BGP Configuration Guide for Cisco 8000 Series Routers, Cisco IOS XR Releases

PDF

BGP Configuration Guide for Cisco 8000 Series Routers, Cisco IOS XR Releases

BGP FIB Out Of Resources mitigation

Want to summarize with AI?

Log in

Explains BGP-driven Forwarding Information Base (FIB) Out-of-Resource (OOR) eviction mechanism, guiding users through route evict parameters configuration to support operational stability. By leveraging a policy-based approach to resource management, network operators can ensure that high-priority services remain reachable during periods of extreme scale, while enabling an automated and controlled recovery once resource pressure subsides.


You will learn how this BGP mechanism protects network stability by selectively evicting BGP routes when hardware resource utilization crosses critical thresholds

Table 1. Feature history table

Feature Name

Release Name

Description

BGP FIB Out Of Resources mitigation

Release 26.3.1

Introduced in this release on: Fixed Systems (8010 [ASIC: A100]), (8200 [ASIC: Q100, Q200], (8700 [ASIC: K100]) (select variants only*)

When the IOS-XR Forwarding Information Base (FIB) approaches hardware resource limits, the system employs a BGP-driven eviction mechanism to maintain operational stability. This process ensures that system performance is preserved by selectively removing routes rather than suffering unpredictable hardware-level failures.


FIB Out Of Resources mitigation mechanism

FIB Out Of Resources mitigation mechanism is a network stability feature that:

  • facilitates an automated and controlled recovery

  • uses a policy-based approach to resource management

  • reinstates routes automatically once resource pressure subsides

These mechanisms help optimize routing stability and hardware resource usage:

Centralized Resource Monitoring: The Routing Information Base (RIB) acts as the primary monitor for hardware utilization. It continuously tracks the state of the FIB, providing the necessary telemetry to trigger protective actions when thresholds are crossed.

Policy-Driven Eviction: BGP route eviction is governed by a user-configured eviction route-policy defined under the address family. This approach allows administrators to:

  • Protect critical infrastructure (P1 routes) from being evicted.

  • Minimize network disruption by prioritizing the removal of lower-priority prefixes.

  • Ensure that only specific, non-essential traffic paths are affected during high-load scenarios.

Controlled Recovery Lifecycle: The eviction process is dynamic and reversible:

  • Trigger: When FIB resources reach a critical state, BGP evicts routes based on the active policy to reclaim space.

  • Monitoring: The system maintains continuous surveillance of resource usage.

  • Recovery: Once hardware utilization returns to an optimal state (Green status), the eviction process concludes, and the RIB begins the process of re-instating routes to return the system to its full, steady-state configuration.


ORR states and thresholds

These Out-of-Resource state transitions and thresholds ensure that:

  • an automated and controlled recovery is facilitated

  • Provides essential stability by preventing rapid state oscillations during periods of fluctuating resource pressure

  • Eviction Accuracy: BGP receives direct, actionable information to make informed eviction decisions based on current resource utilization.

  • Recovery Synchronization: The platform precisely governs the timing of route recovery to match the hardware's capacity to re-absorb prefix loads.

  • Stability: The implementation of hysteresis and timers provides essential stability by preventing rapid state oscillations (flapping) during periods of fluctuating resource pressure.


Configure FIB Out Of Resources mitigation

Configure a route policy to enable ORR and specify route eviction parameters such as timer and threshold to provide essential stability by preventing rapid state oscillations (flapping) during periods of fluctuating resource pressure.

The oor out-of-programming-resources command enables FIB OOR route-eviction feature.

Before you begin

An OOR route-policy is required under the global AF for this feature to function.

Procedure

  1. Enable OOR via route policy.

    Example:

    
    router bgp <as>
    address-family <afi> <safi>
    oor route-policy <policy_name>
    

    The eviction mechanism must be enabled under the desired address family to link specific route-policy criteria to the OOR process. This can be applied globally or per VRF.

  2. Configure route eviction parameters.

    Example:

    RP/0/0/CPU0:R2(config-bgp)#oor out-of-programming-resources

    Beyond the policy, you must enable the OOR feature and define recovery behaviors. BGP provides a dedicated sub-mode for fine-tuning how the system responds to resource pressure.

  3. Configure route eviction recovery threshold.

    Example:

    RP/0/0/CPU0:R2(config-bgp)#oor route-eviction max-recovery-retries <number>

    Sets the maximum number of OOR events allowed per hour before the system ceases recovery attempts. Use clear bgp oor recovery to manually reset this state.

  4. Configure route eviction timer.

    Example:

    
    RP/0/0/CPU0:R2(config-bgp)#oor route-eviction timers eviction-timer <seconds>
    RP/0/0/CPU0:R2(config-bgp)#oor route-eviction timers recovery-timer <seconds>

    Sets the duration resources must remain in the Red range before triggering eviction as eviction timer, or the Green range before triggering restoration as recovery timer.

    If a timer value configuration command executes while the timer is running, the changed value will take effect next time the timer starts. The time of the running timer will not change.

    The exception is if the recovery-timer value is extended. its new configured value is longer than its previous value. Then if the timer is currently running, the current run time will be extended.


Verify FIB Out Of Resources mitigation

  • Displays prefixes that BGP has identified as eligible for eviction based on the configured route-policy.

  • Displays real-time and historical statistics related to the route-eviction process.

Procedure

  1. Use the show bgp [vrf <name>] [<afi> <safi>] evictable-prefixes command to verify the prefixes BGP has in its table and will run the policy to show the users their evictable routes.

    Example:

    
    router#show bgp [vrf <name>] [<afi> <safi>] evictable-prefixes
    Thu Oct  2 16:11:39.239 PDT
    BGP router identifier 192.168.0.2, local AS number 10
    BGP generic scan interval 60 secs
    Non-stop routing is enabled
    BGP table state: Active
    Table ID: 0xe0000000   RD version: 14
    BGP main routing table version 14
    BGP NSR Initial initsync version 10 (Reached)
    BGP NSR/ISSU Sync-Group versions 0/0
    BGP scan interval 60 secs
    
    Status codes: s suppressed, d damped, h history, * valid, > best
                  i - internal, r RIB-failure, S stale, N Nexthop-discard
    Origin codes: i - IGP, e - EGP, ? - incomplete
    Route Eviction codes: N never, F first, S second, n not evictable or no eviction policy, ? unknown
        Network            Next Hop            Metric LocPrf Weight Path
    N*> 10.10.10.0/24      0.0.0.0                  0         32768 ?
    N* i                   10.10.10.1               0    100      0 ?
    N*> 11.11.11.0/24      0.0.0.0                  0         32768 ?
    N*>i192.168.0.1/32     10.10.10.1               0    100      0 ?
    N*> 192.168.0.2/32     0.0.0.0                  0         32768 ?
    F*>i200.1.1.1/32       11.11.11.3                    100      0 i
    S*>i200.1.1.2/32       11.11.11.3                    100      0 i
    N*>i200.1.1.3/32       11.11.11.3                    100      0 i
    N*>i200.1.1.4/32       11.11.11.3                    100      0 i
    Processed 6 prefixes, 7 paths
    

    Routes that are not evictable include: sourced routes (redistributed or network), permanent, received-only, aggregate. The other reason for ā€˜n’ is if there is no eviction route-policy applicable to the route.

    If you are missing a configuration like the policy or out-of-programming-resources you will see a message like so at the top: OOR eviction-policy CLI is configured but has no effect because out-of-programming-resources is not configured under BGP or OOR out-of-programming-resources CLI is configured but has no effect because there is no eviction-policy under a supported global AF.

  2. Use the show bgp ipv4 unicast command to display the evictable information for the path as part of:

    Example:

    
    RP/0/0/CPU0:R2#show bgp ipv4 unicast 200.1.1.1
    Thu Oct 16 12:04:57.585 PDT
    BGP routing table entry for 200.1.1.1/32
    Versions:
      Process           bRIB/RIB   SendTblVer
      Speaker                 21           21
    Last Modified: Oct 16 11:51:15.000 for 00:13:42
    Paths: (3 available, best #1)
      Not advertised to any peer
      Path #1: Received by speaker 0
      Not advertised to any peer
      Local
        11.11.11.3 from 11.11.11.3 (11.11.11.3)
          Origin IGP, localpref 100, valid, internal, best, group-best
          Received Path ID 0, Local Path ID 1, version 21
          Eviction Priority: NEVER
      Path #2: Received by speaker 0
      Not advertised to any peer
      Local
        11.11.12.3 from 11.11.12.3 (11.11.12.3)
          Origin IGP, localpref 100, valid, internal
          Received Path ID 0, Local Path ID 0, version 0
          Eviction Priority: NEVER
    

    If a route is not evictable or no eviction route-policy applies to the route, then an Eviction Priority is not shown.

  3. Use the show bgp [vrf <name>] OOR statistics command to display route-eviction process information such as timestamps and evicted route counts.

    Example:

    
    router#show bgp [vrf <name>] OOR statistics
    VRF: default
    OOR State changes per resource:
       Resource type: IPv4_Prefix_Host
        Current OOR state               : No_OOR
        Current OOR usage               : Green
        Last green notification         : Nov  8 15:03:23.047
        Last yellow notification        : ---
        Last red notification           : Nov  8 15:01:04.614
        Last NO_OOR state change        : Nov  8 15:04:05.196
        Last EVICT_DELAY state change   : Nov  8 15:01:04.614
        Last EVICTING_P3 state change   : Nov  8 15:01:09.615
        Last EVICTED_YELLOW state change: ---
        Last EVICTING_P2 state change   : Nov  8 15:03:09.616
        Last RECOVERY_P3 state on       : ---
        Last RECOVERY_P2 state on       : Nov  8 15:03:23.047
    
    [repeated for all resource types]
    
    Global Timers:
       Last time red timer was started            : Nov  8 15:01:09.632
       Last time red timer expired                : Nov  8 15:03:09.616
       Last time eviction timer was started       : Nov  8 15:01:04.614
       Last time eviction timer expired           : Nov  8 15:01:09.615
       Last time recovery count timer was started : Nov  8 14:59:55.139
       Last time recovery count timer expired     : Nov  8 15:04:05.196
       Last time recovery timer was started       : Nov  8 15:03:23.047
       Last time recovery timer expired           : Nov  8 15:03:33.049
       Number of Recoveries attempted out of max  : 0/999 (if equal execute "clear bgp oor recovery" to force the recovery)
    
    Routes are either evicted during a BGP table walk or blocked from being installed during route updates.
    Per AFI eviction route counts:      Current      |     Previous
                                 : Evicted | Blocked | Evicted | Blocked
        IPv4 Unicast P3          :       4 |       0 |       0 |       0
        IPv4 Unicast P2          :       2 |       0 |       0 |       0
       VPNv4 Unicast P3 remote RD:       0 |       0 |       0 |       0
       VPNv4 Unicast P2 remote RD:       0 |       0 |       0 |       0
       VPNv4 Unicast P3 local RD :       0 |       0 |       0 |       0
       VPNv4 Unicast P2 local RD :       0 |       0 |       0 |       0
        IPv6 Unicast P3          :       0 |       0 |       0 |       0
        IPv6 Unicast P2          :       0 |       0 |       0 |       0