Describes methods for implementing routing policies including BGP route filtering, community advertisements, remotely triggered blackhole filtering, attribute filtering, error handling, and advanced policy configurations to enhance network security and control.
You will learn how to apply these BGP policy and filtering methods to enhance network security and control.
Routing policy enforcement
Explains how configuring inbound and outbound policies for eBGP neighbors prevents accidental route acceptance or advertisement and enhances security by enforcing routing policies.
Table policy
Describes configuring traffic index values on routes to support policy accounting and selectively drop routes from the routing table based on match criteria.
Policy-based aggregate route management
Explains configuring aggregate routes and marking specific routes as aggregate contributors to control route aggregation and advertisement via route policies.
Remotely triggered blackhole filtering
Describes a technique that drops undesirable traffic at the network edge by forwarding it to a null interface, mitigating attacks and enforcing blocklist filtering.
BGP community and extended-community advertisements
Explains the use of BGP communities and extended communities to tag routes for policy enforcement and traffic management.
BGP attribute filters
Describes filtering BGP routes based on attributes to control route acceptance and advertisement.
Syslog messages for BGP attribute filtering
Explains syslog messages generated during BGP attribute filtering to assist in monitoring and troubleshooting.
BGP update message error management
Explains handling errors in BGP update messages to maintain routing stability and integrity.
User-defined Martian address check
Describes configuring checks for user-defined Martian addresses to prevent invalid routes from propagating.
BGP private AS number management
Explains managing private autonomous system numbers in BGP to ensure proper route handling and policy enforcement.
Private AS number removal in iBGP advertisements
Explains the functionality of removing private AS numbers from iBGP advertisements only when it is safe to do so, helping prevent routing loops and supporting scenarios where eBGP boundary removal is not sufficient.
Conditional matching on transitive and non-transitive bandwidth extended communities in BGP RPL
Describes conditional matching techniques for bandwidth extended communities in BGP route policies to enable granular traffic control.
VPN route limit on route reflectors
Explains configuring route reflectors to limit the number of routes accepted per VPN to optimize resource usage and maintain performance.