Skip to content

BGP and OSPF

The router speaks BGP and OSPF through BIRD 2, which the installer sets up with routing off. You never edit BIRD’s configuration: you set BGP and OSPF with dtvsol bgp … / dtvsol ospf …, the API or the monitor’s Routing tab, and the router writes /etc/bird/bird.conf for you, checks it with BIRD before loading it, and keeps it in step with its settings.

What it does for an operator:

  • Announce your own address blocks (public IPv4 and IPv6) to one or more upstreams.
  • Take routes from each upstream: only a default route, or the full Internet table.
  • Fail over by itself: a primary and a backup upstream; when the primary goes down, traffic moves to the backup.
  • Blackhole an address under a DDoS attack: the upstreams are asked to drop all traffic to it.
  • iBGP between several Super Routers of the same AS, and OSPF with the other routers of your network.
  • Only your prefixes go out. A peer is sent only the prefixes you list with dtvsol bgp announce add (and the blackholed addresses, to upstreams that have a blackhole community). Nothing else can leak, whatever BIRD learns.
  • Only sane routes come in. From an upstream: a default route, or the full table without private and reserved networks and without anything longer than /24 (IPv4) or /48 (IPv6). Every session has a prefix limit.
  • Every change can be undone. A change that could cut the router off (sessions, prefixes, OSPF) is loaded with a 120-second timer: check that the sessions come back, then dtvsol bgp confirm. Without the confirm, BIRD goes back to the old configuration by itself, and the router’s settings follow. dtvsol bgp undo does it at once. While a change waits, no other change is accepted.
  • Only public blocks can be announced: IPv4 from /8 to /24, IPv6 from /16 to /48.
  1. Your AS number and a router id (an IPv4 address of this router):

    Terminal window
    dtvsol bgp set asn 65010
    dtvsol bgp set router-id XXX.XXX.XXX.2
  2. Your address blocks:

    Terminal window
    dtvsol bgp announce add XXX.XXX.XXX.0/22
    dtvsol bgp announce add XXXX:XXXX::/32
  3. Your upstreams (their address and AS; the password only if they gave you one):

    Terminal window
    dtvsol bgp peer add isp-a XXX.XXX.XXX.1 64500 upstream default primary blackhole 64500:666
    dtvsol bgp peer add isp-b XXX.XXX.XXX.5 64501 upstream default backup password 'secret'
    dtvsol bgp peer add isp-a6 XXXX:XXXX::1 64500 upstream default primary
  4. Turn BGP on, look at the sessions, and keep the change:

    Terminal window
    dtvsol bgp set on
    dtvsol bgp # the sessions should reach Established
    dtvsol bgp confirm # within 120 s, or it is undone

While BGP is off, the settings are saved at once, with no timer: there is nothing to cut yet.

routes What the upstream sends you Memory
default Only its default route. Simple, and failover works the same. Nothing noticeable
full The full Internet table (about 1 million IPv4 and 200,000 IPv6 routes): each destination leaves through the best upstream. About 2 GB more per full-table session

A primary upstream is preferred for traffic going out (local preference 200). A backup upstream gets local preference 50 and your prefixes are sent to it with your AS repeated three times, so the Internet prefers the primary for traffic coming in as well. When the primary’s session goes down, both directions move to the backup by themselves.

BGP’s routes go into the kernel with metric 32. A static default route with a higher metric stays behind them as the fallback. IPv6 static routes usually have metric 1024, so BGP comes first there. An IPv4 static default route without a metric (0) stays in front of BGP: give it a metric above 32 (Settings → Interfaces in the monitor, or dtvsol netcfg) to make BGP the main path.

Without BFD, BGP notices a dead upstream only when its hold timer runs out: 90 to 240 seconds, unless the link itself goes down. With BFD on a peer, the router and the peer check each other every 300 ms, and a silent peer is declared down in under a second (0.9 s in our lab); its routes leave at once and the traffic moves to the other upstream.

Terminal window
dtvsol bgp peer add isp-a XXX.XXX.XXX.1 64500 bfd # nobfd turns it off

The upstream must run BFD on its side too — ask them. dtvsol bgp shows BFD’s state under each peer.

With the full table, a mistaken or hijacked route (someone else announcing your or a big network’s block) would be believed. RPKI checks every route’s origin against the route origin authorisations the address owners signed at their registry (LACNIC, ARIN, RIPE, APNIC, AFRINIC):

Terminal window
dtvsol bgp set rpki on
  • Routes whose origin is proven false (invalid) are dropped from full-table upstreams. Routes with no authorisation (unknown) are kept, as everywhere on the Internet today.
  • The validated data comes from rpki-client, which the installer sets up with all five registries and which runs every hour, on CPU the router leaves idle, while RPKI is on (a run takes about ten minutes). The router reloads the data by itself when it changes.
  • A warning is raised when the data is missing or older than two hours.

When one of your addresses is under attack:

Terminal window
dtvsol bgp blackhole add XXX.XXX.XXX.66

The address is sent as a host route (/32 or /128) to every upstream that has a blackhole community (blackhole <as:n> on the peer: ask your upstream for theirs; 65535:666 is the common one), and the router drops traffic to it too. The subscriber behind it is cut off until you remove it:

Terminal window
dtvsol bgp blackhole del XXX.XXX.XXX.66

A blackhole is loaded at once, without the 120-second timer. Only public addresses can be blackholed.

Several Super Routers of the same AS (one per group of OLTs, for example) can share their routes:

Terminal window
dtvsol bgp peer add sr-2 10.0.0.2 65010 ibgp

Each one sends the other its own prefixes and the routes it learned from its upstreams, with itself as the next hop. A peer on a shared link needs nothing else. For a peer that is not directly connected, add multihop <n> and make sure its address is reachable (OSPF does that).

OSPF learns and tells the routes of your own network with your other routers (IPv4 with OSPFv2, IPv6 with OSPFv3, in one area):

Terminal window
dtvsol ospf iface add vlan20 cost 10 # talk OSPF with the routers on vlan20
dtvsol ospf iface add vlan100 passive # tell vlan100's network, talk to no one there
dtvsol ospf default on # tell the OSPF routers our (BGP) default route
dtvsol ospf on
dtvsol ospf # neighbours should reach Full
dtvsol bgp confirm
  • passive: the interface’s network is announced, but no neighbour is looked for on it (the subscribers’ VLANs, for example).
  • ospf default on: the default route this router has from BGP is announced into OSPF, so the routers behind it send their Internet traffic here.
  • ospf accept-default on: take a default route from OSPF. Leave it off on the border router.
  • ospf area <id>: the area, 0.0.0.0 by default.

OSPF needs the router id (dtvsol bgp set router-id …) but not BGP.

  • BGP session down: critical for a primary upstream, a warning for the others. It stays until the session is Established again.
  • OSPF: no neighbour on an interface: a warning for every active (non-passive) OSPF interface without a full neighbour.
  • bird.service not running is critical while BGP or OSPF is on.

These alarms are in the Network area. The 24/7 wall shows a Routing tile (sessions up, routes received, OSPF neighbours, blackholes) while BGP or OSPF is on.

  • Routing tab: the same, from the browser.
  • Routing API: GET /bgp, POST /bgp/<op>.
  • dtvsol bgp config prints the configuration BIRD runs, with the passwords hidden.

This site was written with the help of AI and checked by our team.