Overview
Introduces BGP flowspec, describing the client-server controller models, feature restrictions, step-by-step configuration for clients and servers, and comprehensive verification procedures covering running configurations, flow details, and operational status on clients
The BGP flowspec is a routing feature that
-
dynamically distributes traffic filtering and policing rules
-
enables granular control over network traffic, and
-
automates threat mitigation across BGP-speaking routers.
You use BGP flowspec primarily to quickly and automatically respond to network threats, especially Distributed Denial-of-Service (DDoS) attacks. This feature allows you to deploy filtering rules rapidly across many routers, stopping attack traffic closer to its source. It provides granular control over traffic, letting you define precise matching criteria and actions. By automating rule deployment through BGP updates, you reduce manual configuration effort and ensure consistent policy enforcement across your network.
BGP Flowspec lets you define multiple matching criteria for identifying specific IP traffic, classifies a packet as part of a flow only if it matches all criteria in the n-tuple, and represents each route as a rule with a match condition (encoded in the NLRI field) and an action (encoded as a BGP extended community). BGP flowspec rules are translated internally into equivalent C3PL policies, which represent the match and action parameters. The supported match and action parameters may vary depending on your platform’s hardware capabilities.
| Feature Name |
Release Information |
Feature Description |
| BGP Flowspec |
Release 25.4.1 | Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*) *This feature is supported on:
|
| BGP Flowspec |
Release 25.3.1 | Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*) *This feature is supported on Cisco 8011-4G24Y4H-I routers. |
| BGP Flowspec |
Release 25.1.1 | Introduced in this release on: Fixed Systems (8700 [ASIC: K100])(select variants only*) *This feature is supported on Cisco 8712-MOD-M routers. |
| BGP Flowspec |
Release 24.4.1 | Introduced in this release on: Fixed Systems (8700) (select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*) You can now rapidly deploy and propagate filtering and policing functionality across many BGP peer routers, which helps to mitigate the effects of a distributed denial-of-service (DDoS) attack on your network. This feature allows you to create detailed instructions for matching specific traffic flows based on various parameters (for example, IP addresses, ports, and packet specifics) and to define actions (such as dropping, policing, or redirecting the traffic) through BGP updates. This helps in effectively managing and mitigating unwanted traffic. *This feature is supported on:
|