+----+ as1r1 +--\---/--+ IX1 +--+ as2r +--+ as2c
+ + \ /
as1c |CARP X
+ + / \
+----+ as1r2 +--/---\--+ IX2 +--+ as3r +--+ as3c
| Hostname | IPv4 | AS |
|---|---|---|
| as1r | 10.10.10.1 /29 | 65001 |
| as1c | 10.10.10.2 /29 | 65001 |
| as2r | 10.10.10.9 /29 | 65002 |
| as2c | 10.10.10.10 /20 | 65002 |
| as3r | 10.10.10.17 /29 | 65003 |
| as3c | 10.10.10.18 /29 | 65003 |
| AS | Network |
|---|---|
| 65001 | 10.10.10.0 /29 |
| 65002 | 10.10.10.8 /29 |
| 65003 | 10.10.10.16 /29 |
| Hostname | IPv4 | IX |
|---|---|---|
| as1r | 10.10.10.25 /29 | 1 |
| as2r | 10.10.10.26 /29 | 1 |
| as1r | 10.10.10.33 /29 | 2 |
| as3r | 10.10.10.34 /29 | 2 |
Apply this config on all routers:
echo net.inet.ip.forwarding=1 >>/etc/sysctl.conf
sysctl net.inet.ip.forwarding=1
Hosts list for the clients:
cat <<EOF>> /etc/hosts
10.10.10.1 as1r
10.10.10.25 as1r
10.10.10.33 as1r
10.10.10.2 as1c
10.10.10.9 as2r
10.10.10.26 as2r
10.10.10.10 as2c
10.10.10.17 as3r
10.10.10.34 as3r
10.10.10.18 as3c
EOF
echo net.inet.carp.preempt=1 >>/etc/sysctl.conf
sysctl net.inet.carp.preempt=1
CARP:
echo up >/etc/hostname.vio1
echo up >/etc/hostname.vio2
echo up >/etc/hostname.vio3
echo inet 10.10.10.1 255.255.255.248 NONE vhid 1 carpdev vio1 pass lanpasswd >/etc/hostname.carp0
echo inet 10.10.10.25 255.255.255.248 NONE vhid 2 carpdev vio2 pass lanpasswd >/etc/hostname.carp1
echo inet 10.10.10.33 255.255.255.248 NONE vhid 3 carpdev vio3 pass lanpasswd >/etc/hostname.carp2
pfsync:
echo up syncdev vio0 >/etc/hostname.pfsync0
Reload network: sh /etc/netstart
cat <<EOF> /etc/pf.conf
pass quick on { vio0 } proto pfsync keep state (no-sync)
pass on { vio1 vio2 vio3 } proto carp keep state (no-sync)
EOF
pfctl -f /etc/pf.conf
cat <<EOF> /etc/bgpd.conf
AS 65001
listen on <address of vio0>
listen on 10.10.10.25
listen on 10.10.10.33
log updates
router-id 10.10.10.1
network 10.10.10.0/29
neighbor 10.10.10.26 {
remote-as 65002
descr "as2r"
log updates
depend on carp1
}
neighbor 10.10.10.34 {
remote-as 65003
descr "as3r"
log updates
depend on carp2
}
neighbor <address of as1r2:vio0> {
remote-as 65001
descr "carp_sync"
}
allow from any
allow to any
EOF
rcctl enable bgpd
rcctl start bgpd
echo net.inet.carp.preempt=1 >>/etc/sysctl.conf
sysctl net.inet.carp.preempt=1
CARP:
echo up >/etc/hostname.vio1
echo up >/etc/hostname.vio2
echo up >/etc/hostname.vio3
echo inet 10.10.10.1 255.255.255.248 NONE vhid 1 carpdev vio1 pass lanpasswd advskew 100 >/etc/hostname.carp0
echo inet 10.10.10.25 255.255.255.248 NONE vhid 2 carpdev vio2 pass lanpasswd advskew 100 >/etc/hostname.carp1
echo inet 10.10.10.33 255.255.255.248 NONE vhid 3 carpdev vio3 pass lanpasswd advskew 100 >/etc/hostname.carp2
pfsync:
echo up syncdev vio0 >/etc/hostname.pfsync0
Reload network: sh /etc/netstart
cat <<EOF> /etc/pf.conf
pass quick on { vio0 } proto pfsync keep state (no-sync)
pass on { vio1 vio2 vio3 } proto carp keep state (no-sync)
EOF
pfctl -f /etc/pf.conf
cat <<EOF> /etc/bgpd.conf
AS 65001
listen on <address of vio0>
listen on 10.10.10.25
listen on 10.10.10.33
log updates
router-id 10.10.10.1
network 10.10.10.0/29
neighbor 10.10.10.26 {
remote-as 65002
descr "as2r"
log updates
depend on carp1
}
neighbor 10.10.10.34 {
remote-as 65003
descr "as3r"
log updates
depend on carp2
}
neighbor <address of as1r1:vio0> {
remote-as 65001
descr "carp_sync"
}
allow from any
allow to any
EOF
rcctl enable bgpd
rcctl start bgpd
echo inet 10.10.10.9 255.255.255.248 >/etc/hostname.vio1
echo inet 10.10.10.26 255.255.255.248 >/etc/hostname.vio2
cat <<EOF> /etc/bgpd.conf
AS 65002
listen on 10.10.10.26
log updates
router-id 10.10.10.9
network 10.10.10.8/29
neighbor 10.10.10.25 {
remote-as 65001
descr "as1r"
log updates
}
allow from any
allow to any
EOF
rcctl enable bgpd
rcctl start bgpd
echo inet 10.10.10.17 255.255.255.248 >/etc/hostname.vio1
echo inet 10.10.10.34 255.255.255.248 >/etc/hostname.vio2
cat <<EOF> /etc/bgpd.conf
AS 65003
listen on 10.10.10.34
log updates
router-id 10.10.10.17
network 10.10.10.16/29
neighbor 10.10.10.33 {
remote-as 65001
descr "as1r"
log updates
}
allow from any
allow to any
EOF
rcctl enable bgpd
rcctl start bgpd
as3c -> as2c
traceroute as2c
traceroute to as2c (10.10.10.10), 64 hops max, 40 byte packets
1 as3r (10.10.10.17) 0.306 ms 0.162 ms 0.238 ms
2 as1r (10.10.10.33) 0.402 ms 0.29 ms 0.29 ms
3 as2r (10.10.10.26) 0.522 ms 0.444 ms 0.458 ms
4 as2c (10.10.10.10) 0.674 ms 0.554 ms 0.661 ms
TODO
#allow quick from AS 65002 community BLACKHOLE
#allow quick from AS 65002 community 65534:0
#match to AS 65002 community 65534:0 set community BLACKHOLE
#match to AS 65002 community BLACKHOLE set community NO_EXPORT
#match to AS 65002 community BLACKHOLE set nexthop blackhole
allow quick from AS 65002 community BLACKHOLE set nexthop blackhole
TODO
TODO
bgpd -c
bgpctl show
bgpctl show rib
bgpctl show fib
bgpctl show nexthop
https://wiki.evolix.org/HowtoOpenBSD/OpenBGPD
https://datapacket.com/blog/bgp-network-how-does-it-work/
https://datapacket.com/blog/multihomed-network-vs-single-homed-network/