You can configure the BGP per segment for a Profile or an Edge. This section provides steps on how to configure BGP with Underlay Neighbors.

VMware supports 4-Byte ASN BGP. See section titled, Configure BGP, for more information.

To enable BGP:

Procedure

  1. In the Enterprise portal, click Configure > Profiles.
  2. Click the Device Icon for a profile, or select a profile and click the Device tab.
  3. In the Device tab, scroll down to the BGP Settings section, click the slider to ON position, and then click Edit.
  4. In the BGP Editor window, configure the following settings:
    1. Click Add Filter to create one or more filters. These filters are applied to the neighbor to deny or change the attributes of the route. The same filter can be used for multiple neighbors.
      In the Create BGP Filter window, set the rules for the filter. See the table below for a description of the fields in the BGP Filter image below.
      Option Description
      Filter Name Enter a descriptive name for the BGP filter.
      Match Type and Value Choose the type of the routes to be matched with the filter:
      • Prefix: Choose to match with a prefix and enter the prefix IP address in the Value field.
      • Community: Choose to match with a community and enter the community string in the Value field.
      Exact Match The filter action is performed only when the BGP routes match exactly with the specified prefix or community string. By default, this option is enabled.
      Action Type Choose the action to be performed when the BGP routes match with the specified prefix or the community string. You can either permit or deny the traffic.
      Set When the BGP routes match the specified criteria, you can set to route the traffic to a network based on the attributes of the path. Select one of the following options from the drop-down list:
      • None: The attributes of the matching routes remain the same.
      • Local Preference: The matching traffic is routed to the path with the specified local preference.
      • Community: The matching routes are filtered by the specified community string. You can also select the Community Additive checkbox to enable the additive option, which appends the community value to existing communities.
      • Metric: The matching traffic is routed to the path with the specified metric value.
      • AS-Path-Prepend: Allows prepending multiple entries of Autonomous System (AS) to a BGP route.
      Click the Plus( +) Icon to add more matching rules for the filter.
      Click OK.
      Repeat the procedure to create more BGP filters.
      The configured filters are displayed in the BGP Editor window.
      Note: The maximum number of supported BGPv4 Match/Set rules is 512 (256 inbound, 256 outbound). Exceeding 512 total Match/Set rules is not supported and may cause performance issues, resulting in disruptions to the enterprise network.
    2. In the BGP Editor window, configure BGP settings. See the table below for a description of the BGP settings.
      Note:
      Option Description
      Local ASN Enter the local Autonomous System Number (ASN)
      Neighbor IP Enter the IP address of the BGP neighbor
      ASN Enter the ASN of the neighbor
      Inbound Filter Select an Inbound filer from the drop-down list
      Outbound Filter Select an Outbound filer from the drop-down list
      Additional Options – Click the view all link to configure the following additional settings:
      Uplink Used to flag the neighbor type to Uplink. Select this flag option if it is used as the WAN overlay towards MPLS. It will be used as the flag to determine whether the site will become a transit site (e.g. SD-WAN Hub), by propagating routes leant over a SD-WAN overlay to a WAN link toward MPLS. If you need to make it a transit site, also check "Overlay Prefix Over Uplink" in the Advanced Settings area.
      Local IP Local IP address is the equivalent of a loopback IP address. Enter an IP address that the BGP neighborships can use as the source IP address for the outgoing packets. If you do not enter any value, the IP address of the physical interface is used as the source IP address.
      Note:
      • For eBGP, this field is available only when Max-hop count is more than 1. For iBGP, it is always available as iBGP is inherently multi-hop.
      • You cannot configure a local IP address if you have selected an Edge interface in the Source Interface drop-down list.
      Source Interface Select an Edge interface configured in the segment as the source interface for BGP.
      Note: This field is available:
      • Only when you choose to override the BGP Settings at the Edge-level.
      • For eBGP, only when Max-hop count is more than 1. For iBGP, it is always available as iBGP is inherently multi-hop.
      Note: You cannot select an Edge interface if you have already configured a local IP address in the Local IP field.
      Max-hop Enter the number of maximum hops to enable multi-hop for the BGP peers. The range is from 1 to 255 and the default value is 1.
      Note: This field is available only for eBGP neighbors, when the local ASN and the neighboring ASN are different. With iBGP, when both ASNs are the same, multi-hop is inherent by default and this field is not configurable.
      Allow AS Select the checkbox to allow the BGP routes to be received and processed even if the Edge detects its own ASN in the AS-Path.
      Default Route The Default Route adds a network statement in the BGP configuration to advertise the default route to the neighbor.
      Enable BFD Enables subscription to existing BFD session for the BGP neighbor.
      Keep Alive Enter the keepalive timer in seconds, which is the duration between the keepalive messages that are sent to the peer. The range is from 0 to 65535 seconds. The default value is 60 seconds.
      Hold Timer Enter the hold timer in seconds. When the keepalive message is not received for the specified time, the peer is considered as down. The range is from 0 to 65535 seconds. The default value is 180 seconds.
      Connect Enter the time interval to try a new TCP connection with the peer if it detects the TCP session is not passive. The default value is 120 seconds.
      MD5 Auth Select the checkbox to enable BGP MD5 authentication. This option is used in a legacy network or federal network, and it is common that BGP MD5 is used as a security guard for BGP peering.
      MD5 Password Enter a password for MD5 authentication. The password should not contain the character $ followed by numbers. For example $1, $123, password$123 are invalid inputs.
      Note: The MD5 authentication fails if the password has the character $ followed by numbers.
      Note: Over Multi-hop BGP, the system might learn routes that require recursive lookup. These routes have a next-hop IP which is not in a connected subnet, and do not have a valid exit interface. In this case, the routes must have the next-hop IP resolved using another route in the routing table that has an exit interface. When there is traffic for a destination that needs these routes to be looked up, routes requiring recursive lookup will get resolved to a connected Next Hop IP address and interface. Until the recursive resolution happens, the recursive routes point to an intermediate interface. For more information, see Multi-hop BGP Routes.
    3. Click the Plus (+) Icon to add more BGP neighbors.
      Note: The 4.3 release supports Non-SD-WAN (NSD) neighbors. To configure BGP with Non SD-WAN Neighbors, see the section titled, Configuring Non-SD-WAN BGP Neighbors
    4. Click Advanced to configure the following advanced settings, which are globally applied to all the BGP neighbors
      Option Description
      Router ID Enter the global BGP router ID. If you do not specify any value, the ID is automatically assigned. If you have configured a loopback interface for the Edge, the IP address of the loopback interface will be assigned as the router ID.
      Keep Alive Enter the keepalive timer in seconds, which is the duration between the keepalive messages that are sent to the peer. The range is from 0 to 65535 seconds. The default value is 60 seconds.
      Hold Timer Enter the hold timer in seconds. When the keepalive message is not received for the specified time, the peer is considered as down. The range is from 0 to 65535 seconds. The default value is 180 seconds.
      Uplink Community

      Enter the community string to be treated as uplink routes.

      Uplink refers to link connected to the Provider Edge (PE). Inbound routes towards the Edge matching the specified community value will be treated as Uplink routes. The Hub/Edge is not considered as the owner for these routes.

      Enter the value in number format ranging from 1 to 4294967295 or in AA:NN format.

      Overlay Prefix Select the checkbox to redistribute the prefixes learned from the overlay.
      Disable AS-Path carry over By default, this should be left unchecked. Select the checkbox to disable AS-PATH Carry Over. In certain topologies, disabling AS-PATH Carry Over will influence the outbound AS-PATH to make the L3 routers prefer a path towards an Edge or a Hub.
      Warning: When the AS-PATH Carry Over is disabled, tune your network to avoid routing loops.
      Connected Routes Select the checkbox to redistribute all the connected Interface subnets.
      OSPF Select the checkbox to enable OSPF redistribute into BGP.
      Set Metric When you enable OSPF, enter the BGP metric for the redistributed OSPF routes. The default value is 20.
      Default Route

      Select the checkbox to redistribute the default route only when Edge learns the BGP routes through overlay or underlay.

      When you select the Default Route option, the Advertise option is available as Conditional.

      Overlay Prefixes over Uplink Select the checkbox to propagate routes learned from overlay to the neighbor with uplink flag.
      Networks Enter the network address that BGP will be advertising to the peers. Click the Plus (+) Icon to add more network addresses.
      When you enable the Default Route option, the BGP routes are advertised based on the Default Route selection globally and per BGP neighbor, as shown in the following table:
      Default Route Selection Advertising Options
      Global Per BGP Neighbor
      Yes Yes The per BGP neighbor configuration overrides the global configuration and hence default route is always advertised to the BGP peer.
      Yes No BGP redistributes the default route to its neighbor only when the Edge learns an explicit default route through the overlay or underlay network.
      No Yes Default route is always advertised to the BGP peer.
      No No The default route is not advertised to the BGP peer.
    5. Click OK.

Results

The BGP Settings section displays the BGP configuration settings.

Click Save Changes in the Device screen to save the configuration.

When you configure BGP settings for a profile, the configuration settings are automatically applied to the SD-WAN Edges that are associated with the profile. If required, you can override the configuration for a specific Edge as follows:

  1. In the Enterprise portal, click Configure > Edges.
  2. Click the Device Icon next to an Edge, or click the link to an Edge and then click the Device tab.
  3. In the Device tab, scroll down to the BGP Settings section.
  4. Select the Enable Edge Override checkbox, and then turn on the BGP Settings.
  5. Click Edit to modify the BGP configuration settings for the selected Edge.

  6. Click Save Changes in the Device screen to save the modified configuration.