BGP Graceful Shutdown: the GShut Community (RFC 8326) - 夜莺博客

BGP Graceful Shutdown: the GShut Community (RFC 8326)

Every maintenance window starts with the same question: how do you take a link or a router out of service without dropping the traffic that is already using it? If you simply shut the interface or clear the session, the remote routers withdraw the paths and start forwarding only after convergence - which means packet loss. RFC 8326 defines a well-known BGP community, GRACEFUL_SHUTDOWN (65535:0, previously called planned-shut), that lets the operator signal "these paths are about to go away" so receivers can move traffic first and drain the link safely.

The mechanism

The GRACEFUL_SHUTDOWN community is attached to the paths advertised over the session being drained. A receiver implementing the graceful shutdown procedure matches the community in an inbound policy and sets LOCAL_PREF to a low value - the RFC recommends 0. The path stays in service but immediately loses the best-path comparison against any alternative, so traffic moves to the backup while the link is still up. After convergence, the operator shuts the session down and no packets were lost by the transition itself.

Two operations are involved. Pre-configuration happens once, on every ASBR that should honour the community: an inbound route policy that matches the community and lowers LOCAL_PREF. Maintenance-time configuration happens on the device being drained: an outbound policy that tags the advertised paths (triggering re-advertisement), an optional inbound policy that also lowers LOCAL_PREF for paths received, a wait for convergence, and only then the shutdown.

Cisco IOS XR: the receiver policy

community-set comm-graceful-shutdown
  65535:0
end-set
!
route-policy EBGP-INBOUND
  if community matches-any comm-graceful-shutdown then
    set local-preference 0
  endif
end-policy
!
router bgp 64496
 neighbor 2001:db8:1:2::1
  remote-as 64497
  address-family ipv6 unicast
   send-community-ebgp
   route-policy EBGP-INBOUND in
  !
 !

Cisco IOS XE: per-neighbour graceful shutdown

Device(config)# ip community-list standard GSHUT permit gshut
Device(config)# router bgp 65000
Device(config-router)# neighbor 2001:db8:3::1 shutdown graceful 600 community 1200 local-preference 300

The neighbour is announced as shutting down in 600 seconds, advertised with the GSHUT community (plus community 1200 for policy purposes) and a local preference of 300. The timer must be long enough for iBGP peers to converge and select an alternate path. For whole-router maintenance there is a bulk form:

Device(config-router)# bgp graceful-shutdown all neighbors 180 local-preference 20 community 10
Device(config-router)# bgp graceful-shutdown all neighbors activate
Device# show ip bgp community gshut

The activate step is easy to forget - it is what actually triggers the graceful shutdown across all neighbours or VRFs.

Operational practice

  • Deploy the receiver policy well before you need it; graceful shutdown only works on devices that already honour the community.
  • Include the community in monitoring so that a GShut-tagged path is visible as "draining", not as a mysterious LOCAL_PREF change.
  • Use it for link decommissioning, software upgrades and router reloads where the forwarding plane is impacted - cases where graceful restart does not apply.
  • Wait for convergence before the shutdown. The whole point is that the transition happens while the path is still usable.
  • Remember the community is a signal, not enforcement: without the receiver policy it changes nothing.

Related: BGP add-path advertisement, BGP best path selection, and Prefix-list and route-map filtering.

原文链接:https://www.cisco.com/c/en/us/td/docs/routers/ios-xe/ip-routing/b-ip-routing/m_irg-grace-shut.html