BGP Dynamic Neighbors with Listen Range - 夜莺博客

BGP Dynamic Neighbors with Listen Range

Hub-and-spoke BGP with dozens of branches usually means repeating the same three lines of neighbor configuration over and over, once per remote address. Dynamic neighbors invert that: you describe the address range once, bind it to a peer group, and the router creates a neighbor automatically whenever an incoming TCP session originates from inside that range. This article walks through the listen range configuration on Cisco IOS XE, the limits that keep it from being abused, and how to verify that a session was created dynamically rather than statically.

The problem the feature solves

A listening router that must scale to hundreds of remote sites has no need to initiate sessions — the remote sites come to it. Without dynamic neighbors, the hub still needs an individual neighbor statement for each remote IP, plus an activation line, plus policy attachment. Each new branch becomes a configuration change on the hub, which is exactly the kind of toil that config drift and outages grow out of.

Configuring a listen range group

The range must be bound to a peer group so that dynamically created neighbors inherit session parameters and policy in one place.

router bgp 64503
 bgp log-neighbor-changes
 neighbor group192 peer-group
 neighbor group192 remote-as 64502
 neighbor group192 update-source Loopback0
 bgp listen limit 200
 bgp listen range 192.168.0.0/16 peer-group group192
 !
 address-family ipv4 unicast
  neighbor group192 activate
  neighbor group192 route-map SPOKE-IN in
  neighbor group192 route-map SPOKE-OUT out
 exit-address-family

Nothing else is needed. When a router at 192.168.3.2 opens a TCP session to port 179, IOS XE finds the address inside 192.168.0.0/16, creates a neighbor that is a member of group192, and inherits every peer-group parameter. The hub never has to know that 192.168.3.2 exists.

Limits, blocking and persistence

! global cap on how many dynamic neighbors may exist
bgp listen limit 200

! permanently refuse a specific address even though it is in range
bgp listen block 192.168.3.2

! IOS XE 17.13.1a and later: keep the neighbour context after the session drops
neighbor DN peer-group
neighbor DN remote-as 64502
bgp listen range 1.1.1.0/24 peer-group DN persistent 60

Keep the limit equal to the planned neighbor count. A range that is broader than the population of sites you actually operate is an invitation for an unintended peer, and the limit is the only control that stops the router from accepting thousands of sessions from inside a mis-scoped subnet.

Verifying a dynamically created peer

show ip bgp summary
! *192.168.3.2    4 64502   42   43  0 0 0 00:06:35 0

show ip bgp neighbors 192.168.3.2
! BGP neighbor is *192.168.3.2, remote AS 64502, external link
!  Member of peer-group group192 for session parameters
!  Belongs to the subnet range group: 192.168.0.0/16

The asterisk next to the neighbor address in show ip bgp summary is the fastest way to distinguish a dynamic neighbor from a configured one. The Belongs to the subnet range group line confirms which range produced it, which matters as soon as you have more than one listen range on the same router.

Operational notes and failure modes

  • Address family coverage. Dynamic neighbors were extended to IPv6 in IOS XE Denali 16.3 and to EVPN, VPLS, FlowSpec, multicast and link-state families from Dublin 17.11.1a. On older releases, a range on an unsupported family will simply never match.
  • Passive side only. The listen range makes the local router accept sessions; it does not initiate them. If the remote refuses inbound TCP 179, the peering never forms — check with debug ip tcp transactions or a packet capture rather than suspecting the range.
  • Policy per group, not per neighbor. Every dynamic neighbor inherits the group policy. A single misbehaving spoke cannot be given a different route-map without being blocked and configured statically.
  • Authentication. If the group uses MD5 or TCP-AO, every spoke in the range must use the same key. Range membership and key mismatch produce the same symptom — sessions stuck in Active.

FRR equivalent

! FRR supports the same idea for route-server style deployments
router bgp 64503
 bgp listen range 192.168.0.0/16 peer-group group192
 bgp listen limit 200

For session hardening on the listening router, see BGP session hardening with GTSM, MD5 and TCP-AO. To keep a large dynamic population from filling the table with junk, the mechanisms in BGP prefix limits and route-table protection apply to the peer group exactly as they do to a static peer.

原文链接:https://www.cisco.com/c/en/us/td/docs/routers/ios-xe/ip-routing/b-ip-routing/m_irg-bgp-dynamic-neighbors.html