ESR service routers. ESR-Series. Functionality description. Version 1.12.0
150
Configure the firewall to receive BGP traffic from the WAN security zone
esr-R3(config)# object-group service og_bgp
esr-R3(config-object-group-service)# port-range
179
esr-R3(config-object-group-service)# exit
esr-R3(config)# security zone wan
esr-R3(config-zone)# exit
esr-R3(config)# security zone-pair wan self
esr-R3(config-zone-pair)# rule
100
esr-R3(config-zone-pair-rule)# match protocol tcp
esr-R3(config-zone-pair-rule)# match destination-port og_bgp
esr-R3(config-zone-pair-rule)# action permit
esr-R3(config-zone-pair-rule)# enable
esr-R3(config-zone-pair-rule)# exit
esr-R3(config-zone-pair)# exit
Specify that the interfaces belong to the security zone
esr-R3(config)#
interface
gigabitethernet
1
/
0
/
1
esr-R3(config-
if
-gi)# security-zone wan
esr-R3(config-
if
-gi)# exit
esr-R3(config)#
interface
gigabitethernet
1
/
0
/
2
esr-R3(config-
if
-gi)# security-zone wan
esr-R3(config-
if
-gi)# exit
Create a route-map, which will be used later when configuring enabling advertising to routers from another AS
esr-R3(config)# route-map bgp-general
esr-R3(config-route-map)# rule
1
esr-R3(config-route-map-rule)# match ip address
80.66
.
0.0
/
24
esr-R3(config-route-map-rule)# match ip address
80.66
.
16.0
/
24
esr-R3(config-route-map-rule)# action permit
esr-R3(config-route-map-rule)# exit
esr-R3(config-route-map)# exit
Create BGP process for AS 2500 and enter process parameters' configuration mode:
esr(config)# router bgp
2500
Configure advertising of directly connected subnets:
esr-R3(config-bgp)# address-family ipv4 unicast
esr-R3(config-bgp-af)# redistribute connected
esr-R3(config-bgp-af)# exit
Create neighborhood with R2 router via iBGP
esr-R3(config-bgp)# neighbor
219.0
.
0.2
esr-R3(config-bgp-neighbor)# remote-as
2500
esr-R3(config-bgp-neighbor)# enable