To enable access between your VMs and the outside world, you can configure an external or internal BGP (eBGP/iBGP) connection between a tier-0 logical router and a router in your physical infrastructure.
When configuring eBGP, you must configure a local Autonomous System (AS) number for the tier-0 logical router. For example, the following topology shows the local AS number is 64510. You must also configure the remote AS number of the physical router. In this example, the remote AS number is 64511. The remote neighbor IP address is 192.168.100.254. The neighbor must be in the same IP subnet as the uplink on the tier-0 logical router. BGP multi-hop is supported.
For test purposes, the 10.10.10.10/32 address is configured on the external router loopback interface.
A tier-0 logical router in active-active mode supports inter-SR (service router) routing. If router #1 is unable to communicate with a northbound physical router, traffic is re-routed to router #2 in the active-active cluster. If router #2 is able to communicate with the physical router, traffic between router #1 and the physical router will not be affected.
- In the case of a static route configured on one SR (for example, SR #1 on Edge node #1), another SR (for example, SR #2 on Edge node #2) might learn the same route from an eBGP peer and prefer the learned route to the static route on SR #1, which might be more efficient. To ensure that SR #2 uses the static route configured on SR #1, configure the tier-1 logical router in pre-emptive mode and configure Edge node #1 as the preferred node.
- If the tier-0 logical router has an uplink port on Edge node #1 and another uplink port on Edge node #2, ping traffic from tenant VMs to the uplinks works if the two uplinks are in different subnets. Ping traffic will fail if the two uplinks are in the same subnet.
- With only BGP configured, if all BGP neighbors go down, the service router's state will be down.
- With only BFD configured, if all BFD neighbors go down, the service router's state will be down.
- With BGP and BFD configured, if all BGP and BFD neighbors go down, the service router's state will be down.
- With BGP and static routes configured, if all BGP neighbors go down, the service router's state will be down.
- With only static routes configured, the service router's state will always be up unless the node is experiencing a failure or in a maintenance mode.
- Verify that the tier-1 router is configured to advertise connected routes. See Configure Route Advertisement on a Tier-1 Logical Router. This is not strictly a prerequisite for BGP configuration, but if you have a two-tier topology and you plan to redistribute your tier-1 networks into BGP, this step is required.
- Verify that a tier-0 router is configured. See Create a Tier-0 Logical Router.
- Make sure the tier-0 logical router has learned routes from the tier-1 logical router. See Verify that a Tier-0 Router Has Learned Routes from a Tier-1 Router.
- From your browser, log in with admin privileges to an NSX Manager at https://<nsx-manager-ip-address>.
- Select .
- Select the tier-0 logical router.
- Click the Routing tab and select BGP from the drop-down menu.
- Click Edit.
- Enter the local AS number.
For example, 64510.
- Click the Status toggle to enable or disable BGP.
- Click the ECMP toggle to enable or disable ECMP.
- Click the Graceful Restart toggle to enable or disable graceful restart.
Graceful restart is only supported if the NSX Edge cluster associated with the tier-0 router has only one edge node.
- If this logical router is in active-active mode, click the Inter SR Routing toggle to enable or disable inter-SR routing.
- Configure route aggregation.
- Click Save.
- Enter the local AS number.
- Click Add to add a BGP neighbor.
- Enter the neighbor IP address.
For example, 192.168.100.254.
- Specify the maximum hop limit.
The default is 1.
- Enter the remote AS number.
For example, 64511.
- Configure the timers (keep alive time and hold down time) and a password.
- Click the Local Address tab to select a local address.
- (Optional) Uncheck All Uplinks to see loopback ports as well as uplink ports.
- Click the Address Families tab to add an address family.
- Click the BFD Configuration tab to enable BFD.
- Click Save.
What to do next
Test whether BGP is working properly. See Verify BGP Connections from a Tier-0 Service Router.