Border Gateway Protocol (BGP) automates the exchange of routing information between autonomous systems (AS) to determine optimal paths for data traffic and failover routing without the need to configure and maintain static routes.
When setting up a network tunnel group in Secure Access, choose dynamic routing if you have a BGP peer for your on-premise router. Dynamic routing using BGP enables the advertisement of customer-specific routes, which is essential for Secure Access tunnels to properly route return traffic to your networks. Without these routes, return traffic cannot be routed correctly.
For more information about BGP, refer to Cisco Support documentation topics Select BGP Best Path Algorithm and Examine Border Gateway Protocol Case Studies
For Secure Access configuration details, refer to Add a Network Tunnel Group, View Network Tunnel Group Details, and Secure Access Regions.
Advantages of Dynamic Routing with BGP
-
Automatic Route Updates—Route changes on the customer side are automatically communicated to Secure Access, eliminating the need for manual updates in the dashboard settings.
-
Dynamic Failover—If a tunnel on the Secure Access side becomes unavailable, routes sent to the customer dynamically adjust, enabling seamless failover to a secondary tunnel.
BGP Peer Route Limitations
Exceeding the 10k routes per BGP peer limit resets the BGP connection and blocked further requests to use BGP on that network group tunnel. Review the following limitation for any specific environment limitations or recommendations:
Exceeding the route limitations resets the BGP connection and blocks further requests to use BGP on that network group tunnel.
Secure Access BGP Configuration Best Practices
Tunnel Redundancy and High Availability Principles
-
A single network tunnel group can support multiple IPsec tunnels to achieve redundancy and high availability.
-
For optimal redundancy, maintain a 1-to-1 correspondence between primary and secondary IPsec tunnels. For example, if you configure six primary IPsec tunnels to a data center for Equal-Cost Multi-Path (ECMP), you should have six corresponding secondary IPsec tunnels to ensure full redundancy. This setup requires one BGP connection per IPsec tunnel.
BGP Peer IP Addresses
-
Secure Access (SSE) Side—Secure Access uses IP addresses within the 169.254.0.0/24 range for BGP peering. For example, the primary data center might use 169.254.0.5 and the secondary data center 169.254.0.9.
-
Customer Side—For ease of configuration, it is recommended to use corresponding IP addresses within the 169.254.0.0/24 range (e.g., 169.254.0.6 for 169.254.0.5, and 169.254.0.10 for 169.254.0.9). However, the customer-side IP address range is not restricted to 169.254.0.0/24 and can be different.
BGP Identifier (Router ID)
-
Do not use 169.254.0.1 as the BGP identifier.
-
For the customer-side BGP identifier, use the local router's gateway address (typically an RFC1918 address, e.g., 192.168.x.x). Avoid using addresses within the 169.254.0.0/24 range. Note that some devices refer to the BGP identifier as the Router ID.
Customer Autonomous System Number (ASN)—Use any private BGP ASN within the range 64512–65534.
Note
eBGP peering can only happen between devices with different ASNs.
All newly created Secure Access organizations use the public ASN 32644 by default for BGP peering in network tunnel groups. Existing organizations established prior to November 2025 continue to use the private ASN 64512 that was previously reserved for Secure Access BGP peers.
If the private AS number 64512 is assigned to a device on your network, it will not be able to peer with a network tunnel group configured for Peer (Secure Access) BGP AS64512.
To identify the AS number used by your network tunnel groups, navigate to , click a network tunnel group by name, and check the field Peer (Secure Access) BGP AS to identify the ASN.
If your organization requires a different ASN, contact Cisco Secure Access support to request an update. For more details, refer Welcome to Cisco Secure Access. Note that changing the ASN is a global setting and will affect all network tunnel groups and BGP peering relationships for your Secure Access organization.
Route Advertisement by Secure Access—Secure Access advertises multiple routes for various services and components. To ensure the correct return path for traffic, separate routes are advertised for each region in use. The number of routes advertised will scale depending on the type of features deployed and the number of regions used by end users. The table below details the types of routes Secure Access advertises:
Table 2. Route Advertisement by Secure Access
| Destination Address |
Route Size |
Purpose / Number of routes |
|
35.95.175.78
44.240.251.165
|
/32 |
Secure Access speedtest tool |
| 100.64.0.0/10 |
/32 |
ZTA Proxy servers (several /32 prefixes in each region utilised by ZTA users)
Resource connector (one /32 prefix per connector)
|
| 100.64.0.0/10 |
/28 |
Network tunnel groups in NAT mode (several /28 prefixes, with the NAT prefix shared in common by multiple tunnels) |
| 240.0.0.0/28 |
/32 |
Resource connector (legacy connector groups) |
| System IP Pool |
/32 |
Remote Access VPN servers (two /32 prefixes or more in each configured region) |
| User VPN Pool |
/22 or smaller |
Each pool separated into a minimum of two or more smaller pools (maximum prefix of /22 per chunk) to support high availability and scaling |
| Other Branches |
- |
Routes advertised by other network tunnel branches (depends on customer configuration) |
Routes advertised by Secure Access prepend the original AS path to include:
-
1 for primary tunnels
-
2 for secondary tunnels
This preserves the original AS path and allows customers to install all received routes in their Forwarding Information Base (FIB) and switch between primary and secondary routes based on their routing decisions.
Connecting Multiple High Availability (HA) Devices to Secure Access—Secure Access supports connecting multiple HA routers from the same branch, whether in Active/Active or Active/Standby mode.
-
All IPsec tunnels from all HA routers must belong to the same Network Tunnel Group.
-
Devices should advertise the same set of routes to Secure Access.
-
Use AS path length to define device priority:
-
For Active/Active mode, use the same AS path length for all routes advertised by both devices.
-
For Active/Standby mode, advertise routes from your Active device with a shorter AS path length (e.g., length of 1 for Active, 2 for Standby).
-
You can connect as many HA routers as needed, but a Network Tunnel Group is limited to a maximum of 20 IPsec tunnels overall (10 IPsec tunnels to the primary data center and 10 to the secondary).
-
You can aggregate IPsec tunnels from different devices within the same network tunnel group if those devices are part of a HA pair (either Active/Active or Active/Standby mode).
-
Do not aggregate multiple IPsec tunnels from different devices that are not part of an HA pair within the same network tunnel group.
Block Default Route Advertisement
Advertising default routes via BGP from the customer to Secure Access is not supported and can lead to traffic disruptions. You can block default route advertisements from Secure Access to the customer site.
-
From the Secure Access dashboard, go to .
-
In the Advanced Settings of the network tunnel group routing configuration, check Block default route advertisement.
Avoid Router ID and BGP Peer Conflicts
BGP requires a Router ID to establish BGP sessions between peers. Without a unique Router ID, BGP cannot establish peering sessions. When configuring Secure Access network tunnel groups, you can use the same BGP peer IP addresses for any or all of your network tunnel groups within the same region. However, the BGP Router ID must be unique to each BGP peer within a network. Each router in the network must have a unique Router ID.
Monitor BGP Client and Cloud Routes
To view BGP client routes received from your customer-side network:
-
Navigate to .
-
Click on a specific network tunnel to open its details pane on the right-hand side of the page.
-
The Client Routes section displays the routes received from your network.
-
Routes are visible on the primary tunnels. If multiple primary tunnels advertise the same route, the route will appear on each of those primary tunnels.
All other routes for your organization (those not originating from a primary tunnel) are displayed in the Cloud routes section of the network tunnel details pane.