BGP and OSPF
The router speaks BGP and OSPF through BIRD 2, which the installer sets up with routing off.
You never edit BIRD’s configuration: you set BGP and OSPF with dtvsol bgp … / dtvsol ospf …,
the API or the monitor’s Routing tab, and
the router writes /etc/bird/bird.conf for you, checks it with BIRD before loading it, and keeps
it in step with its settings.
What it does for an operator:
- Announce your own address blocks (public IPv4 and IPv6) to one or more upstreams.
- Take routes from each upstream: only a default route, or the full Internet table.
- Fail over by itself: a primary and a backup upstream; when the primary goes down, traffic moves to the backup.
- Blackhole an address under a DDoS attack: the upstreams are asked to drop all traffic to it.
- iBGP between several Super Routers of the same AS, and OSPF with the other routers of your network.
Safe by design
Section titled “Safe by design”- Only your prefixes go out. A peer is sent only the prefixes you list with
dtvsol bgp announce add(and the blackholed addresses, to upstreams that have a blackhole community). Nothing else can leak, whatever BIRD learns. - Only sane routes come in. From an upstream: a default route, or the full table without private and reserved networks and without anything longer than /24 (IPv4) or /48 (IPv6). Every session has a prefix limit.
- Every change can be undone. A change that could cut the router off (sessions, prefixes,
OSPF) is loaded with a 120-second timer: check that the sessions come back, then
dtvsol bgp confirm. Without the confirm, BIRD goes back to the old configuration by itself, and the router’s settings follow.dtvsol bgp undodoes it at once. While a change waits, no other change is accepted. - Only public blocks can be announced: IPv4 from /8 to /24, IPv6 from /16 to /48.
Setting up BGP
Section titled “Setting up BGP”-
Your AS number and a router id (an IPv4 address of this router):
Terminal window dtvsol bgp set asn 65010dtvsol bgp set router-id XXX.XXX.XXX.2 -
Your address blocks:
Terminal window dtvsol bgp announce add XXX.XXX.XXX.0/22dtvsol bgp announce add XXXX:XXXX::/32 -
Your upstreams (their address and AS; the password only if they gave you one):
Terminal window dtvsol bgp peer add isp-a XXX.XXX.XXX.1 64500 upstream default primary blackhole 64500:666dtvsol bgp peer add isp-b XXX.XXX.XXX.5 64501 upstream default backup password 'secret'dtvsol bgp peer add isp-a6 XXXX:XXXX::1 64500 upstream default primary -
Turn BGP on, look at the sessions, and keep the change:
Terminal window dtvsol bgp set ondtvsol bgp # the sessions should reach Establisheddtvsol bgp confirm # within 120 s, or it is undone
While BGP is off, the settings are saved at once, with no timer: there is nothing to cut yet.
Default route or full table
Section titled “Default route or full table”routes |
What the upstream sends you | Memory |
|---|---|---|
default |
Only its default route. Simple, and failover works the same. | Nothing noticeable |
full |
The full Internet table (about 1 million IPv4 and 200,000 IPv6 routes): each destination leaves through the best upstream. | About 2 GB more per full-table session |
Primary and backup
Section titled “Primary and backup”A primary upstream is preferred for traffic going out (local preference 200). A backup upstream gets local preference 50 and your prefixes are sent to it with your AS repeated three times, so the Internet prefers the primary for traffic coming in as well. When the primary’s session goes down, both directions move to the backup by themselves.
BGP and the default route
Section titled “BGP and the default route”BGP’s routes go into the kernel with metric 32. A static default route with a higher metric
stays behind them as the fallback. IPv6 static routes usually have metric 1024, so BGP comes first
there. An IPv4 static default route without a metric (0) stays in front of BGP: give it a
metric above 32 (Settings → Interfaces in the monitor, or dtvsol netcfg) to make BGP the main
path.
BFD: failover in under a second
Section titled “BFD: failover in under a second”Without BFD, BGP notices a dead upstream only when its hold timer runs out: 90 to 240 seconds, unless the link itself goes down. With BFD on a peer, the router and the peer check each other every 300 ms, and a silent peer is declared down in under a second (0.9 s in our lab); its routes leave at once and the traffic moves to the other upstream.
dtvsol bgp peer add isp-a XXX.XXX.XXX.1 64500 bfd # nobfd turns it offThe upstream must run BFD on its side too — ask them. dtvsol bgp shows BFD’s state under each
peer.
RPKI: drop routes with a false origin
Section titled “RPKI: drop routes with a false origin”With the full table, a mistaken or hijacked route (someone else announcing your or a big network’s block) would be believed. RPKI checks every route’s origin against the route origin authorisations the address owners signed at their registry (LACNIC, ARIN, RIPE, APNIC, AFRINIC):
dtvsol bgp set rpki on- Routes whose origin is proven false (
invalid) are dropped from full-table upstreams. Routes with no authorisation (unknown) are kept, as everywhere on the Internet today. - The validated data comes from
rpki-client, which the installer sets up with all five registries and which runs every hour, on CPU the router leaves idle, while RPKI is on (a run takes about ten minutes). The router reloads the data by itself when it changes. - A warning is raised when the data is missing or older than two hours.
Blackhole for DDoS
Section titled “Blackhole for DDoS”When one of your addresses is under attack:
dtvsol bgp blackhole add XXX.XXX.XXX.66The address is sent as a host route (/32 or /128) to every upstream that has a blackhole community
(blackhole <as:n> on the peer: ask your upstream for theirs; 65535:666 is the common one), and
the router drops traffic to it too. The subscriber behind it is cut off until you remove it:
dtvsol bgp blackhole del XXX.XXX.XXX.66A blackhole is loaded at once, without the 120-second timer. Only public addresses can be blackholed.
iBGP between Super Routers
Section titled “iBGP between Super Routers”Several Super Routers of the same AS (one per group of OLTs, for example) can share their routes:
dtvsol bgp peer add sr-2 10.0.0.2 65010 ibgpEach one sends the other its own prefixes and the routes it learned from its upstreams, with itself
as the next hop. A peer on a shared link needs nothing else. For a peer that is not directly
connected, add multihop <n> and make sure its address is reachable (OSPF does that).
OSPF learns and tells the routes of your own network with your other routers (IPv4 with OSPFv2, IPv6 with OSPFv3, in one area):
dtvsol ospf iface add vlan20 cost 10 # talk OSPF with the routers on vlan20dtvsol ospf iface add vlan100 passive # tell vlan100's network, talk to no one theredtvsol ospf default on # tell the OSPF routers our (BGP) default routedtvsol ospf ondtvsol ospf # neighbours should reach Fulldtvsol bgp confirmpassive: the interface’s network is announced, but no neighbour is looked for on it (the subscribers’ VLANs, for example).ospf default on: the default route this router has from BGP is announced into OSPF, so the routers behind it send their Internet traffic here.ospf accept-default on: take a default route from OSPF. Leave it off on the border router.ospf area <id>: the area,0.0.0.0by default.
OSPF needs the router id (dtvsol bgp set router-id …) but not BGP.
Alarms and the wall
Section titled “Alarms and the wall”- BGP session down: critical for a primary upstream, a warning for the others. It stays until the session is Established again.
- OSPF: no neighbour on an interface: a warning for every active (non-passive) OSPF interface without a full neighbour.
- bird.service not running is critical while BGP or OSPF is on.
These alarms are in the Network area. The 24/7 wall shows a Routing tile (sessions up, routes received, OSPF neighbours, blackholes) while BGP or OSPF is on.
See also
Section titled “See also”- Routing tab: the same, from the browser.
- Routing API:
GET /bgp,POST /bgp/<op>. dtvsol bgp configprints the configuration BIRD runs, with the passwords hidden.
This site was written with the help of AI and checked by our team.