guide | 531


Configuring Inbound Route Filters for IPv6 OSPFv3 in Gaia Clish

Parameter Description

route <IPv6 There are different mechanisms, by which routes can


Address>/<Mask Length> be matched against the configured subnet. A match
normal on type must be configured following the subnet.
Accepts any route equal to or contained within the
specified network.

route <IPv6 There are different mechanisms, by which routes can


Address>/<Mask Length> be matched against the configured subnet. A match
normal restrict on type must be configured following the subnet.
Rejects all routes that match this policy rule, except
those that match a more specific filter that is set to
"accept".

route <IPv6 Removes this address filter from this import policy.
Address>/<Mask Length>
off

route <IPv6 Assigns a rank to all incoming routes that match this
Address>/<Mask Length> filter, except those that match a more specific rule
rank {<0-255> | with a different rank configured.
default} Range: 0-255, or default
Default: The protocol rank configured for
"OSPF3ASE". Run the "show protocol-rank"
command.

route <IPv6 There are different mechanisms, by which routes can


Address>/<Mask Length> be matched against the configured subnet. A match
refines on type must be configured following the subnet.
Matches routes contained within the specified
network, but only more specific (for example, with a
greater mask length).

route <IPv6 There are different mechanisms, by which routes can


Address>/<Mask Length> be matched against the configured subnet. A match
refines restrict on type must be configured following the subnet.
Rejects all routes that match this policy rule, except
those that match a more specific filter that is set to
"accept".

Example

Accept all routes, but assign a different protocol rank to subnets of 5678::/64.

R82.10 Gaia Advanced Routing Administration Guide | 532


Configuring Inbound Route Filters for IPv6 OSPFv3 in Gaia Clish

set ipv6 inbound-route-filter ospf3 accept-all-ipv6


set ipv6 inbound-route-filter ospf3 route 5678::/64 normal on
set ipv6 inbound-route-filter ospf3 route 5678::/64 rank 15

R82.10 Gaia Advanced Routing Administration Guide | 533


Configuring Route Redistribution in Gaia Portal

Configuring Route Redistribution in Gaia Portal


In This Section:

Procedure to Configure Route Redistribution 534


Procedure to Configure BGP Redistribution Settings 548

Important - In a Cluster, you must configure all the Cluster Members in the same way.

Route redistribution lets a router propagate routes between routing protocols - IPv4 or IPv6.

Route redistribution is also useful for advertising the default route, static routes, or aggregate
routes.

Note - Static routes take precedence over dynamic routes of any kind, native or
redistributed.

Procedure to Configure Route Redistribution


1. From the left navigation tree, click Advanced Routing > Route Redistribution.
2. In the Route Redistributions section:
n To add a redistributed route, click Add Redistribution From.
n To edit a redistributed route, select it and click Edit.

3. Configure the applicable settings.


See the corresponding sections below.

4. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 534


Configuring Route Redistribution in Gaia Portal

Add Redistribution From - Interface

Redistributes interface routes.


Settings

Parameter Description

To Protocol Configures the destination routing protocol.

Interface Configures the interface from which to distribute the routes.


You can select all, or one of the configured interfaces.

Metric Configures the cost of the redistributed routes in the destination routing
protocol.

R82.10 Gaia Advanced Routing Administration Guide | 535


Configuring Route Redistribution in Gaia Portal

Add Redistribution From - Static

Redistributes static routes.


Settings

Parameter Description

To Protocol Configures the destination routing protocol:


n RIP
n OSPFv2
n BGP AS <Peer Group AS>
n RIPng
n OSPFv3

Static Route Configures the static route to be redistributed into the destination routing
protocol:
n All IPv4 Routes
n Default
n All IPv6 Routes

Metric Configures the cost of the redistributed routes in the destination routing
protocol.
Note - This parameter is mandatory when configuring redistribution
into RIP.
Range:
n RIP: 1-16
n OSPFv2: 1-16777215
n BGP AS <Peer Group AS>: 1-4294967295
n RIPng: 2-16
n OSPFv3: 8-16777215

R82.10 Gaia Advanced Routing Administration Guide | 536


Configuring Route Redistribution in Gaia Portal

Add Redistribution From - Aggregate

Redistributes aggregate routes.


Settings

Parameter Description

To Protocol Configures the destination routing protocol:


n RIP
n OSPFv2
n BGP AS <Peer Group AS>

Aggregate Configures the route to be redistributed into the destination routing


Route protocol:
n All IPv4 Routes

Metric Configures the cost of the redistributed routes in the destination routing
protocol.
Note - This parameter is mandatory when configuring
redistribution into RIP.
Range:
n RIP: 1-16
n OSPFv2: 1-16777215
n BGP AS <Peer Group AS>: 1-4294967295

Add Redistribution From - NAT Pool

Redistributes NAT Pools. See "NAT Pools" on page 726.


Settings

Parameter Description

To Protocol Configures the destination routing protocol.

NAT Pool Selects the NAT Pool to distribute.


You can select All IPv4 Routes, All IPv6 Routes, or one of the
configured NAT Pools.

Metric Configures the cost of the redistributed routes in the destination routing
protocol.

R82.10 Gaia Advanced Routing Administration Guide | 537


Configuring Route Redistribution in Gaia Portal

Add Redistribution From - Kernel

Redistributes OS kernel routes.


Settings

Parameter Description

To Protocol Configures the destination routing protocol:


n RIP
n OSPFv2
n BGP AS <Peer Group AS>
n RIPng
n OSPFv3

Route Configures the routes to redistribute:


n Select All IPv4 Routes to redistribute all IPv4 routes.
Select All IPv6 Routes to redistribute all IPv6 routes.
n Configure the Address Range to redistribute specific routes.
n There are different mechanisms, by which routes can be matched
against the configured subnet:
l Exact - Matches only routes with prefix and mask length

exactly equal to the specified network.


l Normal - Matches any route contained within the specified

network.
l Refines - Matches only routes that are contained within, but

more specific than, the specified network. For example, with


a greater mask length.

Metric Configures the cost of the redistributed routes in the destination routing
protocol.
Note - This parameter is mandatory when configuring redistribution
into RIP.
Range:
n RIP: 1-16
n OSPFv2: 1-16777215
n BGP AS <Peer Group AS>: 1-4294967295
n RIPng: 2-16
n OSPFv3: 8-16777215

R82.10 Gaia Advanced Routing Administration Guide | 538


Configuring Route Redistribution in Gaia Portal

Add Redistribution From - RIP

Redistributes RIP routes.


Settings

Parameter Description

To Protocol Configures the destination routing protocol:


n OSPFv2
n BGP AS <Peer Group AS>

Route Configures the routes to redistribute:


n Select All IPv4 Routes to redistribute all IPv4 routes.
n Configure the Address Range to redistribute specific routes.
n There are different mechanisms, by which routes can be matched
against the configured subnet:
l Exact - Matches only routes with prefix and mask length

exactly equal to the specified network.


l Normal - Matches any route contained within the specified

network.
l Refines - Matches only routes that are contained within, but

more specific than, the specified network. For example, with


a greater mask length.

Action Configures whether to accept or reject this route.

Metric Configures the cost of the redistributed routes in the destination routing
protocol.
Range:
n OSPFv2: 1-16777215
n BGP AS <Peer Group AS>: 1-4294967295

R82.10 Gaia Advanced Routing Administration Guide | 539


Configuring Route Redistribution in Gaia Portal

Add Redistribution From - OSPFv2, or OSPFv2 External

Redistributes OSPFv2 routes.


Settings

Parameter Description

To Protocol Configures the destination routing protocol:


n RIP
n OSPFv2
n BGP AS <Peer Group AS>

Route Configures the routes to redistribute:


n Select All IPv4 Routes to redistribute all IPv4 routes.
n Configure the Address Range to redistribute specific routes.
n There are different mechanisms, by which routes can be matched
against the configured subnet:
l Exact - Matches only routes with prefix and mask length

exactly equal to the specified network.


l Normal - Matches any route contained within the specified

network.
l Refines - Matches only routes that are contained within, but

more specific than, the specified network. For example, with


a greater mask length.

Action Configures whether to accept or reject this route.

Metric Configures the cost of the redistributed routes in the destination routing
protocol.
Note - This parameter is mandatory when configuring redistribution
into RIP.
Range:
n RIP: 1-16
n OSPFv2: 1-16777215
n BGP AS <Peer Group AS>: 1-4294967295

RIP Tag Optional: Configures the RIP tag assigned to exported routes.
Range: 1-65535

R82.10 Gaia Advanced Routing Administration Guide | 540


Configuring Route Redistribution in Gaia Portal

Add Redistribution From - BGP Based on AS-Path

Redistributes BGP routes based on the AS-Path attribute.


Settings

Parameter Description

To Protocol Configures the destination routing protocol:


n RIP
n OSPFv2
n BGP AS <Peer Group AS>
n RIPng
n OSPFv3

R82.10 Gaia Advanced Routing Administration Guide | 541


Configuring Route Redistribution in Gaia Portal

Parameter Description

From BGP Configures the AS_PATH regular expression that contains only digits
AS-Path and these special characters:
n . - The period character matches any single character.
n \ - The backslash character matches the character right after the
backslash. For pattern recall, match the pattern indicated by the
digit following the backslash.
n ^ - The circumflex character matches the characters or null string
at the beginning of the AS path.
n $ - The dollar character matches the characters or null string at the
end of the AS path.
n ? - The question mark matches zero or one occurrence of the
pattern before "?".
n * - The asterisk character matches zero or more occurrences of the
pattern before "*".
n + - The plus character matches one or more occurrences of the
pattern before "+".
n | - The pipeline (vertical line) character matches one of the patterns
on either side of the "|" character.
n _ - The underscore character matches comma (,), left brace ({),
right brace (}), beginning of ASPath (^), end of ASPath ($), or a
whitespace (space or tabulation).
n [ ] - The square brackets match the set of characters or range of
characters separated by a hyphen (-) within the brackets.
n ( ) - The round brackets group one or more patterns into a single
pattern.
n {m n} - Matches at least "m" and at most "n" repetitions of the
pattern before "{m,n}". Both "m" and "n" are positive integers, and
"m" is less than or equal to "n".
n {m} - Matches exactly "m" repetitions of the pattern before "{m}".
The "m" is a positive integer.
n {m,} - Matches "m" or more repetitions of the pattern before "{m}".
The "m" is a positive integer.
Configures the route origin:
n Any - A route was learned from any protocol and the path is
probably complete.
n IGP - A route was learned from an interior routing protocol and the
path is probably complete.
n EGP - A route was learned from an exterior routing protocol that
does not support AS-PATH, and the path is probably incomplete.
n Incomplete - The route path information is incomplete.

R82.10 Gaia Advanced Routing Administration Guide | 542


Configuring Route Redistribution in Gaia Portal

Parameter Description

Route Configures the routes to redistribute:


n Select All IPv4 Routes to redistribute all IPv4 routes.
Select All IPv6 Routes to redistribute all IPv6 routes.
n Configure the Address Range to redistribute specific routes.
n There are different mechanisms, by which routes can be matched
against the configured subnet:
l Exact - Matches only routes with prefix and mask length

exactly equal to the specified network.


l Normal - Matches any route contained within the specified

network.
l Refines - Matches only routes that are contained within, but

more specific than, the specified network. For example, with


a greater mask length.

Action Configures whether to accept or reject this route.

Metric Configures the cost of the redistributed routes in the destination routing
protocol.
Note - This parameter is mandatory when configuring redistribution
into RIP.
Range:
n RIP: 1-16
n OSPFv2: 1-16777215
n BGP AS <Peer Group AS>: 1-4294967295
n RIPng: 2-16
n OSPFv3: 8-16777215

RIP Tag Optional: Configures the RIP tag assigned to exported routes.
Range: 1-65535

Automatic Optional: Automatically generates the external OSPF route tag based
Tag on the BGP AS.
If enabled, the tag is attached to external OSPF routes upon export.

Manual Tag Optional: Configures the external OSPF route tag assigned to exported
routes.
Note - The Manual Tag value takes precedence over the Automatic
Tag value when both are configured.
Range: 1-2147483647

R82.10 Gaia Advanced Routing Administration Guide | 543


Configuring Route Redistribution in Gaia Portal

Add Redistribution From - BGP Based on AS

Redistributes BGP routes based on the AS Number.


Settings

Parameter Description

To Protocol Configures the destination routing protocol:


n RIP
n OSPFv2
n BGP AS <Peer Group AS>
n RIPng
n OSPFv3

From BGP Configures the AS Number:


AS
n BGP AS <Peer Group AS>

Route Configures the routes to redistribute:


n Select All IPv4 Routes to redistribute all IPv4 routes.
Select All IPv6 Routes to redistribute all IPv6 routes.
n Configure the Address Range to redistribute specific routes.
n There are different mechanisms, by which routes can be matched
against the configured subnet:
l Exact - Matches only routes with prefix and mask length

exactly equal to the specified network.


l Normal - Matches any route contained within the specified

network.
l Refines - Matches only routes that are contained within, but

more specific than, the specified network. For example, with


a greater mask length.

Action Configures whether to accept or reject this route.

Metric Configures the cost of the redistributed routes in the destination routing
protocol.
Note - This parameter is mandatory when configuring redistribution
into RIP.
Range:
n RIP: 1-16
n OSPFv2: 1-16777215
n BGP AS <Peer Group AS>: 1-4294967295
n RIPng: 2-16
n OSPFv3: 8-16777215

R82.10 Gaia Advanced Routing Administration Guide | 544


Configuring Route Redistribution in Gaia Portal

Parameter Description

RIP Tag Optional: Configures the RIP tag assigned to exported routes.
Range: 1-65535

Automatic Optional: Automatically generates the external OSPF route tag based
Tag on the BGP AS.
If enabled, the tag is attached to external OSPF routes upon export.

Manual Tag Optional: Configures the external OSPF route tag assigned to exported
routes.
Note - The Manual Tag value takes precedence over the Automatic
Tag value when both are configured.
Range: 1-2147483647

Add Redistribution From - BGP Default Origin

Redistributes all IPv4 routes into BGP.


Settings

Parameter Description

To Protocol Configures the destination routing protocol:


n BGP AS <Peer Group AS>

Metric Configures the cost of the redistributed routes in the destination routing
protocol.
Range: 1-4294967295

R82.10 Gaia Advanced Routing Administration Guide | 545


Configuring Route Redistribution in Gaia Portal

Add Redistribution From - RIPng

Redistributes IPv6 RIPng routes.


Settings

Parameter Description

To Protocol Configures the destination routing protocol:


n BGP AS <Peer Group AS>
n OSPFv3

Route Configures the routes to redistribute:


n Select All IPv6 Routes to redistribute all IPv6 routes.
n Configure the Address Range to redistribute specific routes.
n There are different mechanisms, by which routes can be matched
against the configured subnet:
l Exact - Matches only routes with prefix and mask length

exactly equal to the specified network.


l Normal - Matches any route contained within the specified

network.
l Refines - Matches only routes that are contained within, but

more specific than, the specified network. For example, with


a greater mask length.

Action Configures whether to accept or reject this route.

Metric Configures the cost of the redistributed routes in the destination routing
protocol.
Range:
n BGP AS <Peer Group AS>: 1-4294967295
n OSPFv3: 1-16777215

R82.10 Gaia Advanced Routing Administration Guide | 546


Configuring Route Redistribution in Gaia Portal

Add Redistribution From - OSPFv3, or OSPFv3 External

Redistributes IPv6 OSPFv3 routes.


Settings

Parameter Description

To Protocol Configures the destination routing protocol:


n BGP AS <Peer Group AS>
n RIPng
n OSPFv3

Route Configures the routes to redistribute:


n Select All IPv6 Routes to redistribute all IPv6 routes.
n Configure the Address Range to redistribute specific routes.
n There are different mechanisms, by which routes can be matched
against the configured subnet:
l Exact - Matches only routes with prefix and mask length

exactly equal to the specified network.


l Normal - Matches any route contained within the specified

network.
l Refines - Matches only routes that are contained within, but

more specific than, the specified network. For example, with


a greater mask length.

Action Configures whether to accept or reject this route.

Metric Configures the cost of the redistributed routes in the destination routing
protocol.
Range:
n BGP AS <Peer Group AS>: 1-4294967295
n OSPFv3: 1-16777215

R82.10 Gaia Advanced Routing Administration Guide | 547


Configuring Route Redistribution in Gaia Portal

Procedure to Configure BGP Redistribution Settings


Settings

1. From the left navigation tree, click Advanced Routing > Route Redistribution.
2. In the BGP Redistribution Settings section, select a BGP Group and click Edit.
3. Configure the applicable settings:
n MED (Multi-Exit Discriminator) - The cost of using this route (0 - 4294967295)
n Local Preference - Local BGP route preference value when routes are
redistributed into BGP (0 - 4294967295). The greater the local preference, the
more preferred is the route.
n In the Match AS Numbers to Communities section, click Add.
Applies this redistribution rule only to BGP routes, whose BGP Community
attribute contains a specified Community.
Configure the applicable Community and AS Number.
Click OK.
n In the Append AS Numbers to Communities section, click Add.
Appends a BGP Community to routes exported through this rule.
Configure the applicable Community and AS Number.
Click OK.
n In the Match Extended Communities section, click Add.
Applies this redistribution rule only to BGP routes, whose BGP Extended
Community attributes match the configured settings.
Configure the settings and click OK.

R82.10 Gaia Advanced Routing Administration Guide | 548


Configuring Route Redistribution in Gaia Portal

Type Required Settings

Transitive Two Octet AS a. In the AS field, enter a value 1 - 65535.


b. In the Value, enter a value 0 -
4294967295.
c. In the Subtype, select the applicable
option:
l Route Target

l Route Origin

l OSPF Domain Identifier

l BGP Data Collection

l L2VPN Identifier

l Cisco VPN Distinguisher

l Source AS

Non-Transitive Two Octet a. In the AS field, enter a value 1 - 65535.


AS b. In the Value, enter a value 0 -
4294967295.
c. In the Subtype, select Link Bandwidth.

Transitive Four Octet AS a. In the AS field, enter a value 65536 -


4294967295.
b. In the Value, enter a value 0 - 65535.
c. In the Subtype, select the applicable
option:
l Route Target

l Route Origin

l OSPF Domain Identifier

l BGP Data Collection

l Generic

l Cisco VPN Distinguisher

l Source AS

Non-Transitive Four Octet a. In the AS field, enter a value 65536 -


AS 4294967295.
b. In the Value, enter a value 0 - 65535.
c. In the Subtype, select Generic.

R82.10 Gaia Advanced Routing Administration Guide | 549


Configuring Route Redistribution in Gaia Portal

Type Required Settings

Transitive IPv4 Address a. In the IPv4 field, enter an IPv4 address.


b. In the Value, enter a value 0 - 65535.
c. In the Subtype, select the applicable
option:
l Route Target

l Route Origin

l OSPF Domain Identifier

l OSPF Route ID

l L2VPN Identifier

l Cisco VPN Distinguisher

l VRF Route Import

n In the Append Extended Communities section, click Add.


Appends a BGP Extended Community to routes exported through this rule.
Configure the settings and click OK.

Type Required Settings

Transitive Two Octet AS a. In the AS field, enter a value 1 - 65535.


b. In the Value, enter a value 0 -
4294967295.
c. In the Subtype, select the applicable
option:
l Route Target

l Route Origin

l OSPF Domain Identifier

l BGP Data Collection

l L2VPN Identifier

l Cisco VPN Distinguisher

l Source AS

Non-Transitive Two Octet a. In the AS field, enter a value 1 - 65535.


AS b. In the Value, enter a value 0 -
4294967295.
c. In the Subtype, select Link Bandwidth.

R82.10 Gaia Advanced Routing Administration Guide | 550


Configuring Route Redistribution in Gaia Portal

Type Required Settings

Transitive Four Octet AS a. In the AS field, enter a value 65536 -


4294967295.
b. In the Value, enter a value 0 - 65535.
c. In the Subtype, select the applicable
option:
l Route Target

l Route Origin

l OSPF Domain Identifier

l BGP Data Collection

l Generic

l Cisco VPN Distinguisher

l Source AS

Non-Transitive Four Octet a. In the AS field, enter a value 65536 -


AS 4294967295.
b. In the Value, enter a value 0 - 65535.
c. In the Subtype, select Generic.

Transitive IPv4 Address a. In the IPv4 field, enter an IPv4 address.


b. In the Value, enter a value 0 - 65535.
c. In the Subtype, select the applicable
option:
l Route Target

l Route Origin

l OSPF Domain Identifier

l OSPF Route ID

l L2VPN Identifier

l Cisco VPN Distinguisher

l VRF Route Import

4. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 551


Configuring IPv4 Route Redistribution in Gaia Clish

Configuring IPv4 Route Redistribution in Gaia


Clish
Important - In a Cluster, you must configure all the Cluster Members in the same way.

You can configure IPv4 route redistribution in Gaia Clish.


n To see the available "set" commands for IPv4 Route Redistribution, enter in Gaia Clish:

set route-redistribution[Esc][Esc]

n To see the configured IPv4 Route Redistribution, enter in Gaia Clish:

show configuration route-redistribution[Esc][Esc]

General Syntax

set route-redistribution to <Destination Protocol> <Destination


Protocol Parameters> from <Source Protocol> <Source Protocol
Parameters>

These are the destination options


n BGP
n OSPFv2
n RIP

Each destination protocol has a set of destination protocol parameters.

These are the source options


n BGP, specific AS
n BGP, specific AS path
n OSPFv2
n OSPFv2 External
n RIP
n NAT Pools

R82.10 Gaia Advanced Routing Administration Guide | 552


Configuring IPv4 Route Redistribution in Gaia Clish

You can also redistribute


n Aggregate routes
n Default routes
n Routes from specific interfaces
n Static routes

R82.10 Gaia Advanced Routing Administration Guide | 553


Configuring IPv4 Route Redistribution to BGP in Gaia Clish

Configuring IPv4 Route Redistribution to BGP in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

You can configure IPv4 route redistribution in Gaia Clish.


n To see the available "set" commands for IPv4 Route Redistribution to a BGP Peer AS,
enter in Gaia Clish:

set route-redistribution to bgp-as[Esc][Esc]

n To see the configured IPv4 Route Redistribution to a BGP Peer AS, enter in Gaia Clish:

show configuration route-redistribution[Esc][Esc]

These commands let you configure a policy for exporting routes to a BGP Peer AS.
Syntax to add redistribution to BGP Peer AS from - Interface

set route-redistribution to bgp-as <BGP Group AS>


from interface <Name of Interface>
[metric {<0-4294967295> | default}] on
off

Syntax to add redistribution to BGP Peer AS from - Static

set route-redistribution to bgp-as <BGP Group AS>


from static-route {all-ipv4-routes | all-ipv6-routes |
default | default6}
[metric {<0-4294967295> | default}] on
off

Syntax to add redistribution to BGP Peer AS from - Aggregate

set route-redistribution to bgp-as <BGP Group AS>


from aggregate {all-ipv4-routes | <IPv4 Address>/<Mask
Length>}
[metric {<0-4294967295> | default}] on
off

R82.10 Gaia Advanced Routing Administration Guide | 554


Configuring IPv4 Route Redistribution to BGP in Gaia Clish

Syntax to add redistribution to BGP Peer AS from - Kernel

set route-redistribution to bgp-as <BGP Group AS> from kernel


all-ipv4-routes
[metric {<0-4294967295> | default}] on
off
all-ipv6-routes
[metric {<0-4294967295> | default}] on
off
network <IPv4 or IPv6 Address>/<Mask Length> on
[metric {<0-4294967295> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length> and
<End Mask Length> on
match-type refines on
off

Syntax to add redistribution to BGP Peer AS from - RIP

set route-redistribution to bgp-as <BGP Group AS> from rip


all-ipv4-routes
[metric {<0-4294967295> | default}] on
off
network <IPv4 Address>/<Mask Length> on
[metric {<0-4294967295> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length> and
<End Mask Length> on
match-type refines on
off

R82.10 Gaia Advanced Routing Administration Guide | 555


Configuring IPv4 Route Redistribution to BGP in Gaia Clish

Syntax to add redistribution to BGP Peer AS from - OSPFv2

set route-redistribution to bgp-as <BGP Group AS> from ospf2


[instance <OSPF Instance>]
all-ipv4-routes
[metric {<0-4294967295> | default}] on
off
network <IPv4 Address>/<Mask Length> on
[metric {<0-4294967295> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length> and
<End Mask Length> on
match-type refines on
off

Syntax to add redistribution to BGP Peer AS from - OSPFv2 External

set route-redistribution to bgp-as <BGP Group AS> from ospf2ase


[instance <OSPF Instance>]
all-ipv4-routes
[metric {<0-4294967295> | default}] on
off
network <IPv4 Address>/<Mask Length> on
[metric {<0-4294967295> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length> and
<End Mask Length> on
match-type refines on
off

R82.10 Gaia Advanced Routing Administration Guide | 556


Configuring IPv4 Route Redistribution to BGP in Gaia Clish

Syntax to add redistribution to BGP Peer AS from - BGP Based on AS-Path

set route-redistribution to bgp-as <BGP Group AS> from bgp-as-


path <Regular Expression>
origin {any | IGP | EGP | incomplete}
all-ipv4-routes
[metric {<0-4294967295> | default}] on
off
all-ipv6-routes
[metric {<0-4294967295> | default}] on
off
network <IPv4 or IPv6 Address>/<Mask Length> on
[metric {<0-4294967295> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length>
and <End Mask Length> on
match-type refines on
off

Syntax to add redistribution to BGP Peer AS from - BGP Based on AS

set route-redistribution to bgp-as <BGP Group AS> from bgp-as-


number <AS Number 1-65535>
all-ipv4-routes
[metric {<0-4294967295> | default}] on
off
all-ipv6-routes
[metric {<0-4294967295> | default}] on
off
network <IPv4 or IPv6 Address>/<Mask Length> on
[metric {<0-4294967295> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length> and
<End Mask Length> on
match-type refines on
off

R82.10 Gaia Advanced Routing Administration Guide | 557


Configuring IPv4 Route Redistribution to BGP in Gaia Clish

Syntax to add redistribution to BGP Peer AS from - BGP Default Origin

set route-redistribution to bgp-as <BGP Group AS> from default-


origin
all-ipv4-routes
[metric {<0-4294967295> | default}] on
off

Syntax to add redistribution to BGP Peer AS from - RIPng

set route-redistribution to bgp-as <BGP Group AS> from ripng


all-ipv6-routes
[metric {<0-4294967295> | default}] on
off
network <IPv6 Address>/<Mask Length> on
[metric {<0-4294967295> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type refines on
off

Syntax to add redistribution to BGP Peer AS from - OSPFv3

set route-redistribution to bgp-as <BGP Group AS> from ospf3


[instance <OSPF Instance>]
all-ipv6-routes
[metric {<0-4294967295> | default}] on
off
network <IPv6 Address>/<Mask Length> on
[metric {<0-4294967295> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type refines on
off

R82.10 Gaia Advanced Routing Administration Guide | 558


Configuring IPv4 Route Redistribution to BGP in Gaia Clish

Syntax to add redistribution to BGP Peer AS from - OSPFv3 External

set route-redistribution to bgp-as <BGP Group AS> from ospf3ase


[instance <OSPF Instance>]
all-ipv6-routes
[metric {<0-4294967295> | default}] on
off
network <IPv6 Address>/<Mask Length> on
[metric {<0-4294967295> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type refines on
off

Syntax to add redistribution to BGP Peer AS from - NAT Pool

set route-redistribution to bgp-as <BGP Group AS> from nat-pool


{all-ipv4-routes | all-ipv6-routes | <IP Address>/<Mask
Length>}
[metric {<0-4294967295> | default}] on
off

Syntax to configure general settings

set route-redistribution to bgp-as <BGP Group AS>


community-append <Community ID 1-65535> as <AS Number 1-
65535> {off | on}
community-match <Community ID 1-65535> as <AS Number 1-
65535> {off | on}
localpref {<0-4294967295> | default}
med {<0-4294967295> | default}
off

R82.10 Gaia Advanced Routing Administration Guide | 559


Configuring IPv4 Route Redistribution to BGP in Gaia Clish

Parameters

The parameters are sorted alphabetically.

Parameter Description

[metric {<0- Enables redistribution of routes into BGP.


4294967295> |
default}] on

action {accept Configures whether to accept or reject (restrict) this route.


| restrict}

all-ipv6-routes Disables the redistribution of all IPv6 routes from this protocol.
off

all-ipv6-routes Enables the redistribution of all IPv6 routes from this protocol.
on

all-ipv4-routes Disables the redistribution of all IPv4 routes from this protocol.
off

all-ipv4-routes Enables the redistribution of all IPv4 routes from this protocol.
on

community- Appends a BGP Community to routes exported through this rule.


append
<Community ID
1-65535> as <AS
Number 1-65535>
{off | on}

community-match Applies this redistribution rule only to BGP routes, whose BGP
<Community ID Community attribute contains a specified Community.
1-65535> as <AS
Number 1-65535>
{off | on}

from aggregate Disables redistribution of this aggregate route into BGP.


{...} off

R82.10 Gaia Advanced Routing Administration Guide | 560


Configuring IPv4 Route Redistribution to BGP in Gaia Clish

Parameter Description

from aggregate Configures the IPv4 aggregate route to redistribute into BGP.
{all-ipv4-
routes | <IPv4
n all-ipv4-routes - Causes all aggregate routes to
Address>/<Mask match the rule and be redistributed into BGP.
Length>}
n <IPv4 Address>/<Mask Length> - Causes only the
specified route to match the rule and be redistributed into
BGP.
Range: Dotted-quad ([0-255].[0-255].[0-255].[0-255] / [0-
32])
Default: None

from bgp-as- Configures the redistribution of BGP routes based on the AS


number <AS Number.
Number 1-65535>

R82.10 Gaia Advanced Routing Administration Guide | 561


Configuring IPv4 Route Redistribution to BGP in Gaia Clish

Parameter Description

from bgp-as- Configures the redistribution of BGP routes based on the AS-
path <Regular Path attribute.
Expression> A valid AS_PATH regular expression contains only digits and
these special characters:
n . - The period character matches any single character.
n \ - The backslash character matches the character right
after the backslash. For pattern recall, match the pattern
indicated by the digit following the backslash. To enter the
backslash character, enter two backslash characters (\\ -
the first backslash character escapes the second
backslash character).
n ^ - The circumflex character matches the characters or null
string at the beginning of the AS path.
n $ - The dollar character matches the characters or null
string at the end of the AS path.
n ? - The question mark matches zero or one occurrence of
the pattern before "?". To enter the question mark, press
the CTRL V keys and then press the SHISFT ? keys.
n * - The asterisk character matches zero or more
occurrences of the pattern before "*".
n + - The plus character matches one or more occurrences
of the pattern before "+".
n | - The pipeline (vertical line) character matches one of the
patterns on either side of the "|" character.
n _ - The underscore character matches comma (,), left
brace ({), right brace (}), beginning of ASPath (^), end of
ASPath ($), or a whitespace (space or tabulation).
n [ ] - The square brackets match the set of characters or
range of characters separated by a hyphen (-) within the
brackets.
n ( ) - The round brackets group one or more patterns into a
single pattern.
n {m n} - Matches at least "m" and at most "n" repetitions of
the pattern before "{m,n}". Both "m" and "n" are positive
integers, and "m" is less than or equal to "n".
n {m} - Matches exactly "m" repetitions of the pattern before "
{m}". The "m" is a positive integer.
n {m,} - Matches "m" or more repetitions of the pattern before
"{m}". The "m" is a positive integer.

from default- Configures the redistribution of all IPv4 routes into BGP.
origin

R82.10 Gaia Advanced Routing Administration Guide | 562


Configuring IPv4 Route Redistribution to BGP in Gaia Clish

Parameter Description

from interface Configures the redistribution of all directly connected routes from
<Name of the specified interface to the given BGP AS.
Interface>

from interface Disables redistribution of routes from this interface into BGP.
<Name of
Interface> off

from kernel Configures the redistribution of OS kernel routes.

from ospf2 Configures the redistribution of IPv4 OSPFv2 routes (from the
[instance <OSPF specified OSPF instance).
Instance>]

from ospf2ase Configures the redistribution of IPv4 OSPFv2 External routes


[instance <OSPF (from the specified OSPF instance).
Instance>]

from rip Configures the redistribution of IPv4 RIP routes.

from ripng Configures the redistribution of IPv6 RIPng routes.

from static- Disables redistribution of this static route into BGP.


route {...} off

from static- Configures the redistribution of static routes to the given BGP
route {all- AS:
ipv4-routes |
all-ipv6-routes
n all-ipv4-routes - Matches all IPv4 static routes.
| default |
n all-ipv6-routes - Matches all IPv6 static routes.
default6} n default - Matches the default IPv4 static route.
n default6 - Matches the default IPv6 static route.

from nat-pool Configures the redistribution of NAT Pools. See "NAT Pools" on
{all-ipv4- page 726.
routes | all-
ipv6-routes |
n all-ipv4-routes - Matches all IPv4 NAT Pools.
<IP
n all-ipv6-routes - Matches all IPv6 NAT Pools
Address>/<Mask n <IP Address>/<Mask Length> - Matches only the
Length>} specified NAT Pool.

localpref {0- Configures the local BGP route preference value, when routes
4294967295 | are redistributed into BGP.
default} The greater the local preference, the more preferred is the route.

R82.10 Gaia Advanced Routing Administration Guide | 563


Configuring IPv4 Route Redistribution to BGP in Gaia Clish

Parameter Description

match-type Matches only routes with prefix and mask length exactly equal to
exact on the specified network.

match-type Matches any route contained within the specified network.


normal on

match-type Matches any route with prefix equal to the specified network,
range between whose mask length falls within a particular range.
<Start Mask
Length> and
<End Mask
Length> on

match-type Matches only routes that are contained within, but more specific
refines on than, the specified network. For example, with a greater mask
length.

med {0- Configures the cost (Multi-Exit Discriminator) of using this route.
4294967295 |
default}

metric {<0- Optional.


4294967295> | Assigns the BGP metric to be added to routes redistributed
default} through this rule.
The metric in BGP is the Multi-Exit Discriminator (MED), used to
break ties between routes with equal preference from the same
neighboring Autonomous System.
Lower MED values are preferred, and routes with no MED tie
with a MED value of 0 for most preferred.
Range: 0-4294967295, or default
Default: No metric

network <IPv4 Disables redistribution of the specified network routes into BGP.
or IPv6
Address>/<Mask
Length> off

network <IPv4 Enables redistribution of the specified network routes into BGP.
or IPv6
Address>/<Mask
Length> on

R82.10 Gaia Advanced Routing Administration Guide | 564


Configuring IPv4 Route Redistribution to BGP in Gaia Clish

Parameter Description

origin {any | Configures the route origin:


IGP | EGP |
incomplete}
n any - A route was learned from any protocol and the path
is probably complete.
n IGP - A route was learned from an interior routing protocol
and the path is probably complete.
n EGP - A route was learned from an exterior routing protocol
that does not support AS-PATH, and the path is probably
incomplete.
n incomplete - The route path information is incomplete.

set route- Configures the Autonomous System of the BGP Group.


redistribution
to bgp-as <BGP
Group AS>

set route- Disables all route redistribution to this protocol.


redistribution
to bgp-as <BGP
Group AS> off

Examples

n Redistribute all IPv4 default routes into BGP AS 100, and assign the cost of 10 to
them.

set route-redistribution to bgp-as 100 from default-origin


all-ipv4-routes metric 10 on

n Redistribute all the static routes into the BGP AS 100:

set route-redistribution to bgp-as 100 from static-route


all-ipv4-routes on

n Redistribute all IPv4 static routes into BGP AS 100, and assign the cost of 1 to them.

set route-redistribution to bgp-as 100 from static-route all


metric 1 on

n Assign the BGP local preference of 100 to routes redistributed into BGP AS 100:

set route-redistribution to bgp-as 100 localpref 100

R82.10 Gaia Advanced Routing Administration Guide | 565


Configuring IPv4 Route Redistribution to OSPFv2 in Gaia Clish

Configuring IPv4 Route Redistribution to OSPFv2 in Gaia


Clish
Important - In a Cluster, you must configure all the Cluster Members in the same way.

You can configure IPv4 route redistribution in Gaia Clish.


n To see the available "set" commands for IPv4 Route Redistribution to OSPFv2, enter in
Gaia Clish:

set route-redistribution to ospf2[Esc][Esc]

n To see the configured IPv4 Route Redistribution to OSPFv2, enter in Gaia Clish:

show configuration route-redistribution[Esc][Esc]

These commands let you configure a policy for exporting routes to OSPFv2.
Syntax to add redistribution to IPv4 OSPFv2 from - Interface

set route-redistribution to ospf2 [instance <OSPF Instance>]


from interface <Name of Interface>
[metric {<1-16777215> | default}] on
off

Syntax to add redistribution to IPv4 OSPFv2 from - Static

set route-redistribution to ospf2 [instance <OSPF Instance>]


from static-route {all-ipv4-routes | all-ipv6-routes |
default | default6}
[metric {<1-16777215> | default}] on
off

Syntax to add redistribution to IPv4 OSPFv2 from - Aggregate

set route-redistribution to ospf2 [instance <OSPF Instance>]


from aggregate {all-ipv4-routes | <IP Address>/<Mask
Length>}
[metric {<1-16777215> | default}] on
off

R82.10 Gaia Advanced Routing Administration Guide | 566


Configuring IPv4 Route Redistribution to OSPFv2 in Gaia Clish

Syntax to add redistribution to IPv4 OSPFv2 from - Kernel

set route-redistribution to ospf2 [instance <OSPF Instance>]


from kernel
all-ipv4-routes
[metric {<1-16777215> | default}] on
off
network <IP Address>/<Mask Length>
[metric {<1-16777215> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length> and
<End Mask Length> on
match-type refines on
off

Syntax to add redistribution to IPv4 OSPFv2 from - RIP

set route-redistribution to ospf2 [instance <OSPF Instance>]


from rip
all-ipv4-routes
[metric {<1-16777215> | default}] on
off
network <IP Address>/<Mask Length>
[metric {<1-16777215> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length> and
<End Mask Length> on
match-type refines on
off

R82.10 Gaia Advanced Routing Administration Guide | 567


Configuring IPv4 Route Redistribution to OSPFv2 in Gaia Clish

Syntax to add redistribution to IPv4 OSPFv2 from - OSPFv2

set route-redistribution to ospf2 [instance <OSPF Instance>]


from ospf2 [instance <OSPF Instance>]
all-ipv4-routes
[metric {<1-16777215> | default}] on
off
network <IP Address>/<Mask Length>
[metric {<1-16777215> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length> and
<End Mask Length> on
match-type refines on
off

Syntax to add redistribution to IPv4 OSPFv2 from - OSPFv2 External

set route-redistribution to ospf2 [instance <OSPF Instance>]


from ospf2ase [instance <OSPF Instance>]
all-ipv4-routes
[metric {<1-16777215> | default}] on
off
network <IP Address>/<Mask Length>
[metric {<1-16777215> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length> and
<End Mask Length> on
match-type refines on
off

R82.10 Gaia Advanced Routing Administration Guide | 568


Configuring IPv4 Route Redistribution to OSPFv2 in Gaia Clish

Syntax to add redistribution to IPv4 OSPFv2 from - BGP Based on AS-Path

set route-redistribution to ospf2 [instance <OSPF Instance>]


from bgp-as-path <Regular Expression>
origin {any | IGP | EGP | incomplete}
all-ipv4-routes
[metric {<1-16777215> | default}] on
off
network <IP Address>/<Mask Length>
[metric {<1-16777215> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length>
and <End Mask Length> on
match-type refines on
off
ospf-automatic-tag {off | on}
ospf-automatic-tag-value {<1-4095> | default}
ospf-manual-tag-value {<1-2147483647> | default}

Syntax to add redistribution to IPv4 OSPFv2 from - BGP Based on AS

set route-redistribution to ospf2 [instance <OSPF Instance>]


from bgp-as-number <AS Number>
all-ipv4-routes
[metric {<1-16777215> | default}] on
off
network <IP Address>/<Mask Length>
[metric {<1-16777215> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length> and
<End Mask Length> on
match-type refines on
off
ospf-automatic-tag {off | on}
ospf-automatic-tag-value {<1-4095> | default}
ospf-manual-tag-value {<1-2147483647> | default}

R82.10 Gaia Advanced Routing Administration Guide | 569


Configuring IPv4 Route Redistribution to OSPFv2 in Gaia Clish

Syntax to add redistribution to IPv4 OSPFv2 from - NAT Pool

set route-redistribution to ospf2 [instance <OSPF Instance>]


from nat-pool
{all-ipv4-routes | <IPv4 Address>/<Mask Length>}
[metric {<0-4294967295> | default}] on
off

Syntax to configure general settings

set route-redistribution to ospf2 [instance <OSPF Instance>] off


set route-redistribution to ospf2 off

R82.10 Gaia Advanced Routing Administration Guide | 570


Configuring IPv4 Route Redistribution to OSPFv2 in Gaia Clish

Parameters

The parameters are sorted alphabetically.

Parameter Description

[metric {<1- Enables redistribution of routes into OSPFv2.


16777215> |
default}] on

action {accept Configures whether to accept or reject (restrict) this route.


| restrict}

all-ipv4-routes Disables the redistribution of all IPv4 routes from this protocol.
off

all-ipv4-routes Enables the redistribution of all IPv4 routes from this protocol.
on

from aggregate Disables redistribution of this aggregate route into OSPFv2.


{...} off

from aggregate Configures the IPv4 aggregate route to redistribute into


{all-ipv4- OSPFv2.
routes | <IPv4
Address>/<Mask
n all-ipv4-routes - Causes all aggregate routes to
Length>} match the rule and be redistributed into OSPFv2.
n <IPv4 Address>/<Mask Length> - Causes only the
specified route to match the rule and be redistributed into
OSPFv2.
Range: Dotted-quad ([0-255].[0-255].[0-255].[0-255] / [0-
32])
Default: None

from bgp-as- Configures the redistribution of BGP routes based on the AS


number <AS Number.
Number 1-65535>

R82.10 Gaia Advanced Routing Administration Guide | 571


Configuring IPv4 Route Redistribution to OSPFv2 in Gaia Clish

Parameter Description

from bgp-as- Configures the redistribution of BGP routes based on the AS-
path <Regular Path attribute.
Expression> A valid AS_PATH regular expression contains only digits and
these special characters:
n . - The period character matches any single character.
n \ - The backslash character matches the character right
after the backslash. For pattern recall, match the pattern
indicated by the digit following the backslash. To enter the
backslash character, enter two backslash characters (\\ -
the first backslash character escapes the second
backslash character).
n ^ - The circumflex character matches the characters or null
string at the beginning of the AS path.
n $ - The dollar character matches the characters or null
string at the end of the AS path.
n ? - The question mark matches zero or one occurrence of
the pattern before "?". To enter the question mark, press
the CTRL V keys and then press the SHISFT ? keys.
n * - The asterisk character matches zero or more
occurrences of the pattern before "*".
n + - The plus character matches one or more occurrences
of the pattern before "+".
n | - The pipeline (vertical line) character matches one of the
patterns on either side of the "|" character.
n _ - The underscore character matches comma (,), left
brace ({), right brace (}), beginning of ASPath (^), end of
ASPath ($), or a whitespace (space or tabulation).
n [ ] - The square brackets match the set of characters or
range of characters separated by a hyphen (-) within the
brackets.
n ( ) - The round brackets group one or more patterns into a
single pattern.
n {m n} - Matches at least "m" and at most "n" repetitions of
the pattern before "{m,n}". Both "m" and "n" are positive
integers, and "m" is less than or equal to "n".
n {m} - Matches exactly "m" repetitions of the pattern before "
{m}". The "m" is a positive integer.
n {m,} - Matches "m" or more repetitions of the pattern before
"{m}". The "m" is a positive integer.

R82.10 Gaia Advanced Routing Administration Guide | 572


Configuring IPv4 Route Redistribution to OSPFv2 in Gaia Clish

Parameter Description

from interface Configures the redistribution of all directly connected routes from
<Name of the specified interface.
Interface>

from interface Disables redistribution of routes from this interface into OSPFv2.
<Name of
Interface> off

from kernel Configures the redistribution of OS kernel routes.

from ospf2 Configures the redistribution of IPv4 OSPFv2 routes (from the
[instance <OSPF specified OSPF instance).
Instance>]

from ospf2ase Configures the redistribution of IPv4 OSPFv2 External routes


[instance <OSPF (from the specified OSPF instance).
Instance>]

from rip Configures the redistribution of IPv4 RIP routes.

from static- Disables redistribution of this static route into OSPFv2.


route {...} off

from static- Configures the redistribution of static routes into OSPFv2:


route {all-
ipv4-routes |
n all-ipv4-routes - Matches all IPv4 static routes.
all-ipv6-routes
n all-ipv6-routes - Matches all IPv6 static routes.
| default | n default - Matches the default IPv4 static route.
default6} n default6 - Matches the default IPv6 static route.

from nat-pool Configures the redistribution of NAT Pools. See "NAT Pools" on
{all-ipv4- page 726.
routes | <IPv4
Address>/<Mask
n all-ipv4-routes - Matches all IPv4 NAT Pools.
Length>}
n <IPv4 Address>/<Mask Length> - Matches only the
specified IPv4 NAT Pool.

match-type Matches only routes with prefix and mask length exactly equal to
exact on the specified network.

match-type Matches any route contained within the specified network.


normal on

R82.10 Gaia Advanced Routing Administration Guide | 573


Configuring IPv4 Route Redistribution to OSPFv2 in Gaia Clish

Parameter Description

match-type Matches any route with prefix equal to the specified network,
range between whose mask length falls within a particular range.
<Start Mask
Length> and
<End Mask
Length> on

match-type Matches only routes that are contained within, but more specific
refines on than, the specified network. For example, with a greater mask
length.

metric {<1- Optional.


16777215> | Assigns the OSPFv2 metric to be added to routes redistributed
default} through this rule.
The metric used by OSPF is a cost, representing the overhead
required (due to bandwidth) to reach a destination.
Routes with higher OSPF cost are more expensive.
Range: 1-16777215, or default
Default: No metric

network <IPv4 Disables redistribution of the specified network routes into


or IPv6 OSPFv2.
Address>/<Mask
Length> off

network <IPv4 Enables redistribution of the specified network routes into


or IPv6 OSPFv2.
Address>/<Mask
Length> on

origin {any | Configures the route origin:


IGP | EGP |
incomplete}
n any - A route was learned from any protocol and the path
is probably complete.
n IGP - A route was learned from an interior routing protocol
and the path is probably complete.
n EGP - A route was learned from an exterior routing protocol
that does not support AS-PATH, and the path is probably
incomplete.
n incomplete - The route path information is incomplete.

R82.10 Gaia Advanced Routing Administration Guide | 574


Configuring IPv4 Route Redistribution to OSPFv2 in Gaia Clish

Parameter Description

ospf-automatic- Modifies the OSPF route tag that was automatically generated
tag-value {<1- based on the BGP AS.
4095> | If this value is configured, then the tag is attached to external
default} OSPF routes upon export.
Range: 1-4095, or default
Default: No route tag

ospf-automatic- Disables (off) or enables (on) the use of an automatically


tag {off | on} generated OSPF route tag, based on the BGP AS.
If this feature is enabled, then the tag is attached to external
OSPF routes upon export.
Range: off, or on
Default: off

ospf-manual- Configures the value to place in the external OSPF route tag
tag-value {<1- field.
2147483647> | Important - This configuration overrides any automatic tag
default} configuration.
Range: 1-2147483647, or default
Default: No route ta

set route- Disables all route redistribution to this protocol (for the specified
redistribution OSPF instance).
to ospf2
[instance <OSPF
Instance>] off

R82.10 Gaia Advanced Routing Administration Guide | 575


Configuring IPv4 Route Redistribution to OSPFv2 in Gaia Clish

Examples

n Redistribute all IPv4 routes from the interface eth2 into OSPFv2:

set route-redistribution to ospf2 from interface eth2 on

n Redistribute all routes from the interface eth0 into OSPFv2, and assign the metric of
50 to them:

set route-redistribution to ospf2 from interface eth0 metric


50 on

n Redistribute all IPv4 routes for the IP addresses in the Autonomous System 100 into
OSPF (valid for OSPFv2 only), and assign the cost of 99 to them:

set route-redistribution to ospf2 from bgp-as-number 100


all-ipv4-routes metric 99 on

n Redistribute all IPv4 routes for the IP addresses in the Autonomous System 100 into
OSPF (valid for OSPFv2 only), except for routes for the network [Link]/16:

set route-redistribution to ospf2 from bgp-as-number 100


network [Link]/16 action restrict
set route-redistribution to ospf2 from bgp-as-number 100
all-ipv4-routes on

R82.10 Gaia Advanced Routing Administration Guide | 576


Configuring IPv4 Route Redistribution to RIP in Gaia Clish

Configuring IPv4 Route Redistribution to RIP in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

You can configure IPv4 route redistribution in Gaia Clish.


n To see the available "set" commands for IPv4 Route Redistribution to RIP, enter in Gaia
Clish:

set route-redistribution to rip[Esc][Esc]

n To see the configured IPv4 Route Redistribution to RIP, enter in Gaia Clish:

show configuration route-redistribution[Esc][Esc]

These commands let you configure a policy for exporting routes to RIP.
Syntax to add redistribution to IPv4 RIP from - Interface

set route-redistribution to rip


from interface <Name of Interface>
metric <1-16> on
off

Syntax to add redistribution to IPv4 RIP from - Static

set route-redistribution to rip


from static-route {all-ipv4-routes | default}
metric <1-16> on
off

Syntax to add redistribution to IPv4 RIP from - Aggregate

set route-redistribution to rip


from aggregate {all-ipv4-routes | <IPv4 Address>/<Mask
Length>}
metric <1-16> on
off

R82.10 Gaia Advanced Routing Administration Guide | 577


Configuring IPv4 Route Redistribution to RIP in Gaia Clish

Syntax to add redistribution to IPv4 RIP from - Kernel

set route-redistribution to rip from kernel


all-ipv4-routes
metric <1-16> on
off
network <IPv4 Address>/<Mask Length>
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length> and
<End Mask Length> on
match-type refines on
metric <1-16> on
off

Syntax to add redistribution to IPv4 RIP from - OSPFv2

set route-redistribution to rip from ospf2 [instance <OSPF


Instance>]
all-ipv4-routes
metric <1-16> on
off
network <IPv4 Address>/<Mask Length>
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length> and
<End Mask Length> on
match-type refines on
metric <1-16> on
off
riptag {<1-65535> | default}

R82.10 Gaia Advanced Routing Administration Guide | 578


Configuring IPv4 Route Redistribution to RIP in Gaia Clish

Syntax to add redistribution to IPv4 RIP from - OSPFv2 External

set route-redistribution to rip from ospf2ase [instance <OSPF


Instance>]
all-ipv4-routes
metric <1-16> on
off
network <IPv4 Address>/<Mask Length>
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length> and
<End Mask Length> on
match-type refines on
metric <1-16> on
off
riptag {<1-65535> | default}

Syntax to add redistribution to IPv4 RIP from - BGP Based on AS-Path

set route-redistribution to rip from bgp-as-path <Regular


Expression>
origin {any | IGP | EGP | incomplete}
all-ipv4-routes
metric <1-16> on
off
network <IPv4 Address>/<Mask Length>
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length>
and <End Mask Length> on
match-type refines on
metric <1-16> on
off
riptag {<1-65535> | default}

R82.10 Gaia Advanced Routing Administration Guide | 579


Configuring IPv4 Route Redistribution to RIP in Gaia Clish

Syntax to add redistribution to IPv4 RIP from - BGP Based on AS

set route-redistribution to rip from bgp-as-number <AS Number 1-


65535>
all-ipv4-routes
metric <1-16> on
off
network <IPv4 Address>/<Mask Length>
action {accept | restrict}
match-type exact on
match-type normal on
match-type range between <Start Mask Length> and
<End Mask Length> on
match-type refines on
metric <1-16> on
off
riptag {<1-65535> | default}

Syntax to add redistribution to IPv4 RIP from - NAT Pool

set route-redistribution to rip from nat-pool


{all-ipv4-routes | <IPv4 Address>/<Mask Length>}
[metric {<1-16> | default}] on
off

Syntax to configure general settings

set route-redistribution to rip off

R82.10 Gaia Advanced Routing Administration Guide | 580


Configuring IPv4 Route Redistribution to RIP in Gaia Clish

Parameters

The parameters are sorted alphabetically.

Parameter Description

action {accept Configures whether to accept or reject (restrict) this route.


| restrict}

all-ipv4-routes Enables the redistribution of all IPv4 routes from this protocol.
metric <1-16>
on

all-ipv4-routes Disables the redistribution of all IPv4 routes from this protocol.
off

from aggregate Disables redistribution of this aggregate route into RIP.


{...} off

from aggregate Configures the IPv4 aggregate route to redistribute into RIP.
{all-ipv4-
routes | <IPv4
n all-ipv4-routes - Causes all aggregate routes to
Address>/<Mask match the rule and be redistributed into RIP.
Length>}
n <IPv4 Address>/<Mask Length> - Causes only the
specified route to match the rule and be redistributed into
RIP.
Range: Dotted-quad ([0-255].[0-255].[0-255].[0-255] / [0-
32])
Default: None

from bgp-as- Configures the redistribution of BGP routes based on the AS


number <AS Number.
Number 1-65535>

R82.10 Gaia Advanced Routing Administration Guide | 581


Configuring IPv4 Route Redistribution to RIP in Gaia Clish

Parameter Description

from bgp-as- Configures the redistribution of BGP routes based on the AS-
path <Regular Path attribute.
Expression> A valid AS_PATH regular expression contains only digits and
these special characters:
n . - The period character matches any single character.
n \ - The backslash character matches the character right
after the backslash. For pattern recall, match the pattern
indicated by the digit following the backslash. To enter the
backslash character, enter two backslash characters (\\ -
the first backslash character escapes the second
backslash character).
n ^ - The circumflex character matches the characters or null
string at the beginning of the AS path.
n $ - The dollar character matches the characters or null
string at the end of the AS path.
n ? - The question mark matches zero or one occurrence of
the pattern before "?". To enter the question mark, press
the CTRL V keys and then press the SHISFT ? keys.
n * - The asterisk character matches zero or more
occurrences of the pattern before "*".
n + - The plus character matches one or more occurrences
of the pattern before "+".
n | - The pipeline (vertical line) character matches one of the
patterns on either side of the "|" character.
n _ - The underscore character matches comma (,), left
brace ({), right brace (}), beginning of ASPath (^), end of
ASPath ($), or a whitespace (space or tabulation).
n [ ] - The square brackets match the set of characters or
range of characters separated by a hyphen (-) within the
brackets.
n ( ) - The round brackets group one or more patterns into a
single pattern.
n {m n} - Matches at least "m" and at most "n" repetitions of
the pattern before "{m,n}". Both "m" and "n" are positive
integers, and "m" is less than or equal to "n".
n {m} - Matches exactly "m" repetitions of the pattern before "
{m}". The "m" is a positive integer.
n {m,} - Matches "m" or more repetitions of the pattern before
"{m}". The "m" is a positive integer.

R82.10 Gaia Advanced Routing Administration Guide | 582


Configuring IPv4 Route Redistribution to RIP in Gaia Clish

Parameter Description

from interface Configures the redistribution of all directly connected routes from
<Name of the specified interface.
Interface>

from interface Disables redistribution of routes from this interface into RIP.
<Name of
Interface> off

from kernel Configures the redistribution of OS kernel routes.

from ospf2 Configures the redistribution of IPv4 OSPFv2 routes (from the
[instance <OSPF specified OSPF instance).
Instance>]

from ospf2ase Configures the redistribution of IPv4 OSPFv2 External routes


[instance <OSPF (from the specified OSPF instance).
Instance>]

from static- Disables redistribution of this static route into RIP.


route {...} off

from static- Configures the redistribution of static routes into RIP:


route {all-
ipv4-routes |
n all-ipv4-routes - Matches all IPv4 static routes.
default}
n default - Matches the default IPv4 static route.

from nat-pool Configures the redistribution of NAT Pools. See "NAT Pools" on
{all-ipv4- page 726.
routes | <IPv4
Address>/<Mask
n all-ipv4-routes - Matches all IPv4 NAT Pools.
Length>}
n <IPv4 Address>/<Mask Length> - Matches only the
specified IPv4 NAT Pool.

match-type Matches only routes with prefix and mask length exactly equal to
exact on the specified network.

match-type Matches any route contained within the specified network.


normal on

match-type Matches any route with prefix equal to the specified network,
range between whose mask length falls within a particular range.
<Start Mask
Length> and
<End Mask
Length> on

R82.10 Gaia Advanced Routing Administration Guide | 583


Configuring IPv4 Route Redistribution to RIP in Gaia Clish

Parameter Description

match-type Matches only routes that are contained within, but more specific
refines on than, the specified network. For example, with a greater mask
length.

metric <1-16> Configures the RIP metric to be added to routes redistributed


through this rule.
The metric used by RIP/RIPng is a hop count, representing the
distance to a destination.
Routes with higher hop counts are more expensive.
Routes with a metric greater than or equal to 16 are treated as
unreachable, and are not installed or propagated to peers.
Note - When redistributing routes to RIP or RIPng, a metric
must be configured.
Range: 1-16
Default: None

metric <1-16> Enables redistribution of routes into RIP.


on

network <IPv4 Enables redistribution of the specified network routes into RIP.
or IPv6
Address>/<Mask
Length> metric
<1-16> on

network <IPv4 Disables redistribution of the specified network routes into RIP.
or IPv6
Address>/<Mask
Length> off

origin {any | Configures the route origin:


IGP | EGP |
incomplete}
n any - A route was learned from any protocol and the path
is probably complete.
n IGP - A route was learned from an interior routing protocol
and the path is probably complete.
n EGP - A route was learned from an exterior routing protocol
that does not support AS-PATH, and the path is probably
incomplete.
n incomplete - The route path information is incomplete.

R82.10 Gaia Advanced Routing Administration Guide | 584


Configuring IPv4 Route Redistribution to RIP in Gaia Clish

Parameter Description

riptag {<1- Configures a route tag field on routes redistributed to RIP


65535> | through this rule
default} Range: 1-65535, or default
Default: No route tag

set route- Disables all route redistribution to this protocol.


redistribution
to rip off

R82.10 Gaia Advanced Routing Administration Guide | 585


Configuring IPv4 Route Redistribution to RIP in Gaia Clish

Examples

n Redistribute all RIP routes for the network [Link]/16 that fall in the range
between [Link]/18 and [Link]/24 into OSPF (valid for OSPFv2 only):

set route-redistribution to ospf2 from rip network


[Link]/16 match-type range between 18 and 24 on

n Redistribute all OSPF external routes into RIP, and assign the cost of 2 to them:

set route-redistribution to rip from ospf2ase all metric 2


on

n Redistribute all OSPF external routes into RIP, and assign the RIP tag value of 20 to
them:

set route-redistribution to rip from ospf2ase riptag 20

n Redistribute aggregate routes for the network [Link]/16 into RIP, and assign the cost
of 2 to them:

set route-redistribution to rip from aggregate [Link]/16


metric 2 on

n Redistribute all routes for the network [Link]/16 from OSPF into RIP, and assign
the cost of 2 to them:

set route-redistribution to rip from ospf2 network


[Link]/16 metric 2 on

n Redistribute all external OSPFv2 routes for the network [Link]/16 into RIP, and
assign the metric of 3 to them:

set route-redistribution to rip from ospf2ase network


[Link]/16 metric 3 on

n Redistribute all IPv4 routes that are learned from BGP AS 100 into RIP, and assign
the RIP tag value of 99 to them:

set route-redistribution to rip from bgp-aspath ^100_ origin


any riptag 99

n Redistribute routes for network [Link]/16 that are originated in BGP AS 100 and
learned through any interior routing protocol, into RIP, and assign the cost of 10 to
them:

R82.10 Gaia Advanced Routing Administration Guide | 586


Configuring IPv4 Route Redistribution to RIP in Gaia Clish

set route-redistribution to rip from bgp-aspath _100$ origin


IGP network [Link]/16 metric 10 on

R82.10 Gaia Advanced Routing Administration Guide | 587


Configuring IPv6 Route Redistribution in Gaia Clish

Configuring IPv6 Route Redistribution in Gaia


Clish
Important - In a Cluster, you must configure all the Cluster Members in the same way.

You can configure IPv6 route redistribution in Gaia Clish.


n To see the available "set" commands for IPv6 Route Redistribution, enter in Gaia Clish:

set ipv6 route-redistribution[Esc][Esc]

n To see the configured IPv6 Route Redistribution, enter in Gaia Clish:

show configuration ipv6 route-redistribution[Esc][Esc]

General Syntax

set ipv6 route-redistribution to <Destination Protocol>


<Destination Protocol Parameters> from <Source Protocol> <Source
Protocol Parameters>

These are the destination options


n OSPFv3
n RIPng
Each destination protocol has a set of destination protocol parameters.

These are the source options


n BGP
n OSPFv3
n OSPFv3 External
n RIPng
n NAT Pools

You can also redistribute


n Routes from specific interfaces
n Static routes

R82.10 Gaia Advanced Routing Administration Guide | 588


Configuring IPv6 Route Redistribution to OSPFv3 in Gaia Clish

Configuring IPv6 Route Redistribution to OSPFv3 in Gaia


Clish
Important - In a Cluster, you must configure all the Cluster Members in the same way.

You can configure IPv6 route redistribution in Gaia Clish.


n To see the available "set" commands for IPv6 Route Redistribution to OSPFv3, enter in
Gaia Clish:

set ipv6 route-redistribution to ospf3[Esc][Esc]

n To see the configured IPv6 Route Redistribution to OSPFv3, enter in Gaia Clish:

show configuration ipv6 route-redistribution[Esc][Esc]

These commands let you configure a policy for exporting routes to OSPFv3.
Syntax to add redistribution to IPv6 OSPFv3 from - Interface

set ipv6 route-redistribution to ospf3 [instance <OSPF


Instance>]
from interface <Name of Interface>
[metric {<1-16777215> | default}] on
off

Syntax to add redistribution to IPv6 OSPFv3 from - Static

set ipv6 route-redistribution to ospf3 [instance <OSPF


Instance>]
from static-route {all-ipv6-routes | default6}
[metric {<1-16777215> | default}] on
off

R82.10 Gaia Advanced Routing Administration Guide | 589


Configuring IPv6 Route Redistribution to OSPFv3 in Gaia Clish

Syntax to add redistribution to IPv6 OSPFv3 from - Kernel

set ipv6 route-redistribution to ospf3 [instance <OSPF


Instance>] from kernel
all-ipv6-routes
[metric {<1-16777215> | default}] on
off
network <IPv6 Address>/<Mask Length>
[metric {<1-16777215> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type refines on
off

Syntax to add redistribution to IPv6 OSPFv3 from - RIPng

set ipv6 route-redistribution to ospf3 [instance <OSPF


Instance>] from ripng
all-ipv6-routes
[metric {<1-16777215> | default}] on
off
network <IPv6 Address>/<Mask Length>
[metric {<1-16777215> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type refines on
off

Syntax to add redistribution to IPv6 OSPFv3 from - OSPFv3

set ipv6 route-redistribution to ospf3 [instance <OSPF


Instance>]
from ospf3 [instance <OSPF Instance>]
all-ipv6-routes
[metric {<1-16777215> | default}] on
off
network <IPv6 Address>/<Mask Length>
[metric {<1-16777215> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type refines on
off

R82.10 Gaia Advanced Routing Administration Guide | 590


Configuring IPv6 Route Redistribution to OSPFv3 in Gaia Clish

Syntax to add redistribution to IPv6 OSPFv3 from - OSPFv3 External

set ipv6 route-redistribution to ospf3 [instance <OSPF


Instance>]
from ospf3ase [instance <OSPF Instance>]
all-ipv6-routes
[metric {<1-16777215> | default}] on
off
network <IPv6 Address>/<Mask Length>
[metric {<1-16777215> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type refines on
off

Syntax to add redistribution to IPv6 OSPFv3 from - BGP Based on AS-Path

set ipv6 route-redistribution to ospf3 [instance <OSPF


Instance>] from bgp-as-path <Regular Expression>
origin {any | IGP | EGP | incomplete}
all-ipv6-routes
[metric {<1-16777215> | default}] on
off
network <IPv6 Address>/<Mask Length>
[metric {<1-16777215> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type refines on
off

R82.10 Gaia Advanced Routing Administration Guide | 591


Configuring IPv6 Route Redistribution to OSPFv3 in Gaia Clish

Syntax to add redistribution to IPv6 OSPFv3 from - BGP Based on AS

set ipv6 route-redistribution to ospf3 [instance <OSPF


Instance>] from bgp-as-number <AS Number 1-65535>
all-ipv6-routes
[metric {<1-16777215> | default}] on
off
network <IPv6 Address>/<Mask Length>
[metric {<1-16777215> | default}] on
action {accept | restrict}
match-type exact on
match-type normal on
match-type refines on
off
off

Syntax to add redistribution to IPv6 OSPFv3 from - NAT Pool

set ipv6 route-redistribution to ospf3 [instance <OSPF


Instance>]
from nat-pool {all-ipv6-routes | <IPv6 Address>/<Mask
Length>}
metric <1-16> on
off

Syntax to configure general settings

set ipv6 route-redistribution to ospf3 off

R82.10 Gaia Advanced Routing Administration Guide | 592


Configuring IPv6 Route Redistribution to OSPFv3 in Gaia Clish

Parameters

The parameters are sorted alphabetically.

Parameter Description

[metric {<1- Enables redistribution of routes into OSPFv3.


16777215> |
default}] on

action {accept Configures whether to accept or reject (restrict) this route.


| restrict}

all-ipv6-routes Disables the redistribution of all IPv6 routes from this protocol.
off

all-ipv6-routes Enables the redistribution of all IPv6 routes from this protocol.
on

from bgp-as- Configures the redistribution of BGP routes based on the AS


number <AS Number.
Number 1-65535>

R82.10 Gaia Advanced Routing Administration Guide | 593


Configuring IPv6 Route Redistribution to OSPFv3 in Gaia Clish

Parameter Description

from bgp-as- Configures the redistribution of BGP routes based on the AS-
path <Regular Path attribute.
Expression> A valid AS_PATH regular expression contains only digits and
these special characters:
n . - The period character matches any single character.
n \ - The backslash character matches the character right
after the backslash. For pattern recall, match the pattern
indicated by the digit following the backslash. To enter the
backslash character, enter two backslash characters (\\ -
the first backslash character escapes the second
backslash character).
n ^ - The circumflex character matches the characters or null
string at the beginning of the AS path.
n $ - The dollar character matches the characters or null
string at the end of the AS path.
n ? - The question mark matches zero or one occurrence of
the pattern before "?". To enter the question mark, press
the CTRL V keys and then press the SHISFT ? keys.
n * - The asterisk character matches zero or more
occurrences of the pattern before "*".
n + - The plus character matches one or more occurrences
of the pattern before "+".
n | - The pipeline (vertical line) character matches one of the
patterns on either side of the "|" character.
n _ - The underscore character matches comma (,), left
brace ({), right brace (}), beginning of ASPath (^), end of
ASPath ($), or a whitespace (space or tabulation).
n [ ] - The square brackets match the set of characters or
range of characters separated by a hyphen (-) within the
brackets.
n ( ) - The round brackets group one or more patterns into a
single pattern.
n {m n} - Matches at least "m" and at most "n" repetitions of
the pattern before "{m,n}". Both "m" and "n" are positive
integers, and "m" is less than or equal to "n".
n {m} - Matches exactly "m" repetitions of the pattern before "
{m}". The "m" is a positive integer.
n {m,} - Matches "m" or more repetitions of the pattern before
"{m}". The "m" is a positive integer.

R82.10 Gaia Advanced Routing Administration Guide | 594


Configuring IPv6 Route Redistribution to OSPFv3 in Gaia Clish

Parameter Description

from interface Configures the redistribution of all directly connected routes from
<Name of the specified interface.
Interface>

from interface Disables redistribution of routes from this interface into OSPFv3.
<Name of
Interface> off

from kernel Configures the redistribution of OS kernel routes.

from ospf3 Configures the redistribution of IPv6 OSPFv3 routes (from the
[instance <OSPF specified OSPF instance).
Instance>]

from ospf3ase Configures the redistribution of IPv6 OSPFv3 External routes


[instance <OSPF (from the specified OSPF instance).
Instance>]

from ripng Configures the redistribution of IPv6 RIPng routes.

from static- Disables redistribution of this static route into OSPFv3.


route {...} off

from static- Configures the redistribution of static routes into OSPFv3:


route {all-
ipv6-routes |
n all-ipv6-routes - Matches all IPv6 static routes.
default6}
n default6 - Matches the default IPv6 static route.

from nat-pool Configures the redistribution of NAT Pools. See "NAT Pools" on
{all-ipv6- page 726.
routes | <IPv6
Address>/<Mask
n all-ipv6-routes - Matches all IPv4 NAT Pools.
Length>}
n <IPv6 Address>/<Mask Length> - Matches only the
specified IPv6 NAT Pool.

match-type Matches only routes with prefix and mask length exactly equal to
exact on the specified network.

match-type Matches any route contained within the specified network.


normal on

match-type Matches only routes that are contained within, but more specific
refines on than, the specified network. For example, with a greater mask
length.

R82.10 Gaia Advanced Routing Administration Guide | 595


Configuring IPv6 Route Redistribution to OSPFv3 in Gaia Clish

Parameter Description

metric {<1- Optional.


16777215> | Assigns the OSPFv3 metric to be added to routes redistributed
default} through this rule.
The metric used by OSPF is a cost, representing the overhead
required (due to bandwidth) to reach a destination.
Routes with higher OSPF cost are more expensive.
Range: 1-16777215, or default
Default: No metric

network <IPv6 Disables redistribution of the specified network routes into


Address>/<Mask OSPFv3.
Length> off

network <IPv6 Enables redistribution of the specified network routes into


Address>/<Mask OSPFv3.
Length> on

origin {any | Configures the route origin:


IGP | EGP |
incomplete}
n any - A route was learned from any protocol and the path
is probably complete.
n IGP - A route was learned from an interior routing protocol
and the path is probably complete.
n EGP - A route was learned from an exterior routing protocol
that does not support AS-PATH, and the path is probably
incomplete.
n incomplete - The route path information is incomplete.

set ipv6 route- Disables all route redistribution to this protocol (for the specified
redistribution OSPF instance).
to ospf3 off

R82.10 Gaia Advanced Routing Administration Guide | 596


Configuring IPv6 Route Redistribution to OSPFv3 in Gaia Clish

Examples

n Redistribute the default IPv6 static route into OSPFv3, and assign the cost of 15000 to
it:

set route-redistribution to ospf3 from static-route default


metric 15000 on

n Redistribute all IPv6 routes from the interface eth0 into OSPFv3 and assign the cost of
10 to them:

set ipv6 route-redistribution to ospf3 from interface eth0


metric 10 on

n Redistribute all RIPng routes for the network fd14:8502:5b14:456a::/64, including the
routes for the addresses within the network into OSPFv3:

set ipv6 route-redistribution to ospf3 from rip network


fd14:8502:5b14:456a::/64 match-type normal on

R82.10 Gaia Advanced Routing Administration Guide | 597


Configuring IPv6 Route Redistribution to RIPng in Gaia Clish

Configuring IPv6 Route Redistribution to RIPng in Gaia


Clish
Important - In a Cluster, you must configure all the Cluster Members in the same way.

You can configure IPv6 route redistribution in Gaia Clish.


n To see the available "set" commands for IPv6 Route Redistribution to RIPng, enter in
Gaia Clish:

set ipv6 route-redistribution to ripng[Esc][Esc]

n To see the configured IPv6 Route Redistribution to RIPng, enter in Gaia Clish:

show configuration ipv6 route-redistribution[Esc][Esc]

These commands let you configure a policy for exporting routes to RIPng.
Syntax to add redistribution to IPv6 RIPng from - Interface

set ipv6 route-redistribution to ripng


from interface <Name of Interface>
metric <1-16> on
off

Syntax to add redistribution to IPv6 RIPng from - Static

set ipv6 route-redistribution to ripng


from static-route {all-ipv6-routes | default6}
metric <1-16> on
off

Syntax to add redistribution to IPv6 RIPng from - Kernel

set ipv6 route-redistribution to ripng from kernel


all-ipv6-routes
metric <1-16> on
off
network <IPv6 Address>/<Mask Length>
action {accept | restrict}
match-type exact on
match-type normal on
match-type refines on
metric <1-16> on
off

R82.10 Gaia Advanced Routing Administration Guide | 598


Configuring IPv6 Route Redistribution to RIPng in Gaia Clish

Syntax to add redistribution to IPv6 RIPng from - OSPFv3

set ipv6 route-redistribution to ripng from ospf3 [instance


<OSPF Instance>]
all-ipv6-routes
metric <1-16> on
off
network <IPv6 Address>/<Mask Length>
action {accept | restrict}
match-type exact on
match-type normal on
match-type refines on
metric <1-16> on
off

Syntax to add redistribution to IPv6 RIPng from - OSPFv3 External

set ipv6 route-redistribution to ripng from ospf3ase [instance


<OSPF Instance>]
all-ipv6-routes
metric <1-16> on
off
network <IPv6 Address>/<Mask Length>
action {accept | restrict}
match-type exact on
match-type normal on
match-type refines on
metric <1-16> on
off

Syntax to add redistribution to IPv6 RIPng from - BGP Based on AS-Path

set ipv6 route-redistribution to ripng from bgp-as-path <Regular


Expression>
origin {any | IGP | EGP | incomplete}
all-ipv6-routes
metric <1-16> on
off
network <IPv6 Address>/<Mask Length>
action {accept | restrict}
match-type exact on
match-type normal on
match-type refines on
metric <1-16> on
off

R82.10 Gaia Advanced Routing Administration Guide | 599


Configuring IPv6 Route Redistribution to RIPng in Gaia Clish

Syntax to add redistribution to IPv6 RIPng from - BGP Based on AS

set ipv6 route-redistribution to ripng from bgp-as-number <AS


Number 1-65535>
all-ipv6-routes
metric <1-16> on
off
network <IPv6 Address>/<Mask Length>
action {accept | restrict}
match-type exact on
match-type normal on
match-type refines on
metric <1-16> on
off

Syntax to add redistribution to IPv6 RIPng from - NAT Pool

set ipv6 route-redistribution to ripng


from nat-pool {all-ipv6-routes | <IPv6 Address>/<Mask
Length>}
metric <1-16> on
off

Syntax to configure general settings

set ipv6 route-redistribution to ripng off

R82.10 Gaia Advanced Routing Administration Guide | 600


Configuring IPv6 Route Redistribution to RIPng in Gaia Clish

Parameters

The parameters are sorted alphabetically.

Parameter Description

action {accept Configures whether to accept or reject (restrict) this route.


| restrict}

all-ipv6-routes Enables the redistribution of all IPv6 routes from this protocol.
metric <1-16>
on

all-ipv6-routes Disables the redistribution of all IPv6 routes from this protocol.
off

from bgp-as- Configures the redistribution of BGP routes based on the AS


number <AS Number.
Number 1-65535>

R82.10 Gaia Advanced Routing Administration Guide | 601


Configuring IPv6 Route Redistribution to RIPng in Gaia Clish

Parameter Description

from bgp-as- Configures the redistribution of BGP routes based on the AS-
path <Regular Path attribute.
Expression> A valid AS_PATH regular expression contains only digits and
these special characters:
n . - The period character matches any single character.
n \ - The backslash character matches the character right
after the backslash. For pattern recall, match the pattern
indicated by the digit following the backslash. To enter the
backslash character, enter two backslash characters (\\ -
the first backslash character escapes the second
backslash character).
n ^ - The circumflex character matches the characters or null
string at the beginning of the AS path.
n $ - The dollar character matches the characters or null
string at the end of the AS path.
n ? - The question mark matches zero or one occurrence of
the pattern before "?". To enter the question mark, press
the CTRL V keys and then press the SHISFT ? keys.
n * - The asterisk character matches zero or more
occurrences of the pattern before "*".
n + - The plus character matches one or more occurrences
of the pattern before "+".
n | - The pipeline (vertical line) character matches one of the
patterns on either side of the "|" character.
n _ - The underscore character matches comma (,), left
brace ({), right brace (}), beginning of ASPath (^), end of
ASPath ($), or a whitespace (space or tabulation).
n [ ] - The square brackets match the set of characters or
range of characters separated by a hyphen (-) within the
brackets.
n ( ) - The round brackets group one or more patterns into a
single pattern.
n {m n} - Matches at least "m" and at most "n" repetitions of
the pattern before "{m,n}". Both "m" and "n" are positive
integers, and "m" is less than or equal to "n".
n {m} - Matches exactly "m" repetitions of the pattern before "
{m}". The "m" is a positive integer.
n {m,} - Matches "m" or more repetitions of the pattern before
"{m}". The "m" is a positive integer.

R82.10 Gaia Advanced Routing Administration Guide | 602


Configuring IPv6 Route Redistribution to RIPng in Gaia Clish

Parameter Description

from interface Configures the redistribution of all directly connected routes from
<Name of the specified interface.
Interface>

from interface Disables redistribution of routes from this interface into RIPng.
<Name of
Interface> off

from kernel Configures the redistribution of OS kernel routes.

from ospf3 Configures the redistribution of IPv6 OSPFv3 routes (from the
[instance <OSPF specified OSPF instance).
Instance>]

from ospf3ase Configures the redistribution of IPv6 OSPFv3 External routes


[instance <OSPF (from the specified OSPF instance).
Instance>]

from static- Disables redistribution of this static route into RIPng.


route {...} off

from static- Configures the redistribution of static routes into RIPng:


route {all-
ipv6-routes |
n all-ipv6-routes - Matches all IPv6 static routes.
default6}
n default6 - Matches the default IPv6 static route.

from nat-pool Configures the redistribution of NAT Pools. See "NAT Pools" on
{all-ipv6- page 726.
routes | <IPv6
Address>/<Mask
n all-ipv6-routes - Matches all IPv4 NAT Pools.
Length>}
n <IPv6 Address>/<Mask Length> - Matches only the
specified IPv6 NAT Pool.

match-type Matches only routes with prefix and mask length exactly equal to
exact on the specified network.

match-type Matches any route contained within the specified network.


normal on

match-type Matches only routes that are contained within, but more specific
refines on than, the specified network. For example, with a greater mask
length.

R82.10 Gaia Advanced Routing Administration Guide | 603


Configuring IPv6 Route Redistribution to RIPng in Gaia Clish

Parameter Description

metric <1-16> Configures the RIPng metric to be added to routes redistributed


through this rule.
The metric used by RIP/RIPng is a hop count, representing the
distance to a destination.
Routes with higher hop counts are more expensive.
Routes with a metric greater than or equal to 16 are treated as
unreachable, and are not installed or propagated to peers.
Note - When redistributing routes to RIP or RIPng, a metric
must be configured.
Range: 1-16
Default: None

metric <1-16> Enables redistribution of routes into RIPng.


on

network <IPv6 Enables redistribution of the specified network routes into


Address>/<Mask RIPng.
Length> metric
<1-16> on

network <IPv6 Disables redistribution of the specified network routes into


Address>/<Mask RIPng.
Length> off

origin {any | Configures the route origin:


IGP | EGP |
incomplete}
n any - A route was learned from any protocol and the path
is probably complete.
n IGP - A route was learned from an interior routing protocol
and the path is probably complete.
n EGP - A route was learned from an exterior routing protocol
that does not support AS-PATH, and the path is probably
incomplete.
n incomplete - The route path information is incomplete.

set ipv6 route- Disables all route redistribution to this protocol.


redistribution
to ripng off

R82.10 Gaia Advanced Routing Administration Guide | 604


Configuring IPv6 Route Redistribution to RIPng in Gaia Clish

Examples

n Redistribute all OSPFv3 External routes into RIPng, and assign the cost of 22 to them:

set ipv6 route-redistribution to ripng from ospf3ase all


metric 22 on

n Redistribute all routes for the network fd14:8502:5b14:456a::/64 from OSPFv3 into
RIPng, and assign the cost of 999 to them:

set ipv6 route-redistribution to ripng from ospf3 network


fd14:8502:5b14:456a::/64 metric 999 on

n Do not redistribute routes for the network fd14:8502:5b14:456a::/64 from OSPFv3


External into RIPng:

set ipv6 route-redistribution to ripng from ospf3ase network


fd14:8502:5b14:456a::/64 action restrict

R82.10 Gaia Advanced Routing Administration Guide | 605


Configuring Route Maps in Gaia Clish

Configuring Route Maps in Gaia Clish


Route maps support both IPv4 and IPv6 protocols, which includes RIP, RIPng, BGP, OSPFv2,
and OSPFv3.
You can only define BGP-4 Multiprotocol Extensions policy with route maps.
For the other protocols, you can use route maps or the Route Redistribution and Inbound
Route Filters features that you configured.
Each route map includes a list of criteria and statements. You can apply route maps to
inbound, outbound, or redistribution routes. Routes are compared to the match criteria, and all
the actions defined in the criteria are applied to those routes which match all the criteria. You
can set the match criteria in any order. If you do not define match criteria in a route map, the
route map matches all routes.
You define route maps, then assign them to protocols for export or import policy for that
protocol.
To create a route map, use CLI commands to define a set of criteria that must be matched for
the command to run. If the criteria are matched, then the system runs the actions you define. A
route map is identified by a name and a number, an Allow or Restrict clause, and a collection
of match and set statements.
There can be more than one instance of a route map (same name, different ID). The lowest
numbered instance of a route map is checked first. Route map processing stops when all the
criteria of a route map instance are matched, or all the instances of a route map are exhausted.
If the criteria are matched, the actions in the section are run.

Routing protocols can use more than one route map when you set clear preference values for
each. The applicable route map with lowest preference value is checked first.

Important: - Route maps override the settings configured in Gaia Portal.

For more information, see sk100501: How to configure Routemaps in Gaia Clish.

R82.10 Gaia Advanced Routing Administration Guide | 606


Route Maps - Configuration Commands

Route Maps - Configuration Commands


Important - In a Cluster, you must configure all the Cluster Members in the same way.

n To see the available "set" commands for Routemaps, enter in Gaia Clish:

set routemap[Esc][Esc]

n To see the configured Routemaps, enter in Gaia Clish:

show routemaps
show routemap <Name of Route Map> {all | id <1-65535>}

Important - Some statements have an effect on some protocols only. The same
parameter cannot appear both as a "match" and as an "action" statement in a route
map. These include Community, Metric, and Nexthop.

R82.10 Gaia Advanced Routing Administration Guide | 607


Route Maps - Configuration Commands

Syntax to configure Route Map match conditions


set routemap <Name of Route Map> id {<1-65535> | default} match
as <BGP AS Number> {on | off}
aspath-regex {empty | <Regular Expression>} origin {any | egp | igp | incomplete}
community
<Community ID> as <Community AS Number 1-65535> {on | off}
exact {on | off}
no-advertise {on | off}
no-export {on | off}
no-export-subconfed {on | off}
none {on | off}
community-regex {empty | <Regular Expression>}
extcommunity
match-type {all | any | exact}
type transitive-two-octet-as
subtype {bgp-data-collect | cisco-vpn-dist | l2vpn-id | ospf-domain-id | route-origin | route-target | source-as}
value <1-65535>:<0-4294967295> {on | off}
type non-transitive-two-octet-as
subtype link-bandwidth value <1-65535>:<0-4294967295> {on | off}
type transitive-four-octet-as
subtype {bgp-data-collect | cisco-vpn-dist | generic | ospf-domain-id | route-origin | route-target | source-as}
value <65536-4294967295>:<0-65535> {on | off}
type non-transitive-four-octet-as
subtype generic value <65536-4294967295>:<0-65535> {on | off}
type transitive-ipv4-address
subtype {cisco-vpn-dist | l2vpn-id | ospf-domain-id | ospf-route-id | route-origin | route-target | vrf-route-
import} value <IPv4 Address>:<0-65535> {on | off}
extcommunity-regex {empty | <Regular Expression>}
ifaddress <IPv4 or IPv6 Address of Interface> {on | off}
interface <Name of Interface> {on | off}
level {level-1 | level-2} {on | off}
metric value <Metric>
neighbor <IPv4 or IPv6 Address of Network> {on | off}
network <IPv4 or IPv6 Address of Interface>/<Mask Length>
all [restrict {on | off}]
between <Start Mask Length> and <End Mask Length> [restrict {on | off}]
exact [restrict {on | off}]
off
refines [restrict {on | off}]
nexthop <IPv4 or IPv6 Address of Next Hop Gateway> {on | off}
ospf-instance <OSPF Instance> {on | off}
prefix-list <Prefix List>
off
preference <1-255> invert {on | off}
preference <1-255> on
prefix-tree <Prefix Tree>
off
preference <1-255> invert {on | off}
preference <1-255> on
protocol <Protocol>
remove
as
aspath-regex
community
community-regex
extcommunity
extcommunity-regex
ifaddress
interface
level
metric
metric-type
neighbor
network
nexthop
ospf-instance
prefix-list
prefix-tree
protocol
route-type
tag
route-type {type-1 | type-2 | inter-area | intra-area} {on | off}
tag <1-4294967295> {on | off}

R82.10 Gaia Advanced Routing Administration Guide | 608


Route Maps - Configuration Commands

Syntax to configure Route Map actions on matching routes


set routemap <Name of Route Map> id {<1-65535> | default} action
aspath-prepend-count <1-25>
community
<Community ID> as <Community AS Number 1-65535> {on | off}
append {on | off}
delete {on | off}
no-advertise {on | off}
no-export {on | off}
no-export-subconfed {on | off}
none {on | off}
replace {on | off}
extcommunity
action-type {append | replace}
type transitive-two-octet-as
subtype {bgp-data-collect | cisco-vpn-dist | l2vpn-id | ospf-domain-id | route-origin | route-target | source-as}
value <1-65535>:<0-4294967295> {on | off}
type non-transitive-two-octet-as
subtype link-bandwidth value <1-65535>:<0-4294967295> {on | off}
type transitive-four-octet-as
subtype {bgp-data-collect | cisco-vpn-dist | generic | ospf-domain-id | route-origin | route-target | source-as}
value <65536-4294967295>:<0-65535> {on | off}
type non-transitive-four-octet-as
subtype generic value <65536-4294967295>:<0-65535> {on | off}
type transitive-ipv4-address
subtype {cisco-vpn-dist | l2vpn-id | ospf-domain-id | ospf-route-id | route-origin | route-target | vrf-route-
import} value <IPv4 Address>:<0-65535> {on | off}
localpref <0-65535>
metric
add <1-4294967295>
igp add <1-4294967295>
igp subtract <1-4294967295>
subtract <1-4294967295>
value <0-4294967295>
metric-type {internal | external}
nexthop
ip <IPv4 Address of Next Hop Gateway>
ipv6 <IPv6 Address of Next Hop Gateway>
ospfautomatictag <0-4095>
ospfmanualtag <1-4294967295>
precedence <0-65535>
preference <0-65535>
prefix-list <Prefix List>
remove
aspath-prepend-count
community
extcommunity
localpref
metric
metric-type
nexthop ip
nexthop ipv6
ospfautomatictag
ospfmanualtag
precedence
preference
prefix-list
riptag
route-type
riptag <1-65535>
route-type {type-1 | type-2}

Syntax to configure other Route Map settings

set routemap <Name of Route Map> id {<1-65535> | default} allow


set routemap <Name of Route Map> id {<1-65535> | default}
inactive
set routemap <Name of Route Map> id {<1-65535> | default} {on |
off}
set routemap <Name of Route Map> id {<1-65535> | default}
restrict

R82.10 Gaia Advanced Routing Administration Guide | 609


Route Maps - Configuration Commands

Parameters

Parameter Description

set routemap Configures Route Map match conditions.


<Name of Route
Map> id {<1-
65535> | default}
match

match as <BGP AS Configures the Route Map to only match routes being
Number> {on | received from or advertised to the specified BGP Autonomous
off} System number.
Multiple AS match conditions can be configured for a given
Route Map ID.
A match will occur if any one of the AS match conditions
matches a given route.
Note - This match condition applies to both the
"import-routemap" and "export-routemap"
commands, but only when you use BGP. For example,
"set bgp import-routemap bar preference 1
on".
n <BGP AS Number> - Number 1 - 4294967295, or
65535.65535
n off - Removes the BGP Autonomous System match
condition.
n on - Creates the BGP Autonomous System match
condition.

match aspath- Configures a regular expression to match the BGP


regex {empty | Autonomous System Path (AS Path).
<Regular Configures a route origin.
Expression>}
origin {any | egp
| igp |
incomplete}

R82.10 Gaia Advanced Routing Administration Guide | 610


Route Maps - Configuration Commands

Parameter Description

A valid AS_PATH regular expression contains only digits and


these special characters:
n . - The period character matches any single character.
n \ - The backslash character matches the character right
after the backslash. For pattern recall, match the pattern
indicated by the digit following the backslash. To enter
the backslash character, enter two backslash
characters (\\ - the first backslash character escapes
the second backslash character).
n ^ - The circumflex character matches the characters or
null string at the beginning of the AS path.
n $ - The dollar character matches the characters or null
string at the end of the AS path.
n ? - The question mark matches zero or one occurrence
of the pattern before "?". To enter the question mark,
press the CTRL V keys and then press the SHISFT ?
keys.
n * - The asterisk character matches zero or more
occurrences of the pattern before "*".
n + - The plus character matches one or more
occurrences of the pattern before "+".
n | - The pipeline (vertical line) character matches one of
the patterns on either side of the "|" character.
n _ - The underscore character matches comma (,), left
brace ({), right brace (}), beginning of ASPath (^), end
of ASPath ($), or a whitespace (space or tabulation).
n [ ] - The square brackets match the set of characters or
range of characters separated by a hyphen (-) within
the brackets.
n ( ) - The round brackets group one or more patterns into
a single pattern.
n {m n} - Matches at least "m" and at most "n" repetitions
of the pattern before "{m,n}". Both "m" and "n" are
positive integers, and "m" is less than or equal to "n".
n {m} - Matches exactly "m" repetitions of the pattern
before "{m}". The "m" is a positive integer.
n {m,} - Matches "m" or more repetitions of the pattern
before "{m}". The "m" is a positive integer.

R82.10 Gaia Advanced Routing Administration Guide | 611


Route Maps - Configuration Commands

Parameter Description

The route origin:


n any - A route was learned from any protocol and the
path is probably complete.
n igp - A route was learned from an interior routing
protocol and the path is probably complete.
n egp - A route was learned from an exterior routing
protocol that does not support AS-PATH, and the path
is probably incomplete.
n incomplete - The route path information is
incomplete.

match community Configures the Route Map to match the specified Community
<Community ID> as ID and Community AS number attributes of BGP routes.
<Community AS
Number 1-65535>
n off - Removes the BGP community match condition.
{on | off}
n on - Creates the BGP community match condition.

match community Matches exactly the set of configured Communities against


exact {on | off} the entire BGP Communities attribute.
You must add the Community String(s) to be matched to this
Route Map ID with this command:
set routemap <Route Map Name> id <Route
Map ID> match community <Community ID> as
<Community AS Number> on

n off - Removes the BGP community match condition.


n on - Creates the BGP community match condition.

Note - This match condition applies to both the


"import-routemap" and "export-routemap"
commands, but only when you use BGP. For example,
"set bgp import-routemap bar preference 1
on".

R82.10 Gaia Advanced Routing Administration Guide | 612


Route Maps - Configuration Commands

Parameter Description

match community Matches routes, which have the No-Advertise option set in the
no-advertise {on BGP Communities attribute.
| off} Routes with this value are not advertised to any BGP peers.
n off - Removes the BGP community match condition.
n on - Creates the BGP community match condition.

Note - This match condition applies to both the


"import-routemap" and "export-routemap"
commands, but only when you use BGP. For example,
"set bgp import-routemap bar preference 1
on".

match community Matches routes, which have the No-Export option set in the
no-export {on | BGP Communities attribute.
off} Routes with this value are not exported outside a BGP
Confederation boundary.
This option also applies to stand-alone Autonomous Systems,
which are not part of a Confederation.
n off - Removes the BGP community match condition.
n on - Creates the BGP community match condition.

Note - This match condition applies to both the


"import-routemap" and "export-routemap"
commands, but only when you use BGP. For example,
"set bgp import-routemap bar preference 1
on".

match community Matches routes, which have the No-Export-Subconfed option


no-export- set in the BGP Communities attribute.
subconfed {on | Routes with this value are not exported outside a BGP
off} Autonomous System.
For Confederations, routes are not exported to routers that
have a different Routing Domain Identifier.
n off - Removes the BGP community match condition.
n on - Creates the BGP community match condition

Note - This match condition applies to both the


"import-routemap" and "export-routemap"
commands, but only when you use BGP. For example,
"set bgp import-routemap bar preference 1
on".

R82.10 Gaia Advanced Routing Administration Guide | 613


Route Maps - Configuration Commands

Parameter Description

match community Matches routes, which have an empty BGP Communities


none {on | off} attribute.
n off - Removes the BGP community match condition.
n on - Creates the BGP community match condition

Note - This match condition applies to both the


"import-routemap" and "export-routemap"
commands, but only when you use BGP. For example,
"set bgp import-routemap bar preference 1
on".

R82.10 Gaia Advanced Routing Administration Guide | 614


Route Maps - Configuration Commands

Parameter Description

match community- Configures a regular expression to match the BGP


regex {empty | Community.
<Regular Notes
Expression>}
n This match condition applies to both the "import-
routemap" and "export-routemap" commands,
but only when you use BGP. For example, "set
bgp import-routemap bar preference 1
on".
n The maximum size of the regular expression is 256
characters.
n . - The period character matches any single character.
n \ - The backslash character matches the character right
after the backslash. For pattern recall, match the pattern
indicated by the digit following the backslash. To enter
the backslash character, enter two backslash
characters (\\ - the first backslash character escapes
the second backslash character).
n ^ - The circumflex character matches the characters or
null string at the beginning of the AS path.
n $ - The dollar character matches the characters or null
string at the end of the AS path.
n ? - The question mark matches zero or one occurrence
of the pattern before "?". To enter the question mark,
press the CTRL V keys and then press the SHISFT ?
keys.
n * - The asterisk character matches zero or more
occurrences of the pattern before "*".
n + - The plus character matches one or more
occurrences of the pattern before "+".
n | - The pipeline (vertical line) character matches one of
the patterns on either side of the "|" character.
n _ - The underscore character matches comma (,), left
brace ({), right brace (}), beginning of ASPath (^), end
of ASPath ($), or a whitespace (space or tabulation).
n [ ] - The square brackets match the set of characters or
range of characters separated by a hyphen (-) within
the brackets.
n ( ) - The round brackets group one or more patterns into
a single pattern.
n {m n} - Matches at least "m" and at most "n" repetitions
of the pattern before "{m,n}". Both "m" and "n" are
positive integers, and "m" is less than or equal to "n".

R82.10 Gaia Advanced Routing Administration Guide | 615


Route Maps - Configuration Commands

Parameter Description

n {m} - Matches exactly "m" repetitions of the pattern


before "{m}". The "m" is a positive integer.
n {m,} - Matches "m" or more repetitions of the pattern
before "{m}". The "m" is a positive integer.

match Configures the method to match the BGP Extended


extcommunity Communities provided in this Route Map ID:
match-type {all |
any | exact}
n all - Must match all of the Extended Communities.
n any - Must match at least one of the Extended
Communities (this is the default)
n exact - Must match exactly the entire set of Extended
Communities.

match Matches routes that contain the specified Extended


extcommunity- Community in the BGP Extended Community attribute.
match type <Type> Note - You can configure a maximum of 25 Extended
subtype <Subtype> Communities.
value <Value> {on
| off}

n type <Type>
Configures the BGP Extended Community type, which
determines the format of the BGP Extended Community
value, and whether it is transitive across ASes.
You can use Transitive types for eBGP.
You can use Non-Transitive types only for iBGP.
For more information, see RFC 4360.
Supported types:
l transitive-two-octet-as - Transitive Two

Octet AS
l non-transitive-two-octet-as - Non-

Transitive Two Octet AS


l transitive-four-octet-as - Transitive Four

Octet AS
l non-transitive-four-octet-as - Non-

Transitive Four Octet AS


l transitive-ipv4-address - Transitive IPv4

Address

R82.10 Gaia Advanced Routing Administration Guide | 616


Route Maps - Configuration Commands

Parameter Description

n subtype <Subtype>
Configures the Subtype for a BGP Extended
Community.
Supported subtypes (depend on the "Type"):
l bgp-data-collect - BGP Data Collection

l cisco-vpn-dist - Cisco VPN Distinguisher

l generic - Generic

l l2vpn-id - L2VPN Identifier

l link-bandwidth - Link Bandwidth

l ospf-domain-id - OSPF Domain Identifier

l ospf-route-id - OSPF Route ID

l route-origin - Route Origin

l route-target - Route Target

l source-as - Source AS

l vrf-route-import - VRF Route Import

n value <Value>
Supported values (depend on the "Type"):
l For the Type "transitive-two-octet-as":

Format: <Two-Octet AS>:<Four-Octet


Value>
Valid values: <1-65535>:<0-4294967295>
l For the Type "non-transitive-two-octet-

as":
Format: <Two-Octet AS>:<Four-Octet
Value>
Valid values: <1-65535>:<0-4294967295>
l For the Type "transitive-four-octet-as":

Format: <Four-Octet AS>:<Two-Octet


Value>
Valid values: <65536-4294967295>:<0-
65535>
l For the Type "non-transitive-four-octet-

as":
Format: <Four-Octet AS>:<Two-Octet
Value>
Valid values: <65536-4294967295>:<0-
65535>
l For the Type "transitive-ipv4-address":

Format: <IPv4 Address>:<Two-Octet


Value>
Valid values: <IPv4 Address>:<0-65535>

R82.10 Gaia Advanced Routing Administration Guide | 617


Route Maps - Configuration Commands

Parameter Description

match Configures a regular expression to match the BGP Extended


extcommunity- Community.
regex {empty | Notes
"<Regular
Expression>"} n This match condition applies to both the "import-
routemap" and "export-routemap" commands,
but only when you use BGP. For example, "set
bgp import-routemap bar preference 1
on".
n The maximum size of the regular expression is 256
characters.
n . - The period character matches any single character.
n \ - The backslash character matches the character right
after the backslash. For pattern recall, match the pattern
indicated by the digit following the backslash. To enter
the backslash character, enter two backslash
characters (\\ - the first backslash character escapes
the second backslash character).
n ^ - The circumflex character matches the characters or
null string at the beginning of the AS path.
n $ - The dollar character matches the characters or null
string at the end of the AS path.
n ? - The question mark matches zero or one occurrence
of the pattern before "?". To enter the question mark,
press the CTRL V keys and then press the SHISFT ?
keys.
n * - The asterisk character matches zero or more
occurrences of the pattern before "*".
n + - The plus character matches one or more
occurrences of the pattern before "+".
n | - The pipeline (vertical line) character matches one of
the patterns on either side of the "|" character.
n _ - The underscore character matches comma (,), left
brace ({), right brace (}), beginning of ASPath (^), end
of ASPath ($), or a whitespace (space or tabulation).
n [ ] - The square brackets match the set of characters or
range of characters separated by a hyphen (-) within
the brackets.
n ( ) - The round brackets group one or more patterns into
a single pattern.
n {m n} - Matches at least "m" and at most "n" repetitions
of the pattern before "{m,n}". Both "m" and "n" are
positive integers, and "m" is less than or equal to "n".

R82.10 Gaia Advanced Routing Administration Guide | 618


Route Maps - Configuration Commands

Parameter Description

n {m} - Matches exactly "m" repetitions of the pattern


before "{m}". The "m" is a positive integer.
n {m,} - Matches "m" or more repetitions of the pattern
before "{m}". The "m" is a positive integer.

match ifaddress Configures the Route Map to match the specified interface IP
<IPv4 or IPv6 address.
Address of The specified IP address is matched against the IP address of
Interface> {on | the interface, which received the route.
off} This match condition only applies to routes received through
dynamic routing protocols and is otherwise ignored.
For example, static routes match the Route Map, even though
they were not received from the interface IP address specified
by this match condition.
There can be multiple interface address match conditions
under the same Route Map ID.
This type of match condition applies to Route Maps, which are
used with the "import-routemap" command and with the
"export-routemap" command.
n off - Removes the interface address first hop match
condition.
n on - Creates the interface address first hop match
condition.

match interface Configures the Route Map to match the specified interface
<Name of name.
Interface> {on | There can be multiple interface match conditions under the
off} same Route Map ID.
This type of match condition applies to Route Maps, which are
used with the "import-routemap" command and with the
"export-routemap" command.
n off - Removes the interface name first hop match
condition.
n on - Creates the interface name first hop match
condition.

R82.10 Gaia Advanced Routing Administration Guide | 619


Route Maps - Configuration Commands

Parameter Description

match level Configures the Route Map to match only the specified IS-IS
{level-1 | level- route level.
2} {on | off} By default, the Route Map matches both IS-IS route levels.
n off - Removes the match condition for the specified IS-
IS route level.
n on - Creates the match condition for the specified IS-IS
route level.

match metric Configures the Route Map to match routes that have a
value <Metric> specific metric.
This match condition is applicable for RIP, BGP, and OSPF.
n For RIP and IPv6 RIP (RIPng), this matches the RIP
metric.
The valid range of values is 1 - 65535, where 16 or
greater indicates the route is unreachable.
n For OSPF and IPv6 OSPF (OSPFv3), this value
matches the route cost.
The valid range of values is 0 - 65535.
n For BGP, this value matches the MED.
The valid range of values is 0 - 4294967295.

match neighbor Configures the Route Map to match routes from the specified
<IPv4 or IPv6 neighbor.
Address of This match rule is only applicable for BGP or RIP and only
Network> {on | when you use the "import-routemap" command.
off} Multiple neighbor match conditions can be configured for a
given Route Map ID.

match network Configures the Route Map to match routes, which are based
<IPv4 or IPv6 on the specified IPv4 or IPv6 subnet.
Address of
Interface>/<Mask
Length>

match network ... Configures the Route Map to match all subnets, which are
all [restrict {on equal to, or contained within the specified IPv4 or IPv6
| off}] subnet.
n restrict off - Allows the matched subnets to be
exported or imported.
n restrict on - Prevents the matched subnets from
being exported or imported.

R82.10 Gaia Advanced Routing Administration Guide | 620


Route Maps - Configuration Commands

Parameter Description

match network ... Configures the Route Map to match routes that are within the
between <Start specified IPv4 or IPv6 subnet, and which have a mask length
Mask Length> and that is between the specified range of values.
<End Mask Length> To resolve conflicts in match conditions, Route Maps are
[restrict {on | ordered by ID.
off}] For a specified Route Map, the match conditions under ID 1
take precedence, followed by ID 2, and so on.
n restrict off - Allows the matched subnets to be
exported or imported.
n restrict on - Prevents the matched subnets from
being exported or imported.

match network ... Configures the Route Map to only match routes, which have
exact [restrict the same prefix and mask length as the specified IPv4 or IPv6
{on | off}] subnet.
n restrict off - Allows the matched subnets to be
exported or imported.
n restrict on - Prevents the matched subnets from
being exported or imported.

match network ... Removes the network match condition.


off

match network ... Configures the Route Map to match routes, which are
refines [restrict contained within the specified IPv4 or IPv6 subnet.
{on | off}] Routes that exactly match the specified subnet (have the
same mask length), are excluded from the match.
n restrict off - Allows the matched subnets to be
exported or imported.
n restrict on - Prevents the matched subnets from
being exported or imported.

match nexthop Configures the Route Map to match routes that have the
<IPv4 or IPv6 specified IPv4 or IPv6 next hop gateway address.
Address of Next Multiple next hop match conditions can be configured for a
Hop Gateway> {on given Route Map ID.
| off} A match occurs, if any of the next hop values are matched by
a specified route.
This match is only applicable when you use the "export-
routemap" command to export BGP, RIP, or OSPF routes.

R82.10 Gaia Advanced Routing Administration Guide | 621


Route Maps - Configuration Commands

Parameter Description

match ospf- Matches routes learned from a specific OSPF Instance.


instance <OSPF This only affect routes from OSPF.
Instance> {on |
off}

match prefix-list Configures the Route Map to match the specified Prefix List.
<Prefix List> Each route is matched against the specified prefix list's
prefixes and is accepted or rejected according to the prefix
list's policy.
Multiple prefix lists may be matched, and are considered in
order of preference (from low to high).
Prefix lists may be used for either "export-routemap" or
"import-routemap" commands.
A specified Route Map ID may only match one of these types:
n Prefix List
n Prefix Tree
n Network

match prefix-list Removes the match condition for the specified Prefix List.
<Prefix List> off

match prefix-list Configures the preference for this match statement.


<Prefix List> Groups of prefixes are matched in increasing order of
preference <1- preference, until a match is found.
255> invert {on |
off}
n invert off - Does not invert the Accept / Restrict
parameters on prefixes.
n invert on - Inverts the Accept / Restrict parameters
on prefixes. If a prefix is marked as "restrict", allow it
instead. If it is not marked as "restrict", restrict it.

match prefix-list Creates the prefix list match condition.


<Prefix List>
preference <1-
255> on

R82.10 Gaia Advanced Routing Administration Guide | 622


Route Maps - Configuration Commands

Parameter Description

match prefix-tree Configures the Route Map to match the specified Prefix Tree.
<Prefix Tree> Each route is matched against the specified prefix tree's
prefixes and is accepted or rejected according to the prefix
tree's policy.
Multiple prefix trees may be matched, and will be considered
in order of preference (from low to high).
Prefix trees may be used for either "export-routemap" or
"import-routemap" commands.
A specified Route Map ID may only match one of the following
types:
n Prefix List
n Prefix Tree
n Network

match prefix-tree Removes the prefix tree match condition.


<Prefix Tree> off

match prefix-tree Configures the preference for this match statement.


<Prefix Tree> Groups of prefixes are matched in increasing order of
preference <1- preference, until a match is found.
255> invert {on |
off}
n invert off - Does not invert the Accept / Restrict
parameters on prefixes.
n invert on - Inverts the Accept / Restrict parameters
on prefixes. If a prefix is marked as "restrict", allow it
instead. If it is not marked as "restrict", restrict it.

match prefix-tree Creates the prefix tree match condition.


<Prefix Tree>
preference <1-
255> on

R82.10 Gaia Advanced Routing Administration Guide | 623


Route Maps - Configuration Commands

Parameter Description

match protocol Configures the Route Map to match routes of the specified
<Protocol> protocol type.
Use this match for route redistribution between protocols.
n aggregate - Aggregate routes
n bgp - BGP routes
n direct -Interface routes
n kernel - OS kernel (injected) routes
n ospf2 - IPv4 OSPFv2
n ospf2ase - IPv4 OSPFv2 External routes
n ospf3 - IPv6 OSPFv3 routes
n ospf3ase - IPv6 OSPFv3 External routes
n rip - IPv4 RIP routes
n ripng - IPv6 RIPng routes
n static - Static routes

match remove as Removes all BGP Autonomous System match conditions


from this Route Map ID.

match remove Removes the BGP AS-Path RegEx match condition from this
aspath-regex Route Map ID.

match remove Removes all BGP Community match conditions from this
community Route Map ID.

match remove Removes all BGP Community RegEx match conditions from
community-regex this Route Map ID.

match remove Removes all BGP Extended Community match conditions


extcommunity from this Route Map ID.

match remove Removes all BGP Extended Community RegEx match


extcommunity- conditions from this Route Map ID.
regex

match remove Removes all interface address match conditions from this
ifaddress Route Map ID.

match remove Removes all interface name match conditions from this Route
interface Map ID.

match remove Removes the IS-IS route level match conditions from this
level Route Map ID.

R82.10 Gaia Advanced Routing Administration Guide | 624


Route Maps - Configuration Commands

Parameter Description

match remove Removes the metric match conditions from this Route Map
metric ID.

match remove Removes the IS-IS metric type match conditions from this
metric-type Route Map ID.

match remove Removes the neighbor match conditions from this Route Map
neighbor ID.

match remove Removes the network address match conditions from this
network Route Map ID.

match remove Removes the nex thop gateway match conditions from this
nexthop Route Map ID.

match remove Removes the OSPF instance match conditions from this
ospf-instance Route Map ID.

match remove Removes the Prefix List match conditions from this Route
prefix-list Map ID.

match remove Removes the prefix tree match conditions from this Route
prefix-tree Map ID.

match remove Removes the protocol match conditions from this Route Map
protocol ID.

match remove Removes all route type match conditions from this Route Map
route-type ID.

match remove tag Removes all OSPF Tag match conditions from this Route
Map ID.

R82.10 Gaia Advanced Routing Administration Guide | 625


Route Maps - Configuration Commands

Parameter Description

match route-type Configures the Route Map to match the specified route type.
{type-1 | type-2 This match condition is only applicable when used with the
| inter-area | "export-routemap" command to export routes to other
intra-area} {on | routers through OSPFv2 or OSPFv3.
off} For example: set ospf export-routemap foo id 1
on
n If you configure the route type of inter-area or
intra-area, then configure the protocol match to
ospf2.
n If you configure the route type of type-1 or type-2,
then configure the protocol match condition to
ospf2ase.
During the export OSPF ASE routes to other protocols, if the
metric match condition is set, but the route type match
condition is not set, the routing system tries to match the
metric value for both type-1 and type-2 routes.
There can be multiple route type match conditions.
n off - Removes the OSPF route type match condition.
n on - Creates the OSPF route type match condition.

Note - This match condition cannot be used


simultaneously with the "route-type" action.

match tag <1- Configures the Route Map to match OSPF external routes
4294967295> {on | with the specified tag value.
off} Multiple tag match conditions can be added to a given Route
Map ID to broaden the range of tag values which are
matched.
Currently this feature can only be used to export OSPF routes
to BGP.
n off - Removes the OSPF tag match condition.
n on - Creates the OSPF tag match condition.

set routemap Configures action to perform on matching routes.


<Name of Route
Map> id {<1-
65535> | default}
action

R82.10 Gaia Advanced Routing Administration Guide | 626


Route Maps - Configuration Commands

Parameter Description

action aspath- Causes the local Autonomous System (AS) number to be


prepend-count <1- affixed to the beginning of the AS path when routes matching
25> the Route Map are advertised through BGP.
The provided value indicates the number of times the local AS
number should be prepended.
This action only applies to BGP, and only applies when you
export routes with the "export-routemap" command. The
action is otherwise ignored.

action community Configures actions to alter the Communities attribute of BGP


routes matched by this Route Map ID.
The Community Action List configured here and the
configured operation determine how the BGP Communities
attribute are altered.

action community Configures the Route Map to append a BGP Community with
<Community ID> as the specified BGP Community ID and BGP Community AS
<Community AS number to the Community Action List.
Number 1-65535>
{on | off}
n off - Removes the BGP community action.
n on - Creates the BGP community action.

action community Configures the BGP Communities in the Community Action


append {on | off} List to be appended to the BGP Communities attribute of BGP
routes matched by this Route Map ID.
n off - Removes the BGP community action.
n on - Creates the BGP community action.

action community Configures the BGP Communities in the Community Action


delete {on | off} List to be deleted from the existing BGP Communities
attribute of BGP routes matched by this Route Map ID.
n off - Removes the BGP community action.
n on - Creates the BGP community action.

action community Appends the special BGP Community "NO_ADVERTISE"


no-advertise {on (65535:65282) to the Community Action List.
| off} Routes with this value are not advertised to any BGP peers.
n off - Removes the BGP community action.
n on - Creates the BGP community action.

R82.10 Gaia Advanced Routing Administration Guide | 627


Route Maps - Configuration Commands

Parameter Description

action community Appends the special BGP Community "NO_EXPORT"


no-export {on | (65535:65281) to the Community Action List.
off} Routes with this value are not exported outside a BGP
Confederation boundary.
This option also applies to stand-alone Autonomous Systems,
which are not part of a Confederation.
n off - Removes the BGP community action.
n on - Creates the BGP community action.

action community Appends the special BGP Community "NO_EXPORT_


no-export- SUBCONFED" (65535:65283) to the Community Action List.
subconfed {on | Routes with this value are not exported outside a BGP
off} Autonomous System.
For Confederations, routes are not exported to routers that
have a different Routing Domain Identifier.
n off - Removes the BGP community action.
n on - Creates the BGP community action.

action community Configures no BGP Community attribute to be sent,


none {on | off} regardless of any existing BGP Community attribute.
n off - Removes the BGP community action.
n on - Creates the BGP community action.

action community Configures the BGP Communities in the Community Action


replace {on | List to replace all BGP Communities in the BGP Communities
off} attribute of BGP routes matched by this Route Map ID.
If the Community Action List is empty, the BGP Communities
attribute remains unchanged.
n off - Removes the BGP community action.
n on - Creates the BGP community action.

action Configures the BGP Extended Communities in the


extcommunity Community Action List to be appended to the BGP Extended
append {on | off} Communities attribute of BGP routes matched by this Route
Map ID.
n off - Removes the BGP community action.
n on - Creates the BGP community action.

R82.10 Gaia Advanced Routing Administration Guide | 628


Route Maps - Configuration Commands

Parameter Description

action Configures the BGP Extended Communities in the


extcommunity Community Action List to replace all BGP Extended
replace {on | Communities in the BGP Extended Communities attribute of
off} BGP routes matched by this Route Map ID.
If the Community Action List is empty, the BGP Extended
Communities attribute remains unchanged.
n off - Removes the BGP community action.
n on - Creates the BGP community action.

action Configures the BGP Extended Communities in the


extcommunity type Community Action List to use the BGP Extended
<Type> subtype Communities attribute of BGP routes matched by this Route
<Subtype> value Map ID.
<Value> {on | Note - You can configure a maximum of 25 Extended
off} Communities.

n type <Type>
Configures the BGP Extended Community type, which
determines the format of the BGP Extended Community
value, and whether it is transitive across ASes.
You can use Transitive types for eBGP.
You can use Non-Transitive types only for iBGP.
For more information, see RFC 4360.
Supported types:
l transitive-two-octet-as - Transitive Two

Octet AS
l non-transitive-two-octet-as - Non-

Transitive Two Octet AS


l transitive-four-octet-as - Transitive Four

Octet AS
l non-transitive-four-octet-as - Non-

Transitive Four Octet AS


l transitive-ipv4-address - Transitive IPv4

Address

R82.10 Gaia Advanced Routing Administration Guide | 629


Route Maps - Configuration Commands

Parameter Description

n subtype <Subtype>
Configures the Subtype for a BGP Extended
Community.
Supported subtypes (depend on the "Type"):
l bgp-data-collect - BGP Data Collection

l cisco-vpn-dist - Cisco VPN Distinguisher

l generic - Generic

l l2vpn-id - L2VPN Identifier

l link-bandwidth - Link Bandwidth

l ospf-domain-id - OSPF Domain Identifier

l ospf-route-id - OSPF Route ID

l route-origin - Route Origin

l route-target - Route Target

l source-as - Source AS

l vrf-route-import - VRF Route Import

n value <Value>
Supported values (depend on the "Type"):
l For the Type "transitive-two-octet-as":

Format: <Two-Octet AS>:<Four-Octet


Value>
Valid values: <1-65535>:<0-4294967295>
l For the Type "non-transitive-two-octet-

as":
Format: <Two-Octet AS>:<Four-Octet
Value>
Valid values: <1-65535>:<0-4294967295>
l For the Type "transitive-four-octet-as":

Format: <Four-Octet AS>:<Two-Octet


Value>
Valid values: <65536-4294967295>:<0-
65535>
l For the Type "non-transitive-four-octet-

as":
Format: <Four-Octet AS>:<Two-Octet
Value>
Valid values: <65536-4294967295>:<0-
65535>
l For the Type "transitive-ipv4-address":

Format: <IPv4 Address>:<Two-Octet


Value>
Valid values: <IPv4 Address>:<0-65535>

R82.10 Gaia Advanced Routing Administration Guide | 630


Route Maps - Configuration Commands

Parameter Description

action localpref Configures the local preference for iBGP routes which match
<0-65535> this Route Map.
This action only applies to the iBGP protocol, and only to
Route Maps, which are used with the "import-routemap"
command.

action metric add Increments the metric of matching routes by the specified
<1-4294967295> amount.
This action only applies when:
n You export OSPF/OSPFv3 or RIP/RIPng routes to BGP
with the "set bgp ... export-routemap" command
n You import RIP/RIPng routes from other routers with the
"import-routemap" command
Otherwise, this action has no effect. For example, when you
import OSPF/OSPFv3 routes from other routers.
n When you export routes to BGP, the valid range of
values for the resulting metric is 0 - 4294967295.
n When you import routes from RIP, the valid range of the
resulting value is 1 - 65535, where 16 or greater causes
the route to be treated as unreachable and not be
installed in the kernel routing table.
n When you import routes from OSPF, the valid range of
the resulting value is 0 - 65535.

action metric igp Configures the metric to the RIP metric value and adds the
add <1- specified constant to it.
4294967295> This action only applies when you export OSPF/OSPFv3 or
RIP/RIPng routes to BGP with the "set bgp ... export-
routemap" command. Otherwise, this action has no effect.
The valid range of values for the resulting metric is 0 -
4294967295.

action metric igp Configures the metric to the RIP metric value and subtracts
subtract <1- the specified constant from it.
4294967295> This action only applies when you export OSPF/OSPFv3 or
RIP/RIPng routes to BGP with the "set bgp ... export-
routemap" command. Otherwise, this action has no effect.
The valid range of values for the resulting metric is 0 -
4294967295.

R82.10 Gaia Advanced Routing Administration Guide | 631


Route Maps - Configuration Commands

Parameter Description

action metric Decrements the metric of matching routes by the specified


subtract <1- amount.
4294967295> This action only applies when:
n You export OSPF/OSPFv3 or RIP/RIPng routes to BGP
with the "set bgp ... export-routemap" command
n You import RIP/RIPng routes from other routers with the
"import-routemap" command
Otherwise, this action has no effect. For example when you
import OSPF/OSPFv3 routes from other routers.
n When you export routes to BGP, the valid range of
values for the resulting metric is 0 - 4294967295.
n When you import routes from RIP, the valid range of the
resulting value is 1 - 65535, where 16 or greater causes
the route to be treated as unreachable and not be
installed in the kernel routing table.
n When you import routes from OSPF, the valid range of
the resulting value is 0 - 65535.

action metric Configures the metric of matching routes to the specified


value <0- value.
4294967295> When you export to IPv4 RIP or IPv6 RIPng, this action sets
the RIP metric. The valid range of values is 1 - 65535, where
16 or greater indicates the route is unreachable.
n When you export to IPv4 OSPFv2 or IPv6 OSPFv3, this
action sets the OSPF route cost. The valid range of
values is 0 - 65535.
n When you export to BGP, this action affects the BGP
MED. The valid range of values is 0 - 4294967295.
This action only applies to Route Maps used with the "export-
routemap" command. Otherwise, this action has no effect.

R82.10 Gaia Advanced Routing Administration Guide | 632


Route Maps - Configuration Commands

Parameter Description

action metric- Configures the IS-IS metric type for exported routes.
type {internal | Exported IS-IS routes have two metric types - internal and
external} external.
When considering which neighbors to install a route toward,
internal metrics are preferred over external metrics.
By default, routes exported into IS-IS are exported with
internal metrics.
Note - When using wide metrics, this action has no
effect. Wide metrics cannot differentiate between internal
and external. Therefore, all routes sent with wide metrics
are considered internal.

action nexthop ip Configures the IPv4 next hop address for matching BGP
<IPv4 Address of routes.
Next Hop Gateway> The next hop address value in the match condition cannot be
a link-local address.
This action only applies when you import BGP routes from, or
export BGP routes to another router.
When operating as a route reflector, the next hop is not
changed for any route learned from iBGP when the route is
being exported to an internal BGP peer.

action nexthop Configures the IPv6 next hop address for matching BGP
ipv6 <IPv6 routes.
Address of Next The next hop address value in the match condition cannot be
Hop Gateway> a link-local address.
This action only applies when you import BGP routes from, or
export BGP routes to another router.
When operating as a route reflector, the next hop is not
changed for any route learned from iBGP when the route is
being exported to an internal BGP peer.

action Configures the automatic tag for OSPF external routes that
ospfautomatictag match the Route Map.
<0-4095> This action only applies when you export non-OSPF routes
into OSPF with the "export-routemap" command.
See RFC 1403 for more information on OSPF tags.

action Configures the manual tag for OSPF external routes that
ospfmanualtag <1- match this Route Map ID.
4294967295> This action only applies when you export non-OSPF routes
into OSPF with the "export-routemap" command.
See RFC 1403 for more information on OSPF tags.

R82.10 Gaia Advanced Routing Administration Guide | 633


Route Maps - Configuration Commands

Parameter Description

action precedence Configures the precedence of routes, which match this Route
<0-65535> Map ID.
If the same route is being imported into the kernel routing
table from multiple sources (multiple protocols), the
precedence values are compared to determine which route is
preferred.
The lower value has priority.
The non-preferred routes are marked as inactive and not
installed in the kernel.
This action only applies when you use the "import-
routemap" command.

action preference Configures the BGP preference of routes, which match this
<0-65535> Route Map ID.
This action applies only to routes received via BGP
advertisements.
This is equivalent to the BGP weight (in Cisco terms) of the
route.
However, unlike Cisco, the route with lower value is preferred.
Routes with any weight are preferred over routes without a
weight.
The preference value is only applicable for the local router.

action prefix- Configures the Prefix List, which matches this Route Map ID.
list <Prefix
List>

action prefix- Configures the Prefix List, which matches this Route Map ID.
list <Prefix This configuration is required for routemaps used as inject-
List> routemaps by dynamic routing protocols.
Inject-routemaps insert prefixes in the action Prefix List to the
routing table if a condition is satisfied.
You cannot configure this action on routemaps with more than
one Route Map ID.
The injected routes will be the "exact" prefixes, even if you
use the options "all", "between", or "refines" in the Prefix
List configuration.

action remove Removes the "as-prepend-count" action from this Route


aspath-prepend- Map ID.
count

action remove Removes all Community action statements from this Route
community Map ID.

R82.10 Gaia Advanced Routing Administration Guide | 634


Route Maps - Configuration Commands

Parameter Description

action remove Removes the local preference action statements from this
localpref Route Map ID.

action remove Removes the metric action statements from this Route Map
metric ID.

action remove Removes the IPv4 next hop action from this Route Map ID.
nexthop ip

action remove Removes the IPv6 next hop action from this Route Map ID.
nexthop ipv6

action remove Removes the OSPF automatic tag action statements from this
ospfautomatictag Route Map ID.

action remove Removes the OSPF manual tag action statements from this
ospfmanualtag Route Map ID.

action remove Removes the precedence action statements from this Route
precedence Map ID.

action remove Removes the preference action statements from this Route
preference Map ID.

action remove Removes the Prefix List action statements from this Route
prefix-list Map ID.

action remove Removes the RIP tag action statements from this Route Map
riptag ID.

action remove Removes the route type action statements from this Route
route-type Map ID.

action riptag <1- Configures the RIP tag for external routes that match this
65535> Route Map ID.

action route-type This action only applies when you export non-RIP routes into
{type-1 | type-2} RIP with the "export-routemap" command.
See RFC 2453 for more information on RIP route tags.

set routemap Allows all matching routes, unless specifically restricted.


<Name of Route
Map> id {<1-
65535> | default}
allow

R82.10 Gaia Advanced Routing Administration Guide | 635


Route Maps - Configuration Commands

Parameter Description

set routemap Disables the Route Map ID.


<Name of Route Use the option "allow" or "restrict" to enable it again.
Map> id {<1-
65535> | default}
inactive

set routemap Removes (off) or creates (on) this Route Map ID.
<Name of Route Range: 1-65535
Map> id {<1- Default: 10
65535> | default}
{on | off}

set routemap Restricts all routes, unless specifically accepted.


<Name of Route
Map> id {<1-
65535> | default}
restrict

R82.10 Gaia Advanced Routing Administration Guide | 636


Route Maps - Export and Import

Route Maps - Export and Import


Important - In a Cluster, you must configure all the Cluster Members in the same way.

n To see the available "set" commands for Routemaps, enter in Gaia Clish:

set routemap[Esc][Esc]

n To see the configured Routemaps, enter in Gaia Clish:

show routemaps
show routemap <Name of Route Map> {all | id <1-65535>}

n To see the available commands for IPv4 RIP Routemaps, enter in Gaia Clish:

set rip export-routemap[Esc][Esc]


set rip import-routemap[Esc][Esc]

n To see the available commands for IPv6 RIPng Routemaps, enter in Gaia Clish:

set ipv6 ripng export-routemap[Esc][Esc]


set ipv6 ripng import-routemap[Esc][Esc]

n To see the available commands for IPv4 OSPFv2 Routemaps, enter in Gaia Clish:

set ospf export-routemap[Esc][Esc]


set ospf import-routemap[Esc][Esc]

n To see the available commands for IPv6 OSPFv3 Routemaps, enter in Gaia Clish:

set ipv6 ospf3 export-routemap[Esc][Esc]


set ipv6 ospf3 import-routemap[Esc][Esc]

R82.10 Gaia Advanced Routing Administration Guide | 637


Route Maps - Export and Import

n To see the available commands for IPv4 BGP Routemaps, enter in Gaia Clish:

set bgp external remote-as <BGP Peer AS Number> export-


routemap[Esc][Esc]
set bgp external remote-as <BGP Peer AS Number> import-
routemap[Esc][Esc]
set bgp external remote-as <BGP Peer AS Number> peer <Peer IP
Address> export-routemap[Esc][Esc]
set bgp external remote-as <BGP Peer AS Number> peer <Peer IP
Address> import-routemap[Esc][Esc]
set bgp internal export-routemap[Esc][Esc]
set bgp internal import-routemap[Esc][Esc]
set bgp internal peer <Peer IP Address> import-routemap[Esc]
[Esc]

n To see the available commands for IS-IS Routemaps, enter in Gaia Clish:

set isis export-routemap[Esc][Esc]

R82.10 Gaia Advanced Routing Administration Guide | 638


Route Maps - Export and Import

Syntax to assign routemaps to protocols

set {ospf | ipv6 ospfv3 | isis | rip | ipv6 ripng}


export-routemap <Name of Route Map> preference <1-65535>
on
import-routemap <Name of Route Map> preference <1-65535>
on

For IS-IS, you can configure only an export routemap.

Syntax to disable a routemap

set {ospf | ospfv3 | isis | rip | ipv6 ripng}


export-routemap <Name of Route Map> off
import-routemap <Name of Route Map> off

For IS-IS, you can configure only an export routemap.

Syntax to view routemaps assigned to protocols

show {ospf | ospfv3 | rip | ipv6 ripng | bgp) routemap

Syntax to set BGP routemaps for export and import policies

set bgp external remote-as <1-65535>


export-routemap <Name of Route Map>
off
preference <1-65535> [family {inet | inet6 | inet-
and-inet6}] on
set bgp external remote-as <1-65535>
import-routemap <Name of Route Map>
off
preference <1-65535> [family {inet | inet6 | inet-
and-inet6}] on
set bgp internal
export-routemap <Name of Route Map>
off
preference <1-65535> [family {inet | inet6 | inet-
and-inet6}] on
set bgp internal
import-routemap <Name of Route Map>
off
preference <1-65535> [family {inet | inet6 | inet-
and-inet6}] on

R82.10 Gaia Advanced Routing Administration Guide | 639


Route Maps - Export and Import

Note - You cannot use route maps in BGP confederations.


To configure route filters and redistribution for BGP confederations, use these
pages in Gaia Portal:
Advanced Routing > Inbound Route Filters
Advanced Routing > Route Redistribution

R82.10 Gaia Advanced Routing Administration Guide | 640


Route Maps - Export and Import

Parameters

Parameter Description

<Name of Route Map> The name of the configured route map.

preference <1-65535> Determines the order, in which this Route Map is


applied in export policy.
Route Maps are evaluated in order of increasing
preference value.

family {inet | inet6 | Restricts this Route Map to match only routes with the
inet-and-inet6} specified address family or families.
n inet - Ensures this Route Map is applied only to
IPv4 routes.
n inet6 - Ensures this Route Map is applied only
to IPv6 routes.
n inet-and-inet6 - Configure this option, if the
Route Map must be applied to all routes.
Default: inet

R82.10 Gaia Advanced Routing Administration Guide | 641


Route Maps - Supported Route Map Statements by Protocol

Route Maps - Supported Route Map Statements by Protocol


Some statements affect only a particular protocol, for example, matching the Autonomous
System Number is applicable only to BGP.
If such a condition is in a routemap used by OSPF, the match condition is ignored.
Any non-applicable match conditions or actions are ignored and processing is done as if they
do not exist.
A log message is generated in the /var/log/messages file for any such statements.

Note - The same parameter cannot appear both as a match and action statement in a
routemap. These include Community, Metric, and Nexthop.

RIP
n Import Match conditions: metric, network, prefix-list, prefix-tree,
nexthop, interface, ifaddress, neighbor
n Import Actions: precedence, metric
n Export Match Conditions: network, prefix-list, prefix-tree, metric,
nexthop, interface, ifaddress, protocol
n Export Actions: metric, riptag (from other protocols)

OSPFv2 and OSPFv3


n Import Match Conditions: network, prefix-list, prefix-tree, tag,
interface, ifaddress
n Import Actions: precedence
n Export Match Conditions: network, prefix-list, prefix-tree, metric,
nexthop, interface, ifaddress, protocol, route-type, tag, ospf-
instance
n Export Actions: metric, route-type, ospfmanualtag (from other
protocols), ospfautomatictag (from other protocols)

R82.10 Gaia Advanced Routing Administration Guide | 642


Route Maps - Supported Route Map Statements by Protocol

BGP
Import Match Conditions: network, prefix-List, prefix-tree, metric,
nexthop, interface, ifaddress, as, aspath-regex, community,
community-regex, extcommunity, extcommunity-regex, large-community,
large-community-regex, neighbor

Import Actions: precedence, preference, localpref, nexthop


Export Match Conditions: network, prefix-List, prefix-tree, metric,
nexthop, interface, ifaddress, protocol, tag (export from ospf), as,
aspath-regex, community, community-regex, extcommunity,
extcommunity-regex, large-community, large-community-regex, neighbor

Export Actions: community, extcommunity, large-community, metric,


localpref, nexthop, aspath-prepend-count

IS-IS
Export Match Conditions: network, metric, nexthop, interface, ifaddress,
protocol, level, metric-type, tag (export from ospf)
Export Actions: metric, metric-type

R82.10 Gaia Advanced Routing Administration Guide | 643


Route Maps - Examples

Route Maps - Examples


For more information, see sk100501: How to configure Routemaps in Gaia Clish.
Example 1

Redistribute interface route for eth3 into OSPF, and set the OSPF route-type to AS type-2
with cost 20:

set routemap direct-to-ospf id 10 on


set routemap direct-to-ospf id 10 match interface eth3
set routemap direct-to-ospf id 10 match protocol direct
set routemap direct-to-ospf id 10 action route-type type-2
set routemap direct-to-ospf id 10 action metric value 20
set ospf export-routemap direct-to-ospf preference 1 on

Example 2

Do not accept routes from RIP neighbor [Link], accept routes from neighbor [Link]
as is, and for all other routes increment the metric by 2:

set routemap rip-in id 10 on


set routemap rip-in id 10 restrict
set routemap rip-in id 10 match neighbor [Link]
set routemap rip-in id 15 on
set routemap rip-in id 15 match neighbor [Link]
set routemap rip-in id 20 on
set routemap rip-in id 20 action metric add 2
set rip import-routemap rip-in preference 1 on

R82.10 Gaia Advanced Routing Administration Guide | 644


Route Maps - Examples

Example 3

Redistribute all static routes into BGP AS group 400.


Set the MED value to 100, prepend our AS number to the aspath 4 times.
If the route belongs to the prefix [Link]/8, do not redistribute.
Send all BGP routes whose aspath matches the regular expression (100 200+) and set the
MED value to 200.

set routemap static-to-bgp id 10 on


set routemap static-to-bgp id 10 restrict
set routemap static-to-bgp id 10 match protocol static
set routemap static-to-bgp id 10 match network [Link]/8 all
set routemap static-to-bgp id 15 on
set routemap static-to-bgp id 15 match protocol static
set routemap static-to-bgp id 15 action metric 100
set routemap static-to-bgp id 15 action aspath-prepend-count 4
set routemap bgp-out id 10 on
set routemap bgp-out id 10 match aspath-regex "(100 200+)"
origin any
set routemap bgp-out id 10 action metric 200
set bgp external remote-as 400 export-routemap bgp-out
preference 1 family inet on
set bgp external remote-as 400 export-routemap static-to-bgp
preference 2 family inet on
Note - There is no need for a match protocol statement for routes belonging to the
same protocol.

R82.10 Gaia Advanced Routing Administration Guide | 645


Route Maps - Examples

Example 4

To redistribute OSPFv2 routes from one instance to a different instance.


This routemap ("Intranet") matches all OSPF routes from OSPF instance default in the
prefix-list "Intranet" (only when used in OSPF because of missing match statement).
Match all static routes in prefix-list "Intranet".
Match all direct routes in prefix-list "Intranet".
Match all aggregate routes in prefix-list "Intranet".
Match all kernel routes in prefix-list "Intranet".
Export to OSPF - no need to match protocol OSPF for one of the IDs, it will assume it.

Do not match OSPF2 or OSPF2ASE, they are both matched implicitly for this ID.

set routemap Intranet id 1 on


set routemap Intranet id 1 allow
set routemap Intranet id 1 match ospf-instance default on
set routemap Intranet id 1 match prefix-list Intranet preference
1 on
set routemap Intranet id 11 on
set routemap Intranet id 11 match prefix-list Intranet
preference 1 on
set routemap Intranet id 11 match protocol static
set routemap Intranet id 12 on
set routemap Intranet id 12 match prefix-list Intranet
preference 1 on
set routemap Intranet id 12 match protocol direct
set routemap Intranet id 13 on
set routemap Intranet id 13 match prefix-list Intranet
preference 1 on
set routemap Intranet id 13 match protocol aggregate
set routemap Intranet id 14 on
set routemap Intranet id 14 match prefix-list Intranet
preference 1 on
set routemap Intranet id 14 match protocol kernel

R82.10 Gaia Advanced Routing Administration Guide | 646


Route Maps - Examples

Example 5

Redistribute all OSPFv3 (internal and external) routes into BGP group 400.
Set the outgoing community string to 'no-export, 200 as 100'.
For BGP IPv6 routes, send them with an empty community string.
For all routes set the nexthop value to 3003::abcd:1012 (the address on the interface
connecting to the peers).

Note - To exchange IPv6 routes in BGP the multiprotocol capability must be turned
ON in BGP Configuration for the peer.
set routemap ospf3-to-bgp id 10 on
set routemap ospf3-to-bgp id 10 match protocol ospf3 #OSPF3
INTERNAL ROUTES
set routemap ospf3-to-bgp id 10 action community replace on
set routemap ospf3-to-bgp id 10 action community no-export on
set routemap ospf3-to-bgp id 10 action community 200 as 100 on
set routemap ospf3-to-bgp id 10 action nexthop ipv6
3003::abcd:1012

set routemap ospf3-to-bgp id 20 on


set routemap ospf3-to-bgp id 20 match protocol ospf3ase #FOR AS
EXTERNAL ROUTES
set routemap ospf3-to-bgp id 20 action community replace on
set routemap ospf3-to-bgp id 20 action community no-export on
set routemap ospf3-to-bgp id 20 action community 200 as 100 on
set routemap ospf3-to-bgp id 10 action nexthop ipv6
3003::abcd:1012

set routemap bgp-out id 10 on


set routemap bgp-out id 10 action community replace on
set routemap bgp-out id 10 action community none on
set routemap ospf3-to-bgp id 10 action nexthop ipv6
3003::abcd:1012

set bgp external remote-as export-routemap bgp-out preference 1


family inet6 on
set bgp external remote-as export-routemap ospf3-to-bgp
preference 2 family inet6 on

R82.10 Gaia Advanced Routing Administration Guide | 647


Route Maps - Examples

Example 6

To redistribute routes from an OSPFv2 Instance to BGP:

set routemap OSPF-to-BGP id 10 on


set routemap OSPF-to-BGP id 10 allow
set routemap OSPF-to-BGP id 10 match ospf-instance 222 on
set routemap OSPF-to-BGP id 10 match protocol ospf2

Example 7

To redistribute routes from an OSPFv3 Instance to BGP:

set routemap OSPF-to-BGP id 10 on


set routemap OSPF-to-BGP id 10 allow
set routemap OSPF-to-BGP id 10 match ospf-instance 222 on
set routemap OSPF-to-BGP id 10 match protocol ospf3

R82.10 Gaia Advanced Routing Administration Guide | 648


Prefix Lists and Prefix Trees

Prefix Lists and Prefix Trees


The user can create prefix lists or prefix trees and configure routemaps to allow or reject the
lists.

List Description

Prefix List Simulate a sequential lookup and return the first matched entry as the true
match.
Prefix list name:
n Can be up to 16 characters in length
n Can contain only letters, numbers, '-', '_', or '.'

Prefix Return the longest match as the true match.


Tree

Prefix List Syntax


To configure a prefix on a given sequence number

set prefix-list <Name of Prefix List>


sequence-number <1-4294967295>
prefix <IP Address>/<Mask Length>
all [restrict {off | on}]
between <Start Mask Length> and <End Mask
Length> [restrict {off | on}]
exact [restrict {off | on}]
refines [restrict {off | on}]

To remove a sequence number from a prefix list

set prefix-list <Name of Prefix List> sequence-number <1-


4294967295> off

To disable a prefix list

set prefix-list <Name of Prefix List> off

R82.10 Gaia Advanced Routing Administration Guide | 649


Prefix Lists and Prefix Trees

Example 1

Configure a prefix list called non-local to restrict prefixes [Link]/16, [Link]/8, and
[Link]/12, but allow all other IPv4 prefixes:

set prefix-list non-local sequence-number 5 prefix [Link]/8


all restrict on
set prefix-list non-local sequence-number 10 prefix
[Link]/16 all restrict on
set prefix-list non-local sequence-number 15 prefix
[Link]/12 all restrict on
set prefix-list non-local sequence-number 20 prefix [Link]/0
all

Example 2

Configure a prefix-list called "no-5-net" to restrict prefix [Link]/8 but allow all other /8
prefixes.
Any other prefixes will not be matched by this list (and therefore will be restricted unless
another prefix list matches them):

set prefix-list no-5-net sequence-number 1 prefix [Link]/8


exact restrict on
set prefix-list no-5-net sequence-number 2 prefix [Link]/0
between 8 and 8

R82.10 Gaia Advanced Routing Administration Guide | 650


Prefix Lists and Prefix Trees

Prefix Tree Syntax


To configure a prefix

set prefix-tree <Name of Prefix Tree>


prefix <IP Address>/<Mask Length>
all [restrict {off | on}]
between <Start Mask Length> and <End Mask Length>
[restrict {off | on}]
exact [restrict {off | on}]
refines [restrict {off | on}]

To remove a prefix from a prefix tree

set prefix-tree <Name of Prefix Tree> prefix <IP Address>/<Mask


Length> off

To disable a prefix tree

set prefix-tree <Name of Prefix Tree> off

Example 1

Configure a prefix tree called non-local to restrict all prefixes with mask lengths, which are
shorter than or equal to /8, [Link]/16, and [Link]/12, but allow all other IPv4
prefixes:

set prefix-tree non-local prefix [Link]/0 between 0 and 8


restrict on
set prefix-tree non-local prefix [Link]/0 between 9 and 32
set prefix-tree non-local prefix [Link]/16 all restrict on
set prefix-tree non-local prefix [Link]/12 all restrict on

Example 2

Configure a prefix tree named "10-net" to allow [Link]/24, restrict all sub-prefixes of
[Link]/16, and allow all sub-prefixes of [Link]/8, except [Link]/8 itself.
Any other prefixes will not be matched by this list (and thus will be restricted unless another
prefix tree matches them):

set prefix-tree 10-net prefix [Link]/8 refines


set prefix-tree 10-net prefix [Link]/16 all restrict
set prefix-tree 10-net prefix [Link]/24 exact

R82.10 Gaia Advanced Routing Administration Guide | 651


Routing Options

Routing Options
This chapter describes routing options that apply to all dynamic routing protocols.

To configure Routing Options in Gaia Portal:


1. From the left navigation tree, click Advanced Routing > Routing Options.
2. Configure the applicable settings.
3. In the Routing Options section (at the top), click Apply.

To discard the unsaved changes in Routing Options in Gaia Portal:

1. From the left navigation tree, click Advanced Routing > Routing Options.
2. Configure the applicable settings.
3. In the Routing Options section (at the top), click Reload.

To restart the Routing Daemon in Gaia Portal:


1. From the left navigation tree, click Advanced Routing > Routing Options.
2. Scroll to the bottom of this page.
3. Click Restart Routing Daemon.

Important - Do not use this button to add or remove routing options. Use the
Apply button located at the top of this page.

To see the Routing Daemon log file in Gaia Portal:


1. From the left navigation tree, click Advanced Routing > Routing Options.
2. In the top right corner, click the Monitoring tab.
3. In the Trace File field, select the applicable file.
4. In the Number of lines field, enter the applicable number of lines to show.
Range: 5-100
Default: 40
5. Click Get Tail.

R82.10 Gaia Advanced Routing Administration Guide | 652


Equal Cost Path Splitting

Equal Cost Path Splitting


You can configure the maximum number of equal-cost paths that will be used when there is
more than one equal-cost path to a destination.
You can specify a value for the maximum number of equal-cost paths to be used when there is
more than one equal-cost path to a destination.
Only OSPF, BGP, and Static routes are able to use paths/routes with more than one
"nexthop".
The "next hop" algorithm that is used for forwarding when there is more than one "next hop" to
a destination is Source/Destination hash.

A hash function is performed on the source and destination IP address of each packet that is
forwarded to a multipath destination.
This result is used to determine which next hop to use.

Important:
n In a Cluster, you must configure all the Cluster Members in the same way.
n If you change the current number of equal cost paths, the routing system
reinstalls all routes. This causes a traffic outage.

Configuring Equal Cost Path Splitting in Gaia Portal


1. From the left navigation tree, click Advanced Routing > Routing Options.

2. In the Equal Cost Multipath section:


a. In the Maximum Paths field, enter the applicable number of equal cost paths.

Range: 1-8
Default: 8
b. In the Path Selection Algorithm field, select the applicable algorithm:
n 2-tuple Hash - Based on the hash of Source and Destination (this is the
default)
n 5-tuple Hash - Based on the hash of Source, Destination, Source Port,
Destination Port, and Protocol
3. In the Routing Options section (at the top), click Apply.

R82.10 Gaia Advanced Routing Administration Guide | 653


Equal Cost Path Splitting

Configuring Equal Cost Path Splitting in Gaia Clish


1. Configure the applicable number of equal cost paths:

set max-path-splits {<1-8> | default}

Range: 1-8
Default: 8
2. Configure the applicable path selection algorithm:

set router-options ecmp-nexthop-selection {2-tuple-hash | 5-


tuple-hash}

n "2-tuple-hash" - Based on the hash of Source and Destination (this is the


default)
n "5-tuple-hash" - Based on the hash of Source, Destination, Source Port,
Destination Port, and Protocol
3. Save the configuration:

save config

4. Examine the configuration:


n To see the configured number of equal cost paths:

Run in Gaia Clish

show configuration max-path-splits

n To see the configured path selection algorithm:


Run in the Expert mode:

cat /proc/sys/net/ipv4/fib_multipath_hash_policy

The returned value:


l 0 means the "2-tuple Hash" is configured
l 1 means the "5-tuple Hash" is configured

R82.10 Gaia Advanced Routing Administration Guide | 654


Kernel Options

Kernel Options
Introduction
Route Injection Mechanism (RIM) enables a Security Gateway to use dynamic routing
protocols to propagate the encryption domain of a VPN peer Security Gateway to the internal
network and then initiate back connections.
When a Security Gateway establishes a VPN tunnel, RIM updates the local routing table of the
Security Gateway to include the encryption domain of the VPN peer.
In Gaia, the Route Injection Mechanism adds routes directly to the kernel.
You must explicitly configure Gaia to keep these routes in the kernel.

For more about configuring RIM, see the R82.10 Site to Site VPN Administration Guide.

Important:
n In a Cluster, you must configure all the Cluster Members in the same way.
n If you configure a Cloning Group and ISP Redundancy on a Security Gateway /
Cluster / Security Group, then you must enable "Kernel Routes".

Configuring Kernel Routes in Gaia Portal

To configure Gaia to keep the RIM routes in kernel:


1. From the left navigation tree, click Advanced Routing > Routing Options.

2. In the Kernel Options section, select the Kernel Routes option.


3. In the Routing Options section (at the top), click Apply.

To configure Gaia not to keep the RIM routes in kernel:


1. From the left navigation tree, click Advanced Routing > Routing Options.
2. In the Kernel Options section, clear the Kernel Routes option.
3. In the Routing Options section (at the top), click Apply.

R82.10 Gaia Advanced Routing Administration Guide | 655


Kernel Options

Configuring Kernel Routes in Gaia Clish

To configure Gaia keep the RIM routes in kernel:


1. Enable the option:

set kernel-routes on

2. Save the configuration:

save config

3. Examine the configuration:

show configuration kernel-routes

To configure Gaia not to keep the RIM routes in kernel:


1. Disable the option:

set kernel-routes off

2. Save the configuration:

save config

3. Examine the configuration:

show configuration kernel-routes

R82.10 Gaia Advanced Routing Administration Guide | 656


Protocol Rank

Protocol Rank
In This Section:

Introduction 657
Default Protocol Ranks 658
Configuring Protocol Rank in Gaia Portal 659
Configuring Protocol Rank in Gaia Clish 659

Introduction
Rank is used by the routing system when there are routes from different protocols to the same
destination.
For each route, the route from the protocol with lowest rank number is used.
The protocol rank is the value that the routing daemon uses to order routes from different
protocols to the same destination.
It is an arbitrarily assigned value used to determine the order of routes to the same destination.
Each route has only one rank associated with it, even though rank can be set at many places in
the configuration.
The route derives its rank from the most specific route match among all configurations.

The active route is the route installed into the kernel forwarding table by the routing daemon.
In the case where the same route is contributed by more than one protocol, the one with the
lowest rank becomes the active route.

Rank cannot be used to control the selection of routes within a dynamic Interior Gateway
Protocol (IGP). This is accomplished automatically by the protocol and is based on the
protocol metric.
Instead, rank is used to select routes from the same Exterior Gateway Protocol (EGP) learned
from different peers or autonomous systems.
Some protocols - BGP and aggregate - allow for routes with the same rank.
To choose the active route in these cases, a separate tie breaker is used. This tie breaker is
called LocalPref for BGP and Weight for aggregates.

R82.10 Gaia Advanced Routing Administration Guide | 657


Protocol Rank

Default Protocol Ranks


A default rank is assigned to each protocol.
Description

Rank values range from 0 to 255.


The lower the number, the more preferred the route.
The default rank values are:

Routes Default Rank

Interface routes 0

IPv4 OSPFv2 routes 10

IPv6 OSPFv3 Routes 10

Static routes 60

IPv4 RIP routes 100

IPv6 RIPng routes 100

Aggregate routes 130

IPv4 BGP routes 170

IPv6 BGP routes 170

IPv4 OSPF AS external routes 150

IPv6 OSPFv3 AS external routes 150

Kernel 200
Important - These numbers do not generally need to be changed from their
defaults. Use caution when modifying the default route ranks. Rank affects the
route selection process, so unexpected consequences may occur throughout the
network. Such a change should be planned carefully and take into account both
the protocols being used and the location of the router in the network.

Important - In a Cluster, you must configure all the Cluster Members in the same way.

R82.10 Gaia Advanced Routing Administration Guide | 658


Protocol Rank

Configuring Protocol Rank in Gaia Portal


Procedure

1. From the left navigation tree, click Advanced Routing > Routing Options.
2. In the Protocol Rank section, enter the rank for the applicable protocol.

Notes:
n Leave the fields empty to use the default ranks.
n To configure the rank of kernel routes, use Gaia Clish.
n To configure the rank of OSPF and OSPF 3, select the applicable

OSPF Instance and click its current value.

3. In the Routing Options section (at the top), click Apply.

Configuring Protocol Rank in Gaia Clish


Syntax

set protocol-rank protocol


bgp ipv4-routes rank {<1-255> | default}
bgp ipv6-routes rank {<1-255> | default}
kernel rank {<1-255> | default}
ospf [instance {<1-65535> | default}] rank {<1-255> |
default}
ospfase [instance {<1-65535> | default}] rank {<1-255> |
default}
ospf3 [instance {<1-65535> | default}] rank {<1-255> |
default}
ospf3ase [instance {<1-65535> | default}] rank {<1-255> |
default}
rip rank {<1-255> | default}
ripng rank {<1-255> | default}
show protocol-rank

Parameters

Parameter Description

bgp ipv4-routes Configures the rank for IPv4 BGP routes.

bgp ipv6-routes Configures the rank for IPv6 BGP routes.

kernel Configures the rank for routes.

R82.10 Gaia Advanced Routing Administration Guide | 659


Protocol Rank

Parameter Description

ospf [instance {<1- Configures the rank for IPv4 OSPFv2 routes (for the
65535> | default}] specified OSPF Instance).

ospfase [instance {<1- Configures the rank for IPv4 OSPFv2 External
65535> | default}] routes (for the specified OSPF Instance).

ospf3 [instance {<1- Configures the rank for IPv6 OSPFv3 routes (for the
65535> | default}] specified OSPF Instance).

ospf3ase [instance {<1- Configures the rank for IPv6 OSPFv3 External
65535> | default}] routes (for the specified OSPF Instance).

rip Configures the rank for IPv4 RIP routes.

ripng Configures the rank for IPv6 RIPng routes.

rank <1-255> Configures the rank of the specified protocol to the


specified number.
The lower the number, the more preferred the route.

rank default Configures the default rank of the specified protocol.

R82.10 Gaia Advanced Routing Administration Guide | 660


Auto Restore of Interface Routes

Auto Restore of Interface Routes


An interface route may be automatically deleted in error from the router kernel when it
becomes reachable from another interface.
The Gaia Clish command "show route shows the route, but the Expert mode command "ip
route" does not show the route.
A scenario, where this can happen, is when the same route is learned through OSPF and
through BGP.
You can configure Gaia to avoid losing the interface routes. By default, this behavior is
disabled.

Note - If the interface route was deleted, and the option was disabled at that time,
then bring down the applicable interface and then bring up the interface. You can
change the state of the interface in Gaia Portal, Gaia Clish

Important - In a Cluster, you must configure all the Cluster Members in the same way.

Configuring "Auto Restore of Interface Routes" in Gaia


Portal

To enable this option in Gaia Portal:


1. From the left navigation tree, click Advanced Routing > Routing Options.

2. In the Advanced Routing Options section, select Auto Restore of Iface Routes.
3. In the Routing Options section (at the top), click Apply.

To disable this option in Gaia Portal:


1. From the left navigation tree, click Advanced Routing > Routing Options.
2. In the Advanced Routing Options section, clear Auto Restore of Iface Routes.
3. In the Routing Options section (at the top), click Apply.

R82.10 Gaia Advanced Routing Administration Guide | 661


Auto Restore of Interface Routes

Configuring "Auto Restore of Interface Routes" in Gaia Clish

To enable this option in Gaia Clish:


1. Enable this option:

set router-options auto-restore-iface-routes on

2. Save the configuration:

save config

3. Examine the configuration:

show router-options

Examine the row Auto Restore Iface Routes.

To disable this option in Gaia Clish:


1. Disable this option:

set router-options auto-restore-iface-routes off

2. Save the configuration:

save config

3. Examine the configuration:

show router-options

Examine the row Auto Restore Iface Routes.

R82.10 Gaia Advanced Routing Administration Guide | 662


Multithreading

Multithreading
You can configure Gaia to run the Routing Daemon in multithreaded mode.
This increases the responsiveness of monitoring operations during heavy traffic load.

Important:
n In a Cluster, you must configure all the Cluster Members in the same way.
n Changing the setting of this option restarts the routing daemon, which causes
traffic outage.

Configuring "Multithreading" in Gaia Portal

To enable this option in Gaia Portal:


1. From the left navigation tree, click Advanced Routing > Routing Options.
2. In the Advanced Routing Options section, select Multithreading.
3. In the Routing Options section (at the top), click Apply.

To disable this option in Gaia Portal:


1. From the left navigation tree, click Advanced Routing > Routing Options.
2. In the Advanced Routing Options section, clear Multithreading.

3. In the Routing Options section (at the top), click Apply.

R82.10 Gaia Advanced Routing Administration Guide | 663


Multithreading

Configuring "Multithreading" in Gaia Clish

To enable this option in Gaia Clish:


1. Enable this option:

set router-options multithreading on

2. Save the configuration:

save config

3. Examine the configuration:

show router-options

Examine the row Multithreading.

To disable this option in Gaia Clish:


1. Disable this option:

set router-options multithreading off

2. Save the configuration:

save config

3. Examine the configuration:

show router-options

Examine the row Multithreading.

R82.10 Gaia Advanced Routing Administration Guide | 664


Active-Active Mode for Routing Daemon

Active-Active Mode for Routing Daemon


Important:
n In VRRP Clusters, you must enable this setting.
n In ClusterXL clusters, you must disable this setting.
n Changing the setting of this option does not restart the routing
daemon.
n In a Cluster, you must configure all the Cluster Members in the
same way.

This option is designed exclusively for VRRP Cluster on Gaia.


When this option is enabled, the routing daemon behaves as if it is operating on a single
Security Gateway.
The routing daemon uses the physical IP addresses of the VRRP Cluster Members for routing
updates, and ignores all the state of ClusterXL and of Firewall.
Only these features are supported:
n Routing (both IPv4 and IPv6): Static Routes, OSPF, and BGP.
n Security: Firewall Software Blade (for symmetric connections only - where the same
VRRP Cluster Member processes the entire connection).

Configuring "Active-Active Mode" in Gaia Portal

To enable this option in Gaia Portal:


1. From the left navigation tree, click Advanced Routing > Routing Options.

2. In the Advanced Routing Options section, select Multithreading.


3. In the Routing Options section (at the top), click Apply.

To disable this option in Gaia Portal:


1. From the left navigation tree, click Advanced Routing > Routing Options.
2. In the Advanced Routing Options section, clear Multithreading.
3. In the Routing Options section (at the top), click Apply.

R82.10 Gaia Advanced Routing Administration Guide | 665


Active-Active Mode for Routing Daemon

Configuring "Active-Active Mode" in Gaia Clish

To enable this option in Gaia Clish:


1. Enable this option:

set router-options active-active-mode on

2. Save the configuration:

save config

3. Examine the configuration:

show router-options

Examine the row Active-Active Mode.

To disable this option in Gaia Clish:


1. Disable this option:

set router-options active-active-mode off

2. Save the configuration:

save config

3. Examine the configuration:

show router-options

Examine the row Active-Active Mode.

R82.10 Gaia Advanced Routing Administration Guide | 666


Routing Process Message Logging Options

Routing Process Message Logging Options


It is possible to configure the RouteD daemon to write its log messages (for example, OSPF or
BGP errors) to one of these log files:

Log File Description

/var/log/routed_ Dedicated file that contains only the RouteD log messages.
messages In Gaia versions R80 and higher, the RouteD writes to this file
by default.

/var/log/messages This file contains log messages from different daemons and
from the operating system.
In Gaia versions R77.30 and lower, the RouteD writes to this
file by default.
Best Practice - Configure the RouteD to write its log
messages to the /var/log/routed_messages file.

Important:
n In a Cluster, you must configure all the Cluster Members in the same way.
n When you change this configuration, it is not necessary to restart the RouteD
daemon, or reboot.

R82.10 Gaia Advanced Routing Administration Guide | 667


Routing Process Message Logging Options

Configuration in the Gaia Portal


Important - On Scalable Platforms, you must connect to the Gaia Portal of the
applicable Security Group.

Step Instructions

1 From the left navigation tree, click Advanced Routing > Routing Options.

2 In the Routing Process Message Logging Options section, select Log


Routed Separately.

3 In the Maximum File Size field, enter the size (in megabytes) for each log file.
The default size is 1 MB.
When the active log file /var/log/routed_messages reaches the
maximum configured size, the Gaia OS rotates it and creates
the new /var/log/routed_messages file.

4 In the Maximum Number of Files field, enter the maximum number of log files
to keep.
The default is to keep 10 log files:
n /var/log/routed_messages
n /var/log/routed_messages.0
n /var/log/routed_messages.1
n ...
n /var/log/routed_messages.9

If the number of all log files reaches the maximum configured number, the Gaia
OS deletes the oldest file, and rotates the existing files.
The file names end with a number suffix. The greater the suffix number, the
older the file.

5 Click Apply.

R82.10 Gaia Advanced Routing Administration Guide | 668


Routing Process Message Logging Options

Configuration in Gaia Clish


Important - On Scalable Platforms, you must run the applicable commands in Gaia
gClish of the applicable Security Group.

Step Instructions

1 Connect to the command line on Gaia.

2 Log in to Gaia Clish.

3 On Scalable Platforms, go to Gaia gClish:


Type gclish and press Enter.

4 Enable the logging of RouteD messages to a dedicated log file:


set routedsyslog on

5 Configure the size (in megabytes) for each log file:


set routedsyslog size <Number of MB between 1 and 2047>
The default size is 1 MB.
When the active log file /var/log/routed_messages reaches the
maximum configured size, the Gaia OS
rotates it and creates the new /var/log/routed_messages file.

6 Configure the maximum number of log files to keep:


set routedsyslog maxnum <Number of Files between 1 and
4294967295>
The default is to keep 10 log files:
n /var/log/routed_messages
n /var/log/routed_messages.0
n /var/log/routed_messages.1
n ...
n /var/log/routed_messages.9

When the number of log files reaches the maximum configured number, the
Gaia OS deletes the oldest log file and rotates the existing log files.
The file names end with a number suffix. The greater the suffix number, the
older the log file.

7 Save the configuration:


save config

R82.10 Gaia Advanced Routing Administration Guide | 669


Routing Process Message Logging Options

How to examine the configuration in CLI

Examine the configuration in Gaia Clish, or the Expert mode.

Shel
Command Expected output
l

Gaia show n If default values were used for "maxnum" and "size":
Clish configura set routedsyslog on
tion
routedsys n If custom values were configured for "maxnum" and
log "size":
set routedsyslog on
set routedsyslog maxnum <Configured_
Value>
set routedsyslog size <Configured_Value>

Exp grep n If default values were used for "maxnum" and "size":
ert routedsys routed:instance:default:routedsyslog t
mod log
e /config/a n If custom values were configured for "maxnum" and
ctive "size":
routed:instance:default:routedsyslog t

routed:instance:default:routedsyslog:siz
e <Configured_Value>

routed:instance:default:routedsyslog:fil
es <Configured_Value>

Important:
n On Scalable Platforms, you must run the applicable commands in Gaia
gClish of the applicable Security Group.
n On Scalable Platforms, you must run the applicable commands in the Expert
mode on the applicable Security Group.

RFC 1403 Compatibility


You can configure Gaia to run the OSPFv2 and OSPFv3 instances in a mode that is
compatible with RFC 1403.

R82.10 Gaia Advanced Routing Administration Guide | 670


Routing Process Message Logging Options

Important:
n There is no such option in Gaia Portal.
n In a Cluster, you must configure all the Cluster Members in the same way.
n Changing the setting of this option restarts all OSPFv2 and OSPFv3 instances,
which causes traffic outage.

Configuring "RFC 1403 Compatibility" in Gaia Clish


To enable this option in Gaia Clish:
1. Enable this option:

set router-options rfc1403compatibility on

2. Save the configuration:

save config

3. Examine the configuration:

show router-options

Examine the row RFC 1403 Compatibility.


To disable this option in Gaia Clish:
1. Disable this option:

set router-options rfc1403compatibility off

2. Save the configuration:

save config

3. Examine the configuration:

show router-options

Examine the row RFC 1403 Compatibility.

R82.10 Gaia Advanced Routing Administration Guide | 671


Trace Options

Trace Options
In This Section:

Configuring Trace Options in Gaia Portal 673


Configuring Trace Options in Gaia Clish 675
Description of Trace Options 678

The routing system can optionally log information about errors and events.
Logging is configured for each protocol or globally.

Logging is not generally enabled during normal operations, because it can decrease
performance.
Log messages are saved in the /var/log/[Link].* files.
For detailed example instructions, see these procedures:
n sk84520: How to debug OSPF and RouteD daemon on Gaia
n sk101399: How to debug BGP and RouteD daemon on Gaia
n sk92598: How to debug PIM and Multicast on Gaia

R82.10 Gaia Advanced Routing Administration Guide | 672


Trace Options

Configuring Trace Options in Gaia Portal


To configure the trace options

1. From the left navigation tree, click Advanced Routing > Routing Options.
2. Click the Configuration tab.
3. In the Trace Options section, configure:
n Maximum Trace File Size - Enter a value between 1 to 2047 MB (the default is
1 MB).

Note - When the active file reaches this size, Gaia rotates it - renames
the active file to /var/log/[Link].<N> and creates a new
active file. The cycle repeats until the total number of these log files
reaches the configured number.
n Number of Trace Files - Enter a number between 1 to 4294967295 (the default
is 10). The is the total number of the log files /var/log/[Link].* to
keep. When the total number of these log files reaches the configured number,
Gaia deletes the oldest file.
n Filter Visible Tables Below - Select which trace tables to show below. By
default, Gaia Portal shows all available tables (Show All).
n For each applicable set of trace options:
a. In the applicable trace table, select the applicable options.

To select multiple options, press and hold down the Shift key while you
click the options.
b. Above the trace table, click Add.

The trace table shows Enabled for the selected options.

Important:
l In the trace table Global, you can enable the tracing of a specific

routing option for all protocols. For example, enable the tracing of
Cluster option.
l In the trace table Global, you can enable the tracing of all routing

options for all protocols. Select the option All.

4. In the Routing Options section (at the top), click Apply.


5. Replicate the issue.
6. Disable the traces.
7. Examine these log files:

R82.10 Gaia Advanced Routing Administration Guide | 673


Trace Options

a. /var/log/[Link]*
b. /var/log/routed_messages*

To monitor the trace logs

1. From the left navigation tree, click Advanced Routing > Routing Options.
2. In the top right corner, click the Monitoring tab.
3. In the Trace File field, select the /var/log/[Link] file.
4. In the Number of lines field, enter the applicable number of lines to show.
Range: 5-100
Default: 40

5. Click Get Tail.

R82.10 Gaia Advanced Routing Administration Guide | 674


Trace Options

Configuring Trace Options in Gaia Clish


To configure the trace options

1. Configure the size (in Megabytes) of the active log file:

set tracefile size {<1-2047> | default}

2. Configure the maximum number of log files to keep:

set tracefile maxnum {<1-4294967295> | default}

3. Configure the applicable trace options:

R82.10 Gaia Advanced Routing Administration Guide | 675


Trace Options

set trace
bfd <Trace Option> {off | on}
bgp <Trace Option> {off | on}
bootp <Trace Option> {off | on}
cluster <Trace Option> {off | on}
dhcp6relay <Trace Option> {off | on}
global <Trace Option> {off | on}
icmp <Trace Option> {off | on}
igmp <Trace Option> {off | on}
ip-reachability-detection <Trace Option> {off | on}
iphelper <Trace Option> {off | on}
ipsec-routing <Trace Option> {off | on}
isis <Trace Option> {off | on}
kernel <Trace Option> {off | on}
mfc <Trace Option> {off | on}
mfc-static <Trace Option> {off | on}
mfc6 <Trace Option> {off | on}
mld <Trace Option> {off | on}
ospf <Trace Option> {off | on}
ospf3 <Trace Option> {off | on}
pbr <Trace Option> {off | on}
pim <Trace Option> {off | on}
pim6 <Trace Option> {off | on}
rip <Trace Option> {off | on}
ripng <Trace Option> {off | on}
router-discovery <Trace Option> {off | on}
router-discovery6 <Trace Option> {off | on}
routing-event-trigger <Trace Option> {off | on}
static-route <Trace Option> {off | on}
vrrp <Trace Option> {off | on}
vrrp6 <Trace Option> {off | on}
Note - To configure several trace options in the specified category, you must
run the command once for every trace option in the specified category.
For example:
set trace ospf hello on
set trace ospf lsa on

4. Save the configuration:

save config

5. Replicate the issue.


6. Disable the traces.

R82.10 Gaia Advanced Routing Administration Guide | 676


Trace Options

7. Examine these log files:


a. /var/log/[Link]*
b. /var/log/routed_messages*

Parameters

Parameter Description

size {<1-2047> Configures the size (in Megabytes) of the


| default} /var/log/[Link] log file.
When the active file reaches this size, Gaia rotates it - renames
the active file to /var/log/[Link].<N> and creates a
new active file.
Default: 1 MB

maxnum {<1- Configures the total number of the log files


4294967295> | /var/log/[Link].* to keep.
default} When the total number of these log files reaches the configured
number, Gaia deletes the oldest file.
Default: 10

<Trace Option> Disables (off) or enables (on) the specific trace option in the
{off | on} specified category.
To configure all available options in the specified category, enter
all.

global <Trace Disables (off) or enables (on) the specific trace option in all
Option> {off | categories.
on} To configure all available options in all categories, enter all.

R82.10 Gaia Advanced Routing Administration Guide | 677


Trace Options

Description of Trace Options


List of options

Trace Option Description

ack Trace the Link State acknowledgment packets in this category.

address Trace the IP address messages in this category.

adv Trace the allocation of and freeing of policy blocks in this category.

advertise Trace the "Advertise" messages in this category.

alerts Trace the alert callback events in this category.

all Trace all the routing events in this category.

assert Trace the "Assert" messages in this category.

auth Trace the authentication messages in this category.

bootstrap Trace the bootstrap messages in this category.

cache Trace the cache maintenance log details:


n addition or deletion of orphan entries (entries with no route to
source)
n addition or deletion of normal entries
n cache state aging and refresh entries

cluster Trace the cluster-specific events in this category.

crp Trace the Candidate Rendezvous Point advertisements in this


category.

dd Trace the database description packets in this category.

dr Trace the designated router packets in this category.

error Trace the ICMP "Error" packets:


n time exceeded
n parameter problem
n unreachable
n source quench

general Trace the events related to "normal" and "route" options in this
category.

R82.10 Gaia Advanced Routing Administration Guide | 678


Trace Options

Trace Option Description

graft Trace the "Graft" and "Graft Acknowledgment" packets in this category.

group Trace the multicast group "Add", "Delete", "Refresh", and "Accelerated
Leave" events in this category.

hello Trace the "Hello" packets in this category.

iflist Trace the interface list scans in this category.

info Trace the ICMP "Informational" packets:


n mask request/response
n info request/response
n echo request/response
n time stamp request/response

interface Trace the interface-specific messages in this category.

join Trace the "Join"/"Prune" messages in this category.

keepalive Trace the BGP keepalive messages to this peer.


These messages are used to verify peer reachability.

leave Trace the "Leave Group" messages in this category.

lsa Trace the Link State Advertisement packets in this category.

mcastdist Trace the multicast distribution, register encapsulation, and


decapsulation messages in this category.

mfc Trace calls to or from the Multicast Forwarding Cache in this category.

mrt Trace the multicast routing table events in this category.

mtrace Trace the multicast traceroute events in this category.

normal Trace all the normal protocol occurrences.


Abnormal protocol occurrences are always traced.

open Trace the BGP "Open" messages to this peer (used to establish a peer
connection).

packets Trace all packets in this category.

parse Trace the lexical analyzer and parser events in this category.

R82.10 Gaia Advanced Routing Administration Guide | 679


Trace Options

Trace Option Description

policy Trace the application of protocol-specified and user-specified policy to


imported and exported routes.

process Trace the Routing Event Trigger decision program in a process.

query Trace the multicast group membership "Query" packets (both general
and group-specific) in this category.

refresh Trace the PIM state "Refresh" messages.

register Trace the "Register" and "Register-Stop" packets in this category.

remnants Trace the kernel routes at the time when the routing daemon starts.

reply Trace all "Reply" packets in this category.

report Trace the multicast group membership "Report" packets in this


category.

request Trace all "Request" packets in this category.

resolve Trace the resolve requests in this category.

response Trace all "Response" packets in this category.

route Trace the routing table changes in this category.

router- Trace the "Router Discovery" packets in this category.


discovery

routes Trace operations on routes - add, delete, change.

rp Trace Rendezvous Point -specific events, including RP "set-


specific" and "bootstrap-specific" events.

rule Trace the rule messages in this category.

spf Trace the shortest-path-first (SPF) calculation events in this category.

state Trace the state machine transitions in the protocols in this category.

table Trace the table messages in this category.

task Trace the system interface and processing events in this category.

timer Trace the timer usage events in this category.

R82.10 Gaia Advanced Routing Administration Guide | 680


Trace Options

Trace Option Description

trap Trace the trap packets in this category.

update OSPF - Trace the Link State update packets.


BGP - Trace the "Update" messages to this peer (used to pass network
reachability information).

wrongif Trace the kernel multicast incoming physical interface and register
violation notifications in this category.

R82.10 Gaia Advanced Routing Administration Guide | 681


Routing Event Triggers

Routing Event Triggers


Overview
Routing Event Trigger configures:
1. Monitored items (BGP neighborship, IP Reachability Detection status).
2. Actions to perform, when the required state of the monitored items fails (tear the BGP
neighborship, change the cluster state).
3. Decisions when to perform the actions.

Configuring Routing Event Triggers in Gaia


Clish
Configuration of each Routing Event Trigger instance includes:
1. A name (specified with the "instance" parameter).
2. Zero or more monitored items (specified with the "monitor" sub-command).
The state of the monitored items, as processed by the decision program ("trigger"),
determines whether to perform the configured actions.

3. Zero or more actions to perform when the decision program decides to do so (specified
with the "do" sub-command).
4. A decision program (specified with the "trigger" sub-command).

The decision program determines when to perform the configured actions.

R82.10 Gaia Advanced Routing Administration Guide | 682


Routing Event Triggers

Syntax to configure a Routing Event Trigger instance:

set routing-event-trigger instance <Name of Instance>


do
fail-bgp-peer <BGP Peer> {on | off}
fail-clusterxl-member {local | <IPv4 address>}
hold-down {on | off}
{on | off}
monitor
bgp-peer-established <IPv4 or IPv6 of BGP Peer> {on |
off}
ip-reachability-detection <IPv4 or IPv6 Address> {on |
off}
off
trigger
/usr/libexec/routing_evt/routing_evt_all
/usr/libexec/routing_evt/routing_evt_any
/usr/libexec/routing_evt/routing_evt_maj
/usr/libexec/routing_evt/routing_evt_never
hold-down reset

Syntax to view the Routing Event Trigger history:

show routing-event-trigger
instance <Name of Instance> [detailed-history]
instances [detailed-history]

Parameters

Parameter Description

instance <Name of Specifies the name of the routing event trigger instance.
Instance> Notes:
n The length of this string must be between 1-16
characters.
n This string must contain only these characters:
l lowercase letters (a-z)
l digits (0-9)

l minus (-)

l underscore (_)

l period (.)

R82.10 Gaia Advanced Routing Administration Guide | 683


Routing Event Triggers

Parameter Description

do fail-bgp-peer <BGP Specifies the action to fail the BGP neighborship with BGP
Peer> {on | off} peers (even if it would otherwise be "Established").
n on - Adds this action to the instance configuration.
n off - Removes this action from the instance
configuration.

do fail-clusterxl- Specifies the action to fail the ClusterXL state - to change it


member {local | <IPv4 to "Down".
address>} {on | off} Values:
n local - Specifies that the cluster state must change
on this Cluster Member.
n <IPv4 address> - Specifies that the cluster state
must change on the peer Cluster Member with the
specified IPv4 address (use the IP address of the
Cluster Member object).
n on - Adds this action to the instance configuration.
n off - Removes this action from the instance
configuration.
When the cluster state of a Cluster Member changes to
"Down", a cluster failover occurs:
n If this Cluster Member was Active in the High
Availability mode.
n If this Cluster Member was Pivot in the Load Sharing
Unicast mode.
When the triggering condition does not exist anymore,
cluster fallback occurs based on the configuration in the
cluster object on the page ClusterXL and VRRP:
n In the High Availability mode - based on the setting
"Upon cluster member recovery".
n In the Load Sharing Unicast mode - based on the
priority of Cluster Members in the cluster object on
the page Cluster Members.

Note - This action does not support VRRP Clusters.

R82.10 Gaia Advanced Routing Administration Guide | 684


Routing Event Triggers

Parameter Description

do ... hold-down {on Specifies to keep doing the triggered action, even after the
| off} conditions which triggered it do not exist anymore.
Important - To cancel this, you must run this
command:
set routing-event-trigger hold-down
reset
Range: off, on
Default: off

monitor bgp-peer- Monitors the state of BGP with a single BGP peer.
established <IPv4 or This monitor reacts to changes in the BGP neighborship
IPv6 of BGP Peer> {on state "Established" .
| off} This monitor condition becomes "true" if at least one of
these occurs:
n BGP neighborship with the BGP peer reached the
"Established" state.
n BGP neighborship with the BGP peer never reached
the "Established" state since the dynamic routing
startup.
n ClusterXL failover occurs.

monitor ip- Monitors the state of "IP Reachability Detection" (BFD or


reachability- ping) with the specified remote IP address (see "IP
detection <IPv4 or Reachability Detection" on page 243).
IPv6 Address> {on | This monitor reacts to changes in the "reachable" state.
off} This monitor condition becomes "true" if at least one of
these occurs:
n Remote IP address becomes reachable.
n Remote IP address was never reachable since the
Gaia startup.
n ClusterXL failover occurs.

off Removes this routing event trigger instance.

R82.10 Gaia Advanced Routing Administration Guide | 685


Routing Event Triggers

Parameter Description

trigger <Triger> Specifies the trigger - the "decision program" in this


"routing-event-trigger" instance.
The decision program determines whether to perform the
configured action or not.
Available decision programs:
n /usr/libexec/routing_evt/routing_evt_
all
Perform the action if all monitored items fail.
n /usr/libexec/routing_evt/routing_evt_
any
Perform the action if any of the monitored items fail.
n /usr/libexec/routing_evt/routing_evt_
maj
Perform the action if a majority of the monitored items
fail.
n /usr/libexec/routing_evt/routing_evt_
never
Do not perform the action.

hold-down reset Cancels the "hold down" status for the triggered action.

Monitoring Routing Event Triggers in Gaia


Portal
1. From the left tree, in the Advanced Routing section, click Routing Event Trigger.

2. In the top right corner, click Monitoring.


3. In the Information section, click the applicable option to see all, or specific information:
n All data
n Monitored
n Actions
n Trigger runs

R82.10 Gaia Advanced Routing Administration Guide | 686


Router Discovery

Router Discovery
The ICMP Router Discovery protocol is an IETF standard protocol that allows hosts running an
ICMP router discovery client to learn dynamically about the presence of a viable default router
on a LAN.
It is intended to be used instead of having hosts wiretap routing protocols such as RIP.
It is used in place of, or in addition to, statically configured default routes in hosts.

Note - Only the server portion of the Router Discovery Protocol is supported.

Gaia implements only the ICMP router discovery server portion, which means that a Check
Point router can advertise itself as a candidate default router, but it will not adopt a default
router using the router discovery protocol.
The ICMP Router Discovery Service provides a mechanism for hosts attached to a multicast or
broadcast network to discover the IP addresses of their neighboring routers.
This section describes how you can configure a router to advertise its addresses by using
ICMP Router Discovery.

How Router Discovery Works


The router discovery server runs on routers and announces their existence to hosts. It does
this by periodically multicasting or broadcasting a router advertisement to each interface on
which it is enabled. These advertisements contain a list of all the router addresses on a given
interface and their preference for use as a default router.
Initially, these router advertisements occur every few seconds. They then fall back to every few
minutes. In addition, a host can send a router solicitation, to which the router responds with a
unicast router advertisement. However, if a multicast or broadcast advertisement is due in a
moment, the router does not respond with a unicast advertisement.
Each router advertisement contains an advertisement lifetime field indicating the length of time
that the advertised addresses are valid. This lifetime is configured such that another router
advertisement is sent before the lifetime expires. A lifetime of zero (0) indicates that one or
more addresses are no longer valid.
On systems that support IP multicasting, the router advertisements are sent by default to the
all-hosts multicast address [Link]. However, you can specify the use of broadcast. All IP
addresses configured on the physical interface are included in the router advertisement when:
n Router advertisements are sent to the all-hosts multicast address,
or
n An interface is configured for the limited-broadcast address [Link].

R82.10 Gaia Advanced Routing Administration Guide | 687


Router Discovery

When the router advertisements are sent to a net or subnet broadcast, only the address
associated with that net or subnet is included.

R82.10 Gaia Advanced Routing Administration Guide | 688


Configuring Router Discovery in Gaia Portal

Configuring Router Discovery in Gaia Portal


Important - In a Cluster, you must configure all the Cluster Members in the same way.

To enable router discovery services:


1. From the left navigation tree, click Advanced Routing > Router Discovery.
2. In the Router Discovery section, click Add.
3. In the Interface field, select the interface, on which to enable Router Discovery.
4. Optional: In the Min. Advertise Interval field, configure the applicable value.
Description

Configures the minimum time between sending ICMP Router Discovery


advertisements on the interface.
This value cannot be larger than the configured Max. Advertise Interval.
Range: 3-1799 seconds
Default: 0.75 * (Value of Max. Advertise Interval) seconds

5. Optional: In the Max. Advertise Interval field, configure the applicable value.
Description

Configures the maximum time between sending ICMP Router Discovery


advertisements on the interface.

This value cannot be less than the configured Min. Advertise Interval.
Range: 4-1800 seconds
Default: 600 seconds

6. Optional: In the Advertisement Lifetime field, configure the applicable value.


Description

Configures how long an advertised address remains valid in the absence of an update
message.
This value must not be less than the configured Max. Advertise Interval.
The configured value is placed in the "Lifetime" field of Route Advertisement
messages sent on this interface.

R82.10 Gaia Advanced Routing Administration Guide | 689


Configuring Router Discovery in Gaia Portal

Range: 5-9000 seconds


Default: 3 * (Value of Max. Advertise Interval) seconds

7. Optional: In the Advertise Addresses section, configure how to advertise the IP


addresses on this interface.
Description
a. Select the IP address and click Edit.
b. The Advertise option controls whether to enable or disable the advertising of the
configured IP address for this interface.
c. The Eligibility option controls whether to use the configured IP address as a
default IP address.

Range: Eligible (use the configured IP address as a default IP address), or


Ineligible (do not use the configured IP address as a default IP address)
Default: Eligible
d. The Preference value controls the preference of the address as a default router
IP address, relative to other router IP addresses on the same subnet.
Higher numeric values indicate greater preference.
Range: 0-2147483647
Default: 0
For more information, see the PreferenceLevel in RFC 1256.

e. Click OK.

8. Click Save.

To disable router discovery service on an interface:


1. From the left navigation tree, click Advanced Routing > Router Discovery.
2. In the Router Discovery section, select the interface.
3. Click Delete.

Note - There is no prompt to confirm.

4. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 690


Configuring Router Discovery in Gaia Clish

Configuring Router Discovery in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

n To see the available "set" commands for Router Discovery, enter in Gaia Clish:

set rdisc[Esc][Esc]

n To see the available "show" commands for Router Discovery, enter in Gaia Clish:

show rdisc[Esc][Esc]

Syntax

set rdisc interface <Name of Interface>


{off | on}
adv-lifetime {<Lifetime> | default}
advertise <IP Address>
{off | on}
preference {<0-2147483647> | ineligible}
max-adv-interval {<4-1800> | default}
min-adv-interval {<3-1799> | default}

Parameters

Parameter Description

{off | on} Disables (off) or enables (on) the ICMP Router Discovery
on the interface.

adv-lifetime Optional.
{<Lifetime > | Configures how long an advertised address remains valid in
default} the absence of an update message.
This value must not be less than the configured max-adv-
interval.
The configured value is placed in the "Lifetime" field of Route
Advertisement messages sent on this interface.
Range: 5-9000 seconds
Default: 3 x (Value of max-adv-interval) seconds

R82.10 Gaia Advanced Routing Administration Guide | 691


Configuring Router Discovery in Gaia Clish

Parameter Description

advertise <IP Specifies whether this interface IP address should be


Address> advertised in ICMP Router Discovery advertisement
messages.
The specified IP address must be a valid interface IP address
for the interface.
Notes:
n If you change the IP address assigned to this
interface, you must use this command to update
the ICMP Router Discovery configuration on the
interface. Otherwise, ICMP Router Discovery is
disabled for the interface.
n You must configure at least one valid interface IP
address. Otherwise, ICMP Router Discovery is
disabled for the interface.
n By default, all IPv4 addresses associated with the
interface are advertised.

advertise <IP Disables (off) or enables (on) the advertising of the


Address> {off | specified IP address for the interface.
on}

preference {<0- Optional.


2147483647> | Configures the preference of the address as a default router
ineligible} IP address, relative to other router IP addresses on the same
subnet.
Higher numeric values indicate greater preference.
Range: 0-2147483647, or ineligible (indicates that the IP
address should not be used as a default IP address)
Default: 0
For more information, see the PreferenceLevel in RFC 1256.

max-adv-interval Optional.
{<4-1800> | Configures the maximum time between sending ICMP
default} Router Discovery advertisements on the interface.
This value cannot be less than the configured min-adv-
interval.
Range: 4-1800 seconds
Default: 600 seconds

R82.10 Gaia Advanced Routing Administration Guide | 692


Configuring Router Discovery in Gaia Clish

Parameter Description

min-adv-interval Optional.
{<3-1799> | Configures the minimum time between sending ICMP Router
default} Discovery advertisements on the interface.
This value cannot be larger than the configured max-adv-
interval.
Range: 3-1799 seconds
Default: 0.75 x (Value of max-adv-interval) seconds

R82.10 Gaia Advanced Routing Administration Guide | 693


Monitoring Router Discovery

Monitoring Router Discovery


Monitoring Router Discovery in Gaia Portal
1. From the left navigation tree, click Advanced Routing > Router Discovery.
2. In the top right corner, click Monitoring.

Note - The page is static. To see the latest values, click Reload.

Monitoring Router Discovery in Gaia Clish

show rdisc[Esc][Esc]

Troubleshooting Router Discovery


See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 694


IPv6 Router Discovery

IPv6 Router Discovery


ICMPv6 Router Discovery Protocol is an IETF standard protocol.
It lets hosts running an ICMPv6 router discovery client:
n Dynamically find other IPv6 nodes.
n Find available routers and Domain Name System (DNS) servers.
n Learn prefixes and configuration parameters related to address configuration.
n Autoconfigure addresses and make relationships between link layer addresses and IPv6
addresses of other nodes.
n Find out if a neighbor is reachable and maintaining paths to other active neighbor nodes.
n Find duplicated addresses.
Gaia acts as an ICMPv6 router discovery server. It can advertise itself as a candidate default
router, but it will not make a router its default router using the IPv6 Router Discovery protocol.

IPv6 Router Discovery and VRRP


To support VRRP for IPv6 interfaces, only the router in a VRRP Master state sends router
discovery advertisements.
The VRRP Master sends the advertisements with the Virtual IP address as the source address
and the Virtual MAC address as the MAC address.

Routers in VRRP Backup state do not send router discovery advertisements.


When VRRP failover occurs, the new VRRP Master begins to send out router discovery
advertisements.

R82.10 Gaia Advanced Routing Administration Guide | 695


Configuring IPv6 Discovery in Gaia Portal

Configuring IPv6 Discovery in Gaia Portal


Important - In a Cluster, you must configure all the Cluster Members in the same way.

To enable router discovery services:


1. From the left navigation tree, click Advanced Routing > IPv6 Router Discovery.
2. In the Router Discovery section, click Add.
3. In the Interface field, select the interface, on which to enable Router Discovery.
4. Optional: In the Min. Advertise Interval field, configure the applicable value.
Description

Configures the minimum time allowed between sending unsolicited multicast ICMPv6
Router Advertisements on this interface.
Unsolicited Router Advertisements are not strictly periodic.
The interval between two advertisements is randomized to decrease the probability of
synchronization with the advertisements from other routers on the same links.
When an unsolicited advertisement is sent, the timer is reset to a random value
between the Min. Advertise Interval and the Max. Advertise Interval.
Range: 3-1799 seconds

Default: (Value of Max. Advertise Interval) / 3 seconds

5. Optional: In the Max. Advertise Interval field, configure the applicable value.
Description

Configures the maximum time allowed between sending unsolicited multicast ICMPv6
Router Advertisements on this interface.
Unsolicited Router Advertisements are not strictly periodic.
The interval between two advertisements is randomized to decrease the probability of
synchronization with the advertisements from other routers on the same links.
When an unsolicited advertisement is sent, the timer is reset to a random value
between the Min. Advertise Interval and the Max. Advertise Interval.
Range: 4-1800 seconds
Default: 600 seconds

6. Optional: In the Advertisement Lifetime field, configure the applicable value.

R82.10 Gaia Advanced Routing Administration Guide | 696


Configuring IPv6 Discovery in Gaia Portal

Description

Configures how long from receipt of a Router Advertisement message that a host
considers this router to be valid.
If the router lifetime expires with no refreshing Router Advertisement, the host stops
using this router.
The value is placed in the Router Lifetime field of the Router Advertisement message.
A value of 0 means that the router is not used as a default router.
Range: from Max. Advertise Interval to 9000 seconds, or 0 seconds
Default: 3 * (Value of Max. Advertise Interval) seconds

7. Optional: In the Reachable Timer field, configure the applicable value.


Description

Configures how long a node assumes a neighbor is reachable after having received a
reachability confirmation.
This value is used by the Neighbor Unreachability Detection.
The reachable time is placed in the Reachable Time field in the Router Advertisement
message.
The value 0 means it is unspecified by this router.
Range: 0-3600000 seconds

Default: 0 seconds

8. Optional: In the Retransmission Timer field, configure the applicable value.


Description

Configures the interval between retransmitted Neighbor Solicitation messages if the


node does not receive a response.
This value is used by address resolution and Neighbor Unreachability Detection.
The retransmit timer is placed in the Retrans Timer field in the Router Advertisement
message.
The value 0 means it is unspecified by this router.
Range: 0-2147483647 seconds
Default: 0 seconds

9. Optional: In the Hop Limit field, configure the applicable value.

R82.10 Gaia Advanced Routing Administration Guide | 697


Configuring IPv6 Discovery in Gaia Portal

Description

Configures the Cur Hop Limit field of the Router Advertisement message.
This value is used by neighboring nodes as the Hop Count field of the IP header in
outgoing IP packets.
The value of 0 means it is unspecified by this router.
Range: 0-255
Default: 64

10. Optional: The Managed Config option controls whether to perform stateful IP address
autoconfiguration.
Description

Specifies whether to obtain global IPv6 addresses through DHCPv6 (as opposed to
stateless address autoconfiguration provided by ICMPv6 Router Discovery).
This option is placed in the Managed address configuration flag in the Router
Advertisement message.
Range: Selected, or Cleared
Default: Cleared

11. Optional: The Other Config Flag option controls whether to perform stateful
autoconfiguration to obtain other configuration information besides IP addresses.
Description

Stateful autoconfiguration is provided by DHCPv6, as opposed to stateless


autoconfiguration provided by ICMPv6 Router Discovery.

Examples of such information include information related to DNS, or information on


other servers within the network.
This option is placed in the Other configuration flag in the Router Advertisement
message.
Range: Selected, or Cleared
Default: Cleared

12. Optional: The Send MTU option controls whether to include MTU options.
Description

If this option is enabled, Router Advertisement messages (sent to neighboring nodes)


include MTU options.

R82.10 Gaia Advanced Routing Administration Guide | 698


Configuring IPv6 Discovery in Gaia Portal

Range: Selected, or Cleared


Default: Cleared

13. Optional: In the Advertise Addresses section, configure how to advertise the IP
addresses on this interface.
Description
a. Select the IP address and click Edit.
b. The Enable On-Link option controls whether this IPv6 address prefix is
available on the link.
This is necessary because it is possible to have multiple prefix combinations on
the same subnet in IPv6.

Range: Selected, or Cleared


Default: Selected
c. The Enable Autonomous Address Configuration: option controls whether the
given address prefix can be used by ICMPv6 Router Discovery clients for
autonomous address configuration.
Range: Selected, or Cleared
Default: Selected
d. The Valid Lifetime option controls how long the specified prefix is valid for on-
link determination.

This value is placed in the Valid Lifetime field in the Prefix Information option.
This value must not be less than the configured Preferred Lifetime.
The designated value of 4294967295 represents infinity.

Range: 0-4294967295 seconds


Default: 2592000 seconds (30 days)

R82.10 Gaia Advanced Routing Administration Guide | 699


Configuring IPv6 Discovery in Gaia Portal

e. The Preferred Lifetime value controls the preferred lifetime of the specified IPv6
address prefix.
This value is placed in the Preferred Lifetime field in the Prefix Information
option in Router Advertisements.
It conveys how long IPv6 addresses generated from the specified IPv6 address
prefix through stateless address autoconfiguration should stay preferred.
(Stateless address autoconfiguration is the mechanism used by ICMPv6 Router
Discovery protocol, as opposed to stateful address autoconfiguration provided
by DHCPv6.) That means the node can use the IPv6 address in existing
connections, but it is not valid for new connections.
This value must not be greater than the configured Valid Lifetime.
For more information, see RFC 4862.

The designated value of 4294967295 represents infinity.


Range: 0-4294967295 seconds
Default: 604800 seconds (7 days)
f. Click OK.

14. Optional: In the Advertise DNS Information section, configure options for recursive
DNS server advertising and for DNS domain hostname advertising.
To configure options for recursive DNS server advertising
a. Click Add and select Server.

b. In the DNS field, enter the applicable IPv6 network address.


c. In the DNS Lifetime field, configure how long hosts should store this recursive
DNS server.

Range: from (Max. Advertise Interval) to (2 x Max. Advertise Interval) seconds


Default: 1.5 * Max. Advertise Interval seconds
d. Click OK.

To configure options for recursive DNS domain hostname advertising


a. Click Add and select Hostname.
b. In the DNS field, enter the applicable fully qualified DNS hostname.

R82.10 Gaia Advanced Routing Administration Guide | 700


Configuring IPv6 Discovery in Gaia Portal

c. In the DNS Lifetime field, configure how long hosts should store this DNS
hostname.
Range: from (Max. Advertise Interval) to (2 x Max. Advertise Interval) seconds
Default: 1.5 * Max. Advertise Interval seconds
d. Click OK.

Note - If you add or edit a DNS entry to have the same value as an existing
entry, the new configuration overwrites the existing entry.

15. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 701


Configuring IPv6 Discovery in Gaia Clish

Configuring IPv6 Discovery in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

n To see the available "set" commands for IPv6 Discovery, enter in Gaia Clish:

set ipv6 rdisc6[Esc][Esc]

n To see the available "show" commands for IPv6 Discovery, enter in Gaia Clish:

show ipv6 rdisc6[Esc][Esc]

Syntax

set ipv6 rdisc6 interface <Name of Interface>


address <IPv6 address>
autonomous {off | on}
default
on-link {off | on}
prefix-pref-lifetime {<0-4294967295> | default}
prefix-valid-lifetime {<0-4294967295> | default}
dnshost <FQDN>
{off | on}
dnshost-lifetime {<0-2147483647> | default}
dnsserver <IPv6 Network Address>
{off | on}
dnsserver-lifetime {<0-2147483647> | default}
hop-limit {<0-255> | default}
managed-config {off | on}
max-adv-interval {<4-1800> | default}
min-adv-interval {<3-1799> | default}
{off | on}
other-config {off | on}
reachable-time {<0-3600000> | default}
retransmit-timer {<0-2147483647> | default}
router-lifetime {<0-2147483647> | default}
send-mtu {off | on}

R82.10 Gaia Advanced Routing Administration Guide | 702


Configuring IPv6 Discovery in Gaia Clish

Parameters

Parameter Description

interface Specifies the name of the interface, on which to run IPv6 Router
<Name of Discovery.
Interface>

interface Disables (off) or enables (on) the ICMPv6 Router Discovery on the
<Name of specified interface.
Interface> Range: off, or on
{off | on} Default: on

address Optional.
<IPv6 Configures the IPv6 address prefix, for which to configure
address> advertisement options.

address Disables (off) or enables (on) the use of the specified address
<IPv6 prefix by ICMPv6 Router Discovery clients for autonomous address
address> configuration.
autonomous Range: off, or on
{off | on} Default: on

address Resets IPv6 Router Discovery configuration for the specified


<IPv6 address to default.
address> This can be useful when interface addresses have changed,
default because it removes all configuration for the specified address from
the database.

address Disables (off) or enables (on) the specified IPv6 address prefix on
<IPv6 the link.
address> on- Range: off, or on
link {off | Default: on
on}

R82.10 Gaia Advanced Routing Administration Guide | 703


Configuring IPv6 Discovery in Gaia Clish

Parameter Description

address Configures the preferred lifetime of the specified IPv6 address prefix.
<IPv6 This value is placed in the Preferred Lifetime field in the Prefix
address> Information option in Router Advertisements.
prefix-pref- It conveys how long IPv6 addresses generated from the specified
lifetime IPv6 address prefix through stateless address autoconfiguration
{<0- should stay preferred. (Stateless address autoconfiguration is the
4294967295> mechanism used by ICMPv6 Router Discovery protocol, as opposed
| default} to stateful address autoconfiguration provided by DHCPv6.) That
means the node can use the IPv6 address in existing connections,
but it is not valid for new connections.
This value must not be greater than the configured prefix-valid-
lifetime.
For more information, see RFC 4862.
The designated value of 4294967295 represents infinity.
Range: 0-4294967295 seconds
Default: 604800 seconds (7 days)

address Configures the lifetime of the specified IPv6 address prefix for on-link
<IPv6 determination.
address> This value is placed in the Valid Lifetime field in the Prefix
prefix- Information option.
valid- This value must not be less than the configured prefix-pref-
lifetime lifetime.
{<0- The designated value of 4294967295 represents infinity.
4294967295> Range: 0-4294967295 seconds
| default} Default: 2592000 seconds (30 days)

dnshost Optional.
<FQDN> {off Disables (off) or enables (on) the recursive DNS domain hostname
| on} advertising.
<FQDN> is the applicable fully qualified DNS hostname.
When disabled, this configuration is removed from the database.

dnshost Configures how long hosts should store the configured recursive
<FQDN> DNS domain hostname.
dnshost- Range: from (max-adv-interval) to (2 x max-adv-interval)
lifetime seconds
{<0- Default: 1.5 * max-adv-interval seconds
2147483647>
| default}

R82.10 Gaia Advanced Routing Administration Guide | 704


Configuring IPv6 Discovery in Gaia Clish

Parameter Description

dnsserver Optional.
<IPv6 Disables (off) or enables (on) the recursive DNS server
Network advertising.
Address> When disabled, its lifetime configuration is removed from the
{off | on} database.

dnsserver Configures how long hosts should store the configured recursive
<IPv6 DNS server.
address> Range: from (max-adv-interval) to (2 x max-adv-interval)
dnsserver- seconds
lifetime Default: 1.5 * max-adv-interval seconds
{<0-
2147483647>
| default}

hop-limit Optional.
{<0-255> | Configures the Cur Hop Limit field of the Router Advertisement
default} message.
This value is used by neighboring nodes as the Hop Count field of
the IP header in outgoing IP packets.
The value of 0 means it is unspecified by this router.
Range: 0-255
Default: 64

managed- Optional.
config {off Disables (off) or enables (on) the stateful IP address
| on} autoconfiguration.
Specifies whether to obtain global IPv6 addresses through DHCPv6
(as opposed to stateless address autoconfiguration provided by
ICMPv6 Router Discovery).
This option is placed in the Managed address configuration flag in
the Router Advertisement message.
Range: Selected, or Cleared
Default: Cleared

R82.10 Gaia Advanced Routing Administration Guide | 705


Configuring IPv6 Discovery in Gaia Clish

Parameter Description

max-adv- Optional.
interval Configures the maximum time allowed between sending unsolicited
{<4-1800> | multicast ICMPv6 Router Advertisements on this interface.
default} Unsolicited Router Advertisements are not strictly periodic.
The interval between two advertisements is randomized to decrease
the probability of synchronization with the advertisements from other
routers on the same links.
When an unsolicited advertisement is sent, the timer is reset to a
random value between the min-adv-interval and the max-adv-
interval.
Range: 4-1800 seconds
Default: 600 seconds

min-adv- Optional.
interval Configures the minimum time allowed between sending unsolicited
{<3-1800> | multicast ICMPv6 Router Advertisements on this interface.
default} Unsolicited Router Advertisements are not strictly periodic.
The interval between two advertisements is randomized to decrease
the probability of synchronization with the advertisements from other
routers on the same links.
When an unsolicited advertisement is sent, the timer is reset to a
random value between the min-adv-interval and the max-adv-
interval.
Range: 3-1799 seconds
Default: (Value of max-adv-interval) / 3 seconds

other-config Optional.
{off | on} Disables (off) or enables (on) the stateful autoconfiguration to
obtain other configuration information besides IP addresses.
Stateful autoconfiguration is provided by DHCPv6, as opposed to
stateless autoconfiguration provided by ICMPv6 Router Discovery.
Examples of such information include information related to DNS, or
information on other servers within the network.
This option is placed in the Other configuration flag in the Router
Advertisement message.
Range: off, or on
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 706


Configuring IPv6 Discovery in Gaia Clish

Parameter Description

reachable- Optional.
time {<0- Configures how long a node assumes a neighbor is reachable after
3600000> | having received a reachability confirmation.
default} This value is used by the Neighbor Unreachability Detection.
The reachable time is placed in the Reachable Time field in the
Router Advertisement message.
The value 0 means it is unspecified by this router.
Range: 0-3600000 seconds
Default: 0 seconds

retransmit- Optional.
timer {<0- Configures the interval between retransmitted Neighbor Solicitation
2147483647> messages if the node does not receive a response.
| default} This value is used by address resolution and Neighbor
Unreachability Detection.
The retransmit timer is placed in the Retrans Timer field in the
Router Advertisement message.
The value 0 means it is unspecified by this router.
Range: 0-2147483647 seconds
Default: 0 seconds

router- Optional.
lifetime Configures how long from receipt of a Router Advertisement
{<0- message that a host considers this router to be valid.
2147483647> If the router lifetime expires with no refreshing Router Advertisement,
| default} the host stops using this router.
The value is placed in the Router Lifetime field of the Router
Advertisement message.
A value of 0 means that the router is not used as a default router.
Range: from max-adv-interval to 9000 seconds, or 0 seconds
Default: 3 * (Value of max-adv-interval) seconds

send-mtu Optional.
{off | on} Disables (off) or enables (on) the MTU options in Router
Advertisement messages sent to neighboring nodes.
Range: off, or on
Default: off

R82.10 Gaia Advanced Routing Administration Guide | 707


Monitoring IPv6 Router Discovery

Monitoring IPv6 Router Discovery


Monitoring IPv6 Router Discovery in Gaia Portal
1. From the left navigation tree, click Advanced Routing > IPv6 Router Discovery.
2. In the top right corner, click Monitoring.

Note - The page is static. To see the latest values, click Reload.

Monitoring IPv6 Router Discovery in Gaia Clish

show ipv6 rdisc6[Esc][Esc]

Troubleshooting IPv6 Router Discovery


See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 708


Policy Based Routing

Policy Based Routing


In addition to dynamic and static routing, you can use Policy Based Routing (PBR) to control
traffic. PBR Policy Rules have priority over static and dynamic routes in the routing table.
When a packet arrives at a Gaia Security Gateway, the Security Gateway goes through the
PBR Rules in the order of their set priority, and looks for a match:
n If the match exists, the Security Gateway forwards the packet according to the rule.
n If there is no match in the PBR Policy, the Security Gateway forwards the packet
according to static or dynamic routes in the routing table.
For additional information, see sk67135.

R82.10 Gaia Advanced Routing Administration Guide | 709


Configuring Policy Based Routing in Gaia Portal

Configuring Policy Based Routing in Gaia Portal


Important - In a Cluster, you must configure all the Cluster Members in the same way.

To configure Policy Based Routing (PBR):


1. Configure Action Tables - to configure static routes to destination networks.
2. Configure Policy Rules - to configure the priority and the routing action for each set of
matching criteria.
Adding an Action Table with Static Route

1. From the left navigation tree, click Advanced Routing > Policy Based Routing.
2. In the Action Tables section, click Add.
3. Configure the route parameters:
n Table Name - Name of the Policy Table (From 1 to 64 alphanumeric characters.
The first character must be a letter.).
n Table ID - Assigned by the system.
n Default Route - Optional. Controls whether to make this the default route.

Note - If you select this option, the Destination and Subnet mask fields
do not show.
n Destination - Destination IPv4 address
n Subnet mask - Destination IPv4 subnet mask
n Next Hop Type -
l Normal - Accepts and forwards packets
l Reject - Drops packets and sends an ICMP Unreachable message to the
sender
l Black Hole - Drops packets without a notification to the sender
4. Configure the next hop gateway (for Next Hop Type "Normal").

R82.10 Gaia Advanced Routing Administration Guide | 710


Configuring Policy Based Routing in Gaia Portal

To configure an IP address as the next hop gateway

a. Click Add Gateway and select IP Address.


b. In the Gateway Address field, enter the IPv4 address of the next hop
gateway.
c. In the Priority field, enter the priority of this next hop gateway for this static
route in a PBR table.
Range: 1-8
Default: 1
d. In the Monitored IPs section, select IP addresses, whose reachability Gaia
needs to monitor.

For more information, see "IP Reachability Detection" on page 243.


e. The Force Interface Symmetry option controls whether to ignore IP
reachability reports from IP addresses with asymmetric traffic. ICMP Echo
packets must be sent and received on the same interface to be valid remote
monitoring beacon.
Range: Selected, or Cleared
Default: Cleared
f. In the Monitored IP Fail Condition field, select the applicable condition.
n Fail All

Fails the next hop gateway when all monitored IP addresses become
unreachable.
Restores the next hop gateway when any of the monitored IP addresses
becomes reachable.
n Fail Any
Fails the next hop gateway when any of the monitored IP addresses
becomes unreachable.
Restores the next hop gateway when all monitored IP addresses
become reachable.
Range: Fail All, or Fail Any
Default: Fail Any
g. Click OK.

R82.10 Gaia Advanced Routing Administration Guide | 711


Configuring Policy Based Routing in Gaia Portal

To configure an interface as the next hop gateway

a. Click Add Gateway and select Network Interfaces.


b. In the Gateway Interface field, select the applicable interface.
c. In the Priority field, enter the priority of this next hop gateway for this static
route in a PBR table.
Range: 1-8
Default: 1
d. Click OK.

Notes:
n You can configure several next hop gateways.
n Multihop ping for PBR uses ICMP Echo Request to monitor reachability

of an IP address multiple hops away. Multihop ping for PBR updates


the status of an associated PBR nexthop in accordance to the
reachability status. The PBR nexthop status becomes "down", if that IP
address is unreachable.

5. Click Save.

Deleting an Action Table with Static Route

1. From the left navigation tree, click Advanced Routing > Policy Based Routing.
2. In the Action Tables section, select the table.

3. Click Delete.

Note - There is no prompt to confirm.

Adding a Policy Rule

1. From the left navigation tree, click Advanced Routing > Policy Based Routing.
2. In the Policy Rules section, click Add.
3. In the Priority field, enter the priority of this rule in a PBR table.
Description

Priority controls the order in which the rules are evaluated for a given network
packet.

R82.10 Gaia Advanced Routing Administration Guide | 712


Configuring Policy Based Routing in Gaia Portal

Evaluation stops at the first matching rule and only the actions for that rule are
performed.
Priority 1 is the highest and is evaluated before priority 2, and so on.
Priorities 32766 and 32767 are reserved for the main static routing table.
Rules with priorities greater than 32767 are routed after the main routing table.

Best Practice - Do not use a number greater than 5000.

Range: 1-4294967295
Default: None

4. In the Action section, select the action to apply to the traffic that matches the specified
criteria:
n Prohibit - Drop the packet and send a Prohibit message to the sender.
n Unreachable - Drop the packet and send an Unreachable message to the
sender.
n Table - Forward the packet according to the routes in the selected Action Table
with Static Route.
5. In the Match section, configure the applicable criteria.
n Interface - Select the interface, on which the traffic arrived at the Security
Gateway
n Source -Configure the IPv4 address of the source.
n Subnet mask - Configure the IPv4 subnet mask of the source IPv4 address.
n Destination - Configure the IPv4 address of the destination.
n Subnet mask - Configure the IPv4 subnet mask of the destination IPv4 address
n Service Port - Configure the service port. You can enter a number between 1
and 65535, or select a predefined port from the drop-down menu. For more
information, see IANA Service Name and Port Number Registry.
n Protocol - Configure the protocol. You can enter a number between 1 and 255,
or select a predefined protocol from the drop-down menu. For more information,
see IANA Protocol Numbers.
6. Click Save.

R82.10 Gaia Advanced Routing Administration Guide | 713


Configuring Policy Based Routing in Gaia Portal

Deleting a Policy Rule

1. From the left navigation tree, click Advanced Routing > Policy Based Routing.
2. In the Policy Rules section, select the rule.
3. Click Delete.

Note - There is no prompt to confirm.

Configuring Advanced Options

1. From the left navigation tree, click Advanced Routing > Policy Based Routing.
2. In the Advanced Options section, the PBR Route Lookup option controls whether
PBR rules intentionally cause same packets to traverse the Security Gateway more
than once.
Requirements:
a. At least one Policy Rule must exist.
b. SecureXL must be enabled (this is the default).
3. Click Apply.

R82.10 Gaia Advanced Routing Administration Guide | 714


Configuring Policy Based Routing in Gaia Clish

Configuring Policy Based Routing in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

Important - In VSX, to configure Policy Based Routing on a Virtual System or a Virtual


Router, first you must change the context to that Virtual Device with the "set
virtual-system <VSID>" command.
n To see the available "set" commands for Policy Based Routing, enter in Gaia Clish:

set pbr[Esc][Esc]

n To see the available "show" commands for Policy Based Routing, enter in Gaia Clish:

show pbr[Esc][Esc]

To configure Policy Based Routing (PBR):


1. Configure Action Tables - to configure static routes to destination networks.
2. Configure Policy Rules - to configure the priority and the routing action for each set of
matching criteria.

R82.10 Gaia Advanced Routing Administration Guide | 715


Configuring Policy Based Routing in Gaia Clish

Configuring an Action Table with Static Route

Syntax

set pbr table <Name of Table>


off
static-route {default | <Destination IPv4 Address/Mask>}
nexthop
blackhole
gateway address <IPv4 Address>
monitored-ip <IPv4 Address> {off | on}
monitored-ip-option fail-all
monitored-ip-option fail-any
monitored-ip-option force-if-symmetry
{off | on}
{off | on}
priority <1-8>
gateway logical <Name of Interface>
{off | on}
priority <1-8>
reject
off
ping {off | on}

Parameters

Parameter Description

table <Name of Configures the name of the Policy Based Routing (PBR)
Table> Table.
From 1 to 64 alphanumeric characters.
The first character must be a letter.

table <Name of Deletes the Policy Based Routing (PBR) table.


Table> off

R82.10 Gaia Advanced Routing Administration Guide | 716


Configuring Policy Based Routing in Gaia Clish

Parameter Description

static-route Configures a static route for the PBR table.


{default | A PBR Policy Table contains a list of static routes and the
<Destination IPv4 next hop(s) for each route.
Address/Mask>} Multiple tables can be created, where each contains
different static routes and next hops.
A PBR policy table can be associated with a PBR rule, so
that network packets, which match the rule are routed per
the static routes in the given table.
Note - When overlapping static routes exist (e.g.
[Link]/16 and [Link]/24) in a PBR table,
the most specific static route, which matches the
destination is used to route traffic.
n To make this route the default route, enter:
... static-route default
n To make this a specific route, enter:
... static-route <Destination IPv4
Address/Mask>

static-route {...} Deletes this Policy Based Routing (PBR) static route from
off a PBR table.

static-route {...} Disables (off) or enables (on) the Ping monitoring of the
ping {off | on} specified IPv4 static route.
The Ping feature sends ICMP Echo Requests to verify
that the next hop for a PBR static route is working.
Only next hop gateways, which are verified as reachable
are included in the kernel forwarding table.
When this option is enabled, a route is added to the
kernel forwarding table only after at least one next hop
gateway is reachable.
For additional information, see "IP Reachability
Detection" on page 243.
Range: off, or on
Default: off

nexthop blackhole Configures the next hop for a static route to be a


blackhole route.
A blackhole route drops packets without a notification to
the sender.

R82.10 Gaia Advanced Routing Administration Guide | 717


Configuring Policy Based Routing in Gaia Clish

Parameter Description

nexthop reject Configures the next hop for a static route to be a reject
route.
A reject route drops packets and sends an ICMP
Unreachable message to the sender.

nexthop gateway Configures the IPv4 address of the next hop gateway.
address <IPv4
Address>

monitored-ip <IPv4 Removes (off) or adds (on) the IPv4 address, whose
Address> {off | on} reachability Gaia needs to monitor.
After the "monitored-ip", you must press the Space
key and the Tab key to see the available configured IPv4
addresses.
For more information, see "IP Reachability Detection" on
page 243.

monitored-ip-option Fails the next hop gateway when all monitored IP


fail-all addresses become unreachable.
Restores the next hop gateway when any of the
monitored IP addresses becomes reachable.

monitored-ip-option Fails the next hop gateway when any of the monitored IP
fail-any addresses becomes unreachable.
Restores the next hop gateway when all monitored IP
addresses become reachable.

monitored-ip-option Ignores (off) or accepts (on) IP reachability reports from


force-if-symmetry IP addresses with asymmetric traffic.
{off | on} ICMP Echo packets must be sent and received on the
same interface to be valid remote monitoring beacon.
Range: off, or on
Default: off

gateway address Deletes (off) or adds (on) the next hop address from a
<IPv4 Address> {off static route in a Policy Based Routing (PBR) table.
| on}

priority <1-8> Configures the priority of this next hop gateway for this
static route in a PBR table.
Range: 1-8
Default: 1

R82.10 Gaia Advanced Routing Administration Guide | 718


Configuring Policy Based Routing in Gaia Clish

Parameter Description

nexthop gateway Configures the name of the interface to use as the next
logical <Name of hop gateway.
Interface>

nexthop gateway Deletes (off) or adds (on) the next hop interface from a
logical <Name of static route in a Policy Based Routing (PBR) table.
Interface> {off |
on}

Note - You can add multiple routes to the same table. To do that, run the set pbr
table command with the same table_name.

Example
Create an Action Table named PBRtable1, with a route to the network [Link]/24 out of
the interface Ethernet 0 and a route to the network [Link]/24 through the next hop
gateway with the IP address [Link].

set pbr table PBRtable1 static-route [Link]/24 nexthop


gateway logical eth0 on
set pbr table PBRtable1 static-route [Link]/24 nexthop
gateway address [Link] on

R82.10 Gaia Advanced Routing Administration Guide | 719


Configuring Policy Based Routing in Gaia Clish

Configuring a Policy Rule

Syntax

set pbr rule priority <1-4294967295>


action
main-table
prohibit
table <Name of Table>
unreachable
match
[from {<IPv4 Address/Mask Length> | off}]
[to {<IPv4 Address/Mask Length> | off}
[interface {<Name of Interface> | off}
[port {<1-65535> | off}]
[protocol {1 | 6 | 17 | tcp | udp | icmp | off}]
off

Parameters

Parameter Description

priority <1-4294967295> Configures the priority of this rule in a


PBR table.
Priority controls the order in which the rules
are evaluated for a given network packet.
Evaluation stops at the first matching rule and
only the actions for that rule are performed.
Priority 1 is the highest and is evaluated
before priority 2, and so on.
Priorities 32766 and 32767 are reserved for
the main static routing table.
Rules with priorities greater than 32767 are
routed after the main routing table.
Best Practice - Do not use a number
greater than 5000.
Range: 1-4294967295
Default: None

R82.10 Gaia Advanced Routing Administration Guide | 720


Configuring Policy Based Routing in Gaia Clish

Parameter Description

action {main-table | prohibit Configures the action to be performed on


| table <Name of Table> | network traffic, which matches a Policy Based
unreachable} Routing (PBR) rule.
Available actions:
n main-table - Uses the static routes in
the main routing table.
n prohibit - Generates an ICMP
response with message
"Communication is administratively
prohibited".
n table <Name of Table> - Uses the
static routes in the specified PBR table.
n unreachable - Generates an ICMP
response with message "Network is
unreachable".

Important:
n You can configure only one of these
actions for a PBR rule.
n You must configure the match
condition for a PBR rule before you
configure the action.

R82.10 Gaia Advanced Routing Administration Guide | 721


Configuring Policy Based Routing in Gaia Clish

Parameter Description

match ... Configures the traffic matching criteria:


n from {<IPv4 Address/Mask
Length> | off}
Configures the IPv4 address and the
subnet mask of the source.
Value "off" causes the rule to match
any IPv4 address.
n to {<IPv4 Address/Mask
Length> | off}
Configures the IPv4 address and the
subnet mask of the destination.
Value "off" causes the rule to match
any IPv4 address.
n interface {<Name of
Interface> | off}
Configures the name of the incoming
interface.
Value "off" causes the rule to match
any interface.
n port {<1-65535> | off}
Configures the destination port number.
You can configure only one port number
for a PBR rule.
Value "off" causes the rule to match
any port number.
For more information, see IANA Service
Name and Port Number Registry.
n protocol {1 | 6 | 17 | tcp |
udp | icmp | off}
Configures the protocol.
Value "off" causes the rule to match
any protocol type.
To configure a specific protocol other
than the above, use Gaia Portal.
For more information, see IANA Protocol
Numbers.

off Delete the Policy Rule.

R82.10 Gaia Advanced Routing Administration Guide | 722


Configuring Policy Based Routing in Gaia Clish

Example
Create a Policy Rule that forwards all packets with the destination address [Link]/32 that
arrive on the interface Ethernet 2 according to the PBR Table PBRtable1, and assign to it
the priority of 100.

set pbr rule priority 100 match to [Link]/32 interface eth2


set pbr rule priority 100 action table PBRtable1

R82.10 Gaia Advanced Routing Administration Guide | 723


Configuring Policy Based Routing in Gaia Clish

Configuring Advanced Options

The PBR Route Lookup option controls whether PBR rules intentionally cause same
packets to traverse the Security Gateway more than once.

Requirements
1. At least one Policy Rule must exist.
2. SecureXL must be enabled (this is the default).

Syntax

set pbrroute sim flag {0 | 1}

Parameters

Parameter Description

0 Disables the PBR Route Lookup.

1 Enables the PBR Route Lookup.

R82.10 Gaia Advanced Routing Administration Guide | 724


Monitoring Policy Based Routing

Monitoring Policy Based Routing


Monitoring Policy Based Routing in Gaia Portal
1. From the left navigation tree, click Advanced Routing > Policy Based Routing.
2. In the top right corner, click Monitoring.

Monitoring Policy Based Routing in Gaia Clish


1. In VSX mode, change the context to the applicable Virtual Device:

set virtual-system <VSID>

2. Show the applicable PBR information:

show pbr tables


show pbr rules
show pbr summary

Monitoring Policy Based Routing in the Expert mode


1. In VSX mode, change the context to the applicable Virtual Device:

vsenv <VSID>

2. Show the applicable PBR information:

ip table show <1-255>


ip route show table <1-255>
ip rule show

R82.10 Gaia Advanced Routing Administration Guide | 725


NAT Pools

NAT Pools
NAT Pools help routers on a network to learn the reachability information of IP addresses.
NAT Pools are exportable, like routes, through routing protocols, but NAT pools are not used
for local forwarding.
Each NAT Pool has only its destination prefix, and optionally a comment.

Use Case:
A host is located behind a Gaia Security Gateway.
The host's source IP address is NATed to another external IP address (hidden behind NAT).

This external NATed IP address does not belong to any local network.
Routers on the network must route the return traffic to that external (NATed) IP address.
Gaia administrator creates a NAT pool that contains this external IP address and redistributes
this NAT pool through OSPF or BGP to the applicable routers on the network.
This way the routers learn about the NATed IP addresses.

Configuring NAT Pools in Gaia Portal


Important - In a Cluster, you must configure all the Cluster Members in the same way.

Configuring a new NAT Pool

1. From the left navigation tree, click Advanced Routing > NAT Pools.
2. In the NAT Pools section, click Add, and select IPv4 or IPv6.
3. Configure the IP address, behind which the source IP addresses are hidden:
n For an IPv4 NAT Pool:
a. In the Destination field, enter an IPv4 address.
b. In the Subnet mask field, enter an IPv4 subnet mask.
c. In the Comment field, enter the applicable comment text (up to 100
characters).

R82.10 Gaia Advanced Routing Administration Guide | 726


NAT Pools

n For an IPv6 NAT Pool:


a. In the Destination / Mask Length field, enter an IPv6 address and Mask
Length.
b. In the Comment field, enter the applicable comment text (up to 100
characters).
This comment appears in the Gaia Portal and in the output of the Gaia
Clish "show configuration" command.
4. Click Save.
5. Redistribute this NAT Pool to the applicable dynamic routing protocol.
See "Configuring Route Redistribution in Gaia Portal" on page 534.

Editing an existing NAT Pool

1. From the left navigation tree, click Advanced Routing > NAT Pools.
2. In the NAT Pools section, select the applicable NAT Pool.
3. Click Edit.
4. Configure the applicable settings.
5. Click Save.

Deleting an existing NAT Pool

1. Remove this NAT Pool from the applicable Route Redistribution configuration.
See "Configuring Route Redistribution in Gaia Portal" on page 534.
2. From the left navigation tree, click Advanced Routing > NAT Pools.

3. In the NAT Pools section, select the applicable NAT Pool.


4. Click Delete.

Configuring NAT Pools in Gaia Clish


Important - In a Cluster, you must configure all the Cluster Members in the same way.

n To see the available "set" commands for NAT Pools, enter in Gaia Clish:

set nat-pool[Esc][Esc]

n To see the configured NAT Pools, enter in Gaia Clish:

R82.10 Gaia Advanced Routing Administration Guide | 727


NAT Pools

show configuration nat-pool

Action plan
1. Configure the applicable NAT Pools:
See the Syntax section below.
2. Redistribute the applicable NAT Pools to the applicable dynamic routing protocols.
See:
n "Configuring IPv4 Route Redistribution in Gaia Clish" on page 552.
n "Configuring IPv6 Route Redistribution in Gaia Clish" on page 588.
3. Configure the applicable Route Maps that match the applicable NAT Pools.
See "Configuring Route Maps in Gaia Clish" on page 606.
Syntax

set nat-pool <IP Address/Mask>


comment "Text"
off
on

Parameters

Parameter Description

<IP Configures the NAT Pool for IPv4 or IPv6.


Address/ This is the IP address, behind which the source IP addresses are
Mask> hidden.

comment Configures an optional free text comment for an existing NAT Pool.
"Text"
n Write the text in double quotes.
n Text must be up to 100 characters.
n This comment appears in the Gaia Portal and in the output of the
"show configuration" command.

off Removes the existing NAT Pool.

on Adds the new NAT Pool.

R82.10 Gaia Advanced Routing Administration Guide | 728


NAT Pools

Monitoring NAT Pools


Monitoring NAT Pools in Gaia Portal
1. From the left navigation tree, click Advanced Routing > NAT Pools.
2. Refer to the section NAT Pools.

Monitoring NAT Pools in Gaia Clish

show route

Refer to the Codes section at the top.

R82.10 Gaia Advanced Routing Administration Guide | 729


Multicast Forwarding Cache (MFC)

Multicast Forwarding Cache (MFC)


Warning - MFC static entries and Protocol-Independent Multicast (PIM) are mutually
exclusive features and must not be enabled at the same time (see "PIM" on page 155
and "IPv6 PIM" on page 185).

Overview
Various static and dynamic multicast routing protocols use Multicast Forwarding Cache (MFC)
to forward packets that match multicast routes.

Known Limitations
It is not supported to configure IPv6 MFC static entries on VRRP Clusters.

Configuring MFC in Gaia Portal


Adding a new MFC Static Entry

1. With a web browser, connect to the Gaia Portal.


2. Log in.
3. From the left navigation tree, click Advanced Routing > MFC Static Entries.

4. In the Source section:


a. In the Source field, configure the source IPv4 or IPv6 address of the multicast
traffic.

Note - The Source IP address and the Group IP address must belong
to the same address family (both IPv4, or both IPv6).

R82.10 Gaia Advanced Routing Administration Guide | 730


Multicast Forwarding Cache (MFC)

b. In the Source Count field, configure the number of adjacent sources to add.
Explanation

This parameter adds multiple (S,G) entries for the configured number of
sources in a row.
This parameter configures all (S+i*inc, G) entries, where:
n "i" has a range from 0 to n-1.
n The value of the parameter "source-increment" determines the
value of "inc".

Note - If you also configure the "Group Count", then Gaia OS adds
all pairs (S+i*sinc,G+j*ginc)

Range: 1-512
Default: 1 (no additional sources)

c. In the Source increment field, configure the increment between adjacent


sources.
Explanation

This parameter configures all (S+i*inc, G) entries, where "i" has a range
from 0 to n-1.
The value of this parameter has a format an IPv4 or IPv6 address (matching
the source itself). Gaia OS adds this value bit-wise to the group IP address.

Default Increment for IPv4: [Link]


Default Increment for IPv6: ::1

5. In the Group section:

R82.10 Gaia Advanced Routing Administration Guide | 731


Multicast Forwarding Cache (MFC)

a. In the Group field, configure the multicast destination group IPv4 or IPv6
address.

Notes:
n The Group IP address and the Source IP address must belong to

the same address family (both IPv4, or both IPv6).


n Groups in the IPv6 range 224.x.x.0/24 and the IPv6 range

FF02::/16 are reserved for local networks. Gaia OS does not


forward to external networks the multicast traffic that is destined
for these multicast groups.

IPv4 Range: [Link]/4


IPv6 Range: FF00::/8

b. In the Group Count field, configure the number of adjacent groups to add.
Explanation

This parameter adds multiple (S,G) entries for the configured number of
groups in a row.
This parameter configures all (S, G+j*inc) entries, where:
n "j" has a range from 0 to n-1.
n The value of the parameter "group-increment" determines the value
of "inc".

Note - If you also configure the "Source Count", then Gaia OS adds
all pairs (S+i*sinc,G+j*ginc)

Range: 1-512
Default: 1 (no additional groups)

c. In the Group increment field, configure the increment between adjacent groups.
Explanation

This parameter configures all (S, G+j*inc) entries, where "i" has a range
from 0 to n-1.
The value of this parameter has a format an IPv4 or IPv6 address (matching
the group itself). Gaia OS adds this value bit-wise to the group IP address.
Default Increment for IPv4: [Link]
Default Increment for IPv6: ::1

6. In the Incoming Interface section:

R82.10 Gaia Advanced Routing Administration Guide | 732


Multicast Forwarding Cache (MFC)

n In the IIF field, select the applicable interface.

Note - Before you can select an interface, you must configure the
interface (enable it and configure an IP address on it).

7. In the Outgoing Interfaces section:


a. Select the applicable interface from the drop-down menu.

Note - Before you can select an interface, you must configure the
interface (enable it and configure an IP address on it).

b. Click Add.
c. Repeat these steps for other applicable interfaces.

8. Click Save.

Editing an existing MFC Static Entry

1. With a web browser, connect to the Gaia Portal.


2. Log in.
3. From the left navigation tree, click Advanced Routing > MFC Static Entries.
4. Select the applicable entry.
5. Make the required changes.
6. Click Save.

Deleting an existing MFC Static Entry

1. With a web browser, connect to the Gaia Portal.

2. Log in.
3. From the left navigation tree, click Advanced Routing > MFC Static Entries.
4. Select the applicable entry.
5. Click Delete.

Important - There is no prompt to confirm.

R82.10 Gaia Advanced Routing Administration Guide | 733


Multicast Forwarding Cache (MFC)

Configuring MFC in Gaia Clish


Syntax to configure MFC entries

set mfc-static source <Source IP Address> group <Destination


Group IP Address>
group-count <1-512> group-increment <Group Increment IP
Address> {on | off}
iif <Name of Incoming Interface> on
off
oif <Name of Outgoing Interface> {on | off}
source-count <1-512> source-increment <Source Increment IP
Address> {on | off}

Parameters:

Parameter Description

source <Source IP Configures an (S,G) entry in the MFC.


Address> Specifies the source IPv4 or IPv6 address of the multicast
traffic.
Note - The "<Source IP Address>" and the
"<Destination Group IP Address>" must belong
to the same address family (both IPv4, or both IPv6)
Default: none

group <Destination Specifies the multicast destination group IPv4 or IPv6


Group IP Address> address.
Notes:
n The "<Destination Group IP Address>"
and the "<Source IP Address>" must belong to
the same address family (both IPv4, or both IPv6).
n Groups in the IPv6 range 224.x.x.0/24 and the IPv6
range FF02::/16 are reserved for local networks.
Gaia OS does not forward to external networks the
multicast traffic that is destined for these multicast
groups.

IPv4 Range: [Link]/4


IPv6 Range: FF00::/8
Default: none

R82.10 Gaia Advanced Routing Administration Guide | 734


Multicast Forwarding Cache (MFC)

Parameter Description

group-count <1- Configures a number of adjacent groups to add.


512> This parameter adds multiple (S,G) entries for the configured
number of groups in a row.
This parameter configures all (S, G+j*inc) entries, where:
n "j" has a range from 0 to n-1.
n The value of the parameter "group-increment"
determines the value of "inc".

Note - If you also configure the "source-count", then


Gaia OS adds all pairs (S+i*sinc,G+j*ginc)
Range: 1-512
Default: 1 (no additional groups)

group-increment Configures the increment between adjacent groups.


<Group Increment This parameter configures all (S, G+j*inc) entries, where
IP Address> "i" has a range from 0 to n-1.
The value of this parameter has a format an IPv4 or IPv6
address (matching the group itself). Gaia OS adds this value
bit-wise to the group IP address.
Default Increment for IPv4: [Link]
Default Increment for IPv6: ::1

iif <Name of Configures the traffic incoming interface for the (S,G) entry.
Incoming
Interface> {on |
n on - Enables the MFC on the specified interface
off}
n off - Disables the MFC on the specified interface

Note - Before you configure the MFC on an interface,


you must configure the interface (enable it and configure
an IP address on it.

off Remove this (S,G) entry from the MFC.

R82.10 Gaia Advanced Routing Administration Guide | 735


Multicast Forwarding Cache (MFC)

Parameter Description

oif <Name of Configures the traffic outgoing interface for the (S,G) entry -
Outgoing the interface that forwards the traffic.
Interface> {on |
off}
n on - Enables the MFC on the specified interface
n off - Disables the MFC on the specified interface

Notes:
n Before you configure the MFC on an interface, you
must configure the interface (enable it and
configure an IP address on it).
n You can configure more than one outgoing
interface for the same (S,G) entry.

source-count <1- Configures the number of adjacent sources to add.


512> This parameter adds multiple (S,G) entries for the configured
number of sources in a row.
This parameter configures all (S+i*inc, G) entries, where:
n "i" has a range from 0 to n-1.
n The value of the parameter "source-increment"
determines the value of "inc".

Note - If you also configure the "group-count", then


Gaia OS adds all pairs (S+i*sinc,G+j*ginc)
Range: 1-512
Default: 1 (no additional sources)

source-increment Configures the increment between adjacent sources.


<Source Increment This parameter configures all (S+i*inc, G) entries, where
IP Address> "i" has a range from 0 to n-1.
The value of this parameter has a format an IPv4 or IPv6
address (matching the source itself). Gaia OS adds this value
bit-wise to the group IP address.
Default Increment for IPv4: [Link]
Default Increment for IPv6: ::1

Syntax to view MFC entries and configuration

show mfc
cache [static]
interface
orphans
stats
summary

R82.10 Gaia Advanced Routing Administration Guide | 736


Multicast Forwarding Cache (MFC)

Parameters

Parameter Description

cache Shows the MFC cache state.


[static]

interface Shows the state information for all interfaces where the MFC is active.

orphans Shows the MFC <S,G> routes that multicast routing could not resolve
(because the multicast source IP address is not reachable).
For details on why a route is orphaned, enable the corresponding trace
option "MFC Cache". See "Trace Options" on page 672.

stats Shows the MFC statistics.

summary Shows the MFC configuration summary information.

R82.10 Gaia Advanced Routing Administration Guide | 737


Multicast Forwarding Cache (MFC)

Example 1 - MFC Statistics


MyGW> show mfc stats

Multicast Forwarding Cache Stats


Resolve Task MyGW
Total: 0
Errors:
Truncated: 0
Unsupported Version: 0
Multicast Disabled: 0
Unsupported Type: 0

Resolve Requests
Normal: 0
PIM: 0
Errors:
Unsupported Operation: 0
Truncated: 0
Unsupported Type: 0

RPF Failure Notifications


Normal: 0
PIM Register: 0
SPT Switchover: 0
Errors:
Truncated: 0
Unsupported Type: 0
No MFC Active: 0
Interface Not Activ: 0

MFC Maintenance
Packet Count Request: 0
Packet Count Response: 0
Xresolve Request: 0
Mcast Forward Request: 0
Errors:
Packet Count Request: 0
Packet Count Response: 0
Xresolve Request: 0
Mcast Forwarding Request: 0

MyGW>

R82.10 Gaia Advanced Routing Administration Guide | 738


Multicast Forwarding Cache (MFC)

Example 2 - MFC Configuration Summary


MyGW> show mfc

Multicast Forwarding Cache State


Number of interfaces enabled: 0
Number of cache entries: 0
Kernel forwarding entry limit: unlimited
Number of kernel forwarding entries: 0
Cache entry average lifetime: 300 seconds
Prune average lifetime: 7200 seconds
Cache age cycle: 10 seconds
Datarate update interval: 10 seconds
Multicast Protocol(Instance): Any(0)

Multicast Forwarding Cache Static Entry State


Number of interfaces enabled: 0
Number of cache entries: 0
Number of kernel forwarding entries: 0
Multicast Protocol(Instance): MFC Static(N/A)

MyGW>

R82.10 Gaia Advanced Routing Administration Guide | 739


Multicast Forwarding Cache (MFC)

Monitoring MFC Entries


Monitoring in Gaia Clish

To see the IPv4 and IPv6 multicast entries:

show mfc cache

Example:

MyGW> show mfc cache

Multicast Forwarding Cache State


Prefix Type Age
Expire RPF
[Link],[Link]/64 Static N/A N/A
eth1.10
Forwarding:
eth1.20
eth1.30
80::1,ff0e::101/256 Static N/A N/A
eth1.10
Forwarding:
eth1.20
MyGW>

Monitoring in the Expert mode

n To see the IPv4 multicast entries:

ip mroute

Example:

[Expert@MyGW:0]# ip mroute
([Link], [Link]) Iif: eth1.10 Oifs:
eth1.20 eth1.30
[Expert@MyGW:0]#

n To see the IPv6 multicast entries:

ip -6 mroute

Example:

R82.10 Gaia Advanced Routing Administration Guide | 740


Multicast Forwarding Cache (MFC)

[Expert@MyGW:0]# ip -6 mroute
(80::1, ff0e::101) Iif: eth1.10 Oifs:
eth1.20
[Expert@MyGW:0]#

Troubleshooting MFC
See "Trace Options" on page 672.

R82.10 Gaia Advanced Routing Administration Guide | 741


Routing Monitor

Routing Monitor
Monitoring Routes in Gaia Portal
In Gaia Portal, you can see information about active, inactive or all (both active and inactive)
routes on your Gaia system for OSPF, BGP, and RIP protocols.
To see the routes on the Gaia system:
1. From the left navigation tree, click Advanced Routing > Routing Monitor.
2. Optional: In the Filter Protocols column, select the protocol, whose routes you want to
see. (Press and hold the Shift key while you click on items.)

Monitoring Routes in Gaia Clish


To see the available "show" commands for Routes, enter in Gaia Clish:

show route[Esc][Esc]

Monitoring the Routing Daemon in Gaia Clish


To see the available "show" commands for the Routing Daemon, enter in Gaia Clish:

show routed[Esc][Esc]

Monitoring the Multicast Forwarding Cache in Gaia Clish


To see the available "show" commands for Multicast Forwarding Cache, enter in Gaia Clish:

show mfc[Esc][Esc]

R82.10 Gaia Advanced Routing Administration Guide | 742


IPv6 VRRP

IPv6 VRRP
For configuration of a VRRP Cluster, refer to the R82.10 Gaia Administration Guide > Chapter
"High Availability".
VRRP for IPv6 follows the same guidelines and limitations as VRRP for IPv4.
If both IPv6 and IPv4 VRRP are configured, they must be symmetrical in terms of master state
and fail over behavior.

To configure VRRP support for IPv6 on Gaia:

Step Instructions

1 Enable the IPv6 support and reboot.


See "IPv6 Support" on page 16.

2 Configure a Virtual IPv6 address for each VRRP IPv6 group:


a. Configure a link-local Virtual IPv6 address for the VRRP IPv6
group:
set ipv6 vrrp6 interface <Name of
Interface> monitored-circuit vrid <Virtual
Router ID> address <Backup IPv6 Address> on
Example:
MyGW> set ipv6 vrrp6 interface eth2.10
monitored-circuit vrid 11 address
fe80::250:56ff:fea3:4321 on
Note - Configure a link-local address that is on the same
subnet as the hosts.
b. Configure a link-global Virtual IPv6 address for the VRRP IPv6
group:
set ipv6 vrrp6 interface <Name of
Interface> vrid <Virtual Router ID> address
<Backup IPv6 Address> on
Example:
MyGW> set ipv6 vrrp6 interface eth2.10 vrid
11 address 2610:18:8104:1A::5 on

3 Save the configuration:


save config

R82.10 Gaia Advanced Routing Administration Guide | 743


IPv6 VRRP

To verify the configuration:


n In Gaia Portal:
Go to High Availability > IPv6 VRRP
n In Gaia Clish, run:

show ipv6 vrrp interfaces

R82.10 Gaia Advanced Routing Administration Guide | 744


Regular Expressions and Character Sets

Regular Expressions and


Character Sets
Regular Expression Syntax
This table shows the Check Point implementation of standard regular expression
metacharacters.

Metacharacter Name Description

\ Backslash Escape metacharacters.


Non-printable characters.
Character types.

[] Square Character class definition.


Brackets

() Parenthesis Sub-pattern, to use metacharacters on the enclosed


string.

{min[,max]} Curly Min / Max Quantifier:


Brackets
n {m} - exactly m occurrences
n {m,n} - from m to m occurrences
n {m,} - at least m occurrences

. Dot Match any character.

? Question Zero or one occurrences of preceding pattern (equals


Mark {0,1}).

* Asterisk Zero or more occurrences of preceding pattern.

+ Plus Sign One or more occurrences of preceding pattern


(equals {1,}).

| Vertical Bar Alternative.

^ Circumflex Anchor pattern to beginning of buffer (usually a word).

$ Dollar Anchor pattern to end of buffer (usually a word).

- Hyphen Range in character class.

R82.10 Gaia Advanced Routing Administration Guide | 745


Regular Expressions and Character Sets

Special Characters in Gaia Clish


For the "?" character, press the CTRL V keys and then press the SHIFT ? keys.
For the "\" character, enter \\.

R82.10 Gaia Advanced Routing Administration Guide | 746


Glossary

Glossary
A

Anti-Bot
Check Point Software Blade on a Security Gateway that blocks botnet behavior and
communication to Command and Control (C&C) centers. Acronyms: AB, ABOT.

Anti-Spam
Check Point Software Blade on a Security Gateway that provides comprehensive
protection for email inspection. Synonym: Anti-Spam & Email Security. Acronyms: AS,
ASPAM.

Anti-Virus
Check Point Software Blade on a Security Gateway that uses real-time virus signatures
and anomaly-based protections from ThreatCloud to detect and block malware at the
Security Gateway before users are affected. Acronym: AV.

Application Control
Check Point Software Blade on a Security Gateway that allows granular control over
specific web-enabled applications by using deep packet inspection. Acronym: APPI.

Audit Log
Log that contains administrator actions on a Management Server (login and logout,
creation or modification of an object, installation of a policy, and so on).

Bridge Mode
Security Gateway or Virtual System that works as a Layer 2 bridge device for easy
deployment in an existing topology.

Cluster
Two or more Security Gateways that work together in a redundant configuration - High
Availability, or Load Sharing.

R82.10 Gaia Advanced Routing Administration Guide | 747


Glossary

Cluster Member
Security Gateway that is part of a cluster.

Compliance
Check Point Software Blade on a Management Server to view and apply the Security
Best Practices to the managed Security Gateways. This Software Blade includes a
library of Check Point-defined Security Best Practices to use as a baseline for good
Security Gateway and Policy configuration.

Content Awareness
Check Point Software Blade on a Security Gateway that provides data visibility and
enforcement. Acronym: CTNT.

CoreXL
Performance-enhancing technology for Security Gateways on multi-core processing
platforms. Multiple Check Point Firewall instances are running in parallel on multiple
CPU cores.

CoreXL Firewall Instance


On a Security Gateway with CoreXL enabled, the Firewall kernel is copied multiple
times. Each replicated copy, or firewall instance, runs on one processing CPU core.
These firewall instances handle traffic at the same time, and each firewall instance is a
complete and independent firewall inspection kernel. Synonym: CoreXL FW Instance.

CoreXL SND
Secure Network Distributer. Part of CoreXL that is responsible for: Processing incoming
traffic from the network interfaces; Securely accelerating authorized packets (if
SecureXL is enabled); Distributing non-accelerated packets between Firewall kernel
instances (SND maintains global dispatching table, which maps connections that were
assigned to CoreXL Firewall instances). Traffic distribution between CoreXL Firewall
instances is statically based on Source IP addresses, Destination IP addresses, and the
IP 'Protocol' type. The CoreXL SND does not really "touch" packets. The decision to stick
to a particular FWK daemon is done at the first packet of connection on a very high level,
before anything else. Depending on the SecureXL settings, and in most of the cases, the
SecureXL can be offloading decryption calculations. However, in some other cases,
such as with Route-Based VPN, it is done by FWK daemon.

CPUSE
Check Point Upgrade Service Engine for Gaia Operating System. With CPUSE, you can
automatically update Check Point products for the Gaia OS, and the Gaia OS itself.

R82.10 Gaia Advanced Routing Administration Guide | 748


Glossary

DAIP Gateway
Dynamically Assigned IP (DAIP) Security Gateway is a Security Gateway, on which the
IP address of the external interface is assigned dynamically by the ISP.

Data Loss Prevention


Check Point Software Blade on a Security Gateway that detects and prevents the
unauthorized transmission of confidential information outside the organization. Acronym:
DLP.

Data Type
Classification of data in a Check Point Security Policy for the Content Awareness
Software Blade.

Distributed Deployment
Configuration in which the Check Point Security Gateway and the Security Management
Server products are installed on different computers.

Dynamic Object
Special object type, whose IP address is not known in advance. The Security Gateway
resolves the IP address of this object in real time.

Endpoint Policy Management


Check Point Software Blade on a Management Server to manage an on-premises
Harmony Endpoint Security environment.

Expert Mode
The name of the elevated command line shell that gives full system root permissions in
the Check Point Gaia operating system.

Gaia
Check Point security operating system that combines the strengths of both
SecurePlatform and IPSO operating systems.

R82.10 Gaia Advanced Routing Administration Guide | 749


Glossary

Gaia Clish
The name of the default command line shell in Check Point Gaia operating system. This
is a restricted shell (role-based administration controls the number of commands
available in the shell).

Gaia Portal
Web interface for the Check Point Gaia operating system.

Hotfix
Software package installed on top of the current software version to fix a wrong or
undesired behavior, and to add a new behavior.

HTTPS Inspection
Feature on a Security Gateway that inspects traffic encrypted by the Secure Sockets
Layer (SSL) protocol for malware or suspicious patterns. Synonym: SSL Inspection.
Acronyms: HTTPSI, HTTPSi.

ICA
Internal Certificate Authority. A component on Check Point Management Server that
issues certificates for authentication.

Identity Awareness
Check Point Software Blade on a Security Gateway that enforces network access and
audits data based on network location, the identity of the user, and the identity of the
computer. Acronym: IDA.

Identity Logging
Check Point Software Blade on a Management Server to view Identity Logs from the
managed Security Gateways with enabled Identity Awareness Software Blade.

Internal Network
Computers and resources protected by the Firewall and accessed by authenticated
users.

R82.10 Gaia Advanced Routing Administration Guide | 750


Glossary

IPS
Check Point Software Blade on a Security Gateway that inspects and analyzes packets
and data for numerous types of risks (Intrusion Prevention System).

IPsec VPN
Check Point Software Blade on a Security Gateway that provides a Site to Site VPN and
Remote Access VPN access.

Jumbo Hotfix Accumulator


Collection of hotfixes combined into a single package. Acronyms: JHA, JHF, JHFA.

Kerberos
An authentication server for Microsoft Windows Active Directory Federation Services
(ADFS).

Log Server
Dedicated Check Point server that runs Check Point software to store and process logs.

Logging & Status


Check Point Software Blade on a Management Server to view Security Logs from the
managed Security Gateways.

Management Interface
(1) Interface on a Gaia Security Gateway or Cluster member, through which
Management Server connects to the Security Gateway or Cluster member. (2) Interface
on Gaia computer, through which users connect to Gaia Portal or CLI.

Management Server
Check Point Single-Domain Security Management Server or a Multi-Domain Security
Management Server.

R82.10 Gaia Advanced Routing Administration Guide | 751


Glossary

Manual NAT Rules


Manual configuration of NAT rules by the administrator of the Check Point Management
Server.

Mobile Access
Check Point Software Blade on a Security Gateway that provides a Remote Access VPN
access for managed and unmanaged clients. Acronym: MAB.

Multi-Domain Log Server


Dedicated Check Point server that runs Check Point software to store and process logs
in a Multi-Domain Security Management environment. The Multi-Domain Log Server
consists of Domain Log Servers that store and process logs from Security Gateways that
are managed by the corresponding Domain Management Servers. Acronym: MDLS.

Multi-Domain Server
Dedicated Check Point server that runs Check Point software to host virtual Security
Management Servers called Domain Management Servers. Synonym: Multi-Domain
Security Management Server. Acronym: MDS.

Network Object
Logical object that represents different parts of corporate topology - computers, IP
addresses, traffic protocols, and so on. Administrators use these objects in Security
Policies.

Network Policy Management


Check Point Software Blade on a Management Server to manage an on-premises
environment with an Access Control and Threat Prevention policies.

Open Server
Physical computer manufactured and distributed by a company, other than Check Point.

R82.10 Gaia Advanced Routing Administration Guide | 752


Glossary

Provisioning
Check Point Software Blade on a Management Server that manages large-scale
deployments of Check Point Security Gateways using configuration profiles. Synonyms:
SmartProvisioning, SmartLSM, Large-Scale Management, LSM.

QoS
Check Point Software Blade on a Security Gateway that provides policy-based traffic
bandwidth management to prioritize business-critical traffic and guarantee bandwidth
and control latency.

Rule
Set of traffic parameters and other conditions in a Rule Base (Security Policy) that cause
specified actions to be taken for a communication session.

Rule Base
All rules configured in a given Security Policy. Synonym: Rulebase.

SecureXL
Check Point product on a Security Gateway that accelerates IPv4 and IPv6 traffic that
passes through a Security Gateway.

Security Gateway
Dedicated Check Point server that runs Check Point software to inspect traffic and
enforce Security Policies for connected network resources.

Security Management Server


Dedicated Check Point server that runs Check Point software to manage the objects and
policies in a Check Point environment within a single management Domain. Synonym:
Single-Domain Security Management Server.

R82.10 Gaia Advanced Routing Administration Guide | 753


Glossary

Security Policy
Collection of rules that control network traffic and enforce organization guidelines for
data protection and access to resources with packet inspection.

SIC
Secure Internal Communication. The Check Point proprietary mechanism with which
Check Point computers that run Check Point software authenticate each other over SSL,
for secure communication. This authentication is based on the certificates issued by the
ICA on a Check Point Management Server.

SmartConsole
Check Point GUI application used to manage a Check Point environment - configure
Security Policies, configure devices, monitor products and events, install updates, and
so on.

SmartDashboard
Legacy Check Point GUI client used to create and manage the security settings in
versions R77.30 and lower. In versions R80.X and higher is still used to configure
specific legacy settings.

SmartProvisioning
Check Point Software Blade on a Management Server (the actual name is
"Provisioning") that manages large-scale deployments of Check Point Security
Gateways using configuration profiles. Synonyms: Large-Scale Management,
SmartLSM, LSM.

SmartUpdate
Legacy Check Point GUI client used to manage licenses and contracts in a Check Point
environment.

Software Blade
Specific security solution (module): (1) On a Security Gateway, each Software Blade
inspects specific characteristics of the traffic (2) On a Management Server, each
Software Blade enables different management capabilities.

Standalone
Configuration in which the Security Gateway and the Security Management Server
products are installed and configured on the same server.

R82.10 Gaia Advanced Routing Administration Guide | 754


Glossary

Threat Emulation
Check Point Software Blade on a Security Gateway that monitors the behavior of files in
a sandbox to determine whether or not they are malicious. Acronym: TE.

Threat Extraction
Check Point Software Blade on a Security Gateway that removes malicious content from
files. Acronym: TEX.

Updatable Object
Network object that represents an external service, such as Microsoft 365, AWS, Geo
locations, and more.

URL Filtering
Check Point Software Blade on a Security Gateway that allows granular control over
which web sites can be accessed by a given group of users, computers or networks.
Acronym: URLF.

User Directory
Check Point Software Blade on a Management Server that integrates LDAP and other
external user management servers with Check Point products and security solutions.

VSX
Virtual System Extension. Check Point virtual networking solution, hosted on a computer
or cluster with virtual abstractions of Check Point Security Gateways and other network
devices. These Virtual Devices provide the same functionality as their physical
counterparts.

VSX Gateway
Physical server that hosts VSX virtual networks, including all Virtual Devices that provide
the functionality of physical network devices. It holds at least one Virtual System, which
is called VS0.

R82.10 Gaia Advanced Routing Administration Guide | 755


Glossary

Zero Phishing
Check Point Software Blade on a Security Gateway (R81.20 and higher) that provides
real-time phishing prevention based on URLs. Acronym: ZPH.

R82.10 Gaia Advanced Routing Administration Guide | 756

You might also like