BGP Monitoring Protocol (BMP): Router-Side Configuration - 夜莺博客

BGP Monitoring Protocol (BMP): Router-Side Configuration

Screen-scraping show ip bgp gives you the post-policy RIB of one router at one instant. BMP (BGP Monitoring Protocol, RFC 7854) instead streams the routes a router receives before policy, after policy and what it advertises, continuously, to a collector. That pre-policy Adj-RIB-In view is the only practical way to answer questions like which peer sent a hijacked prefix, or whether a route was filtered locally or never arrived. This article covers the router side of BMP on Junos, IOS-XR and FRR, plus the sizing decisions that keep it from eating your control plane.

What BMP Actually Sends

  • Peer up/down notifications with the peer's capability set.
  • Route monitoring messages - essentially BGP UPDATEs, per RIB, per peer.
  • Statistics reports at a configurable interval.
  • Initiation messages carrying the collector's configuration.

Each station is configured for the RIB types you want: pre-policy (Adj-RIB-In before import policy), post-policy (Adj-RIB-In after policy) and rib-out (what you advertise). Start with post-policy plus rib-out for most operational uses; add pre-policy when you need to prove what a peer actually sent.

Junos Configuration

set routing-options bmp station bmp-collector station-address 10.0.0.50
set routing-options bmp station bmp-collector station-port 11019
set routing-options bmp station bmp-collector connection-mode active
set routing-options bmp station bmp-collector route-monitoring pre-policy
set routing-options bmp station bmp-collector route-monitoring post-policy
set routing-options bmp station bmp-collector route-monitoring rib-out post-policy
set routing-options bmp station bmp-collector statistics-timeout 60
set routing-options bmp station bmp-collector memory-limit 10000000
commit

BMP detection is per-peer and can be disabled selectively at group or neighbour level with set protocols bgp group EBGP bmp monitor disable. Junos supports up to three stations per device, and the station can be sourced from a non-default routing instance (for example the management instance) so BMP traffic never shares the table with production routes.

IOS-XR and FRR Configuration

! IOS-XR
bmp server 1
 host 10.0.0.50 port 11019
 description collector
 initial-delay 60
 initial-refresh delay 30 spread 2
!
router bgp 65000
 bmp server 1
  update-source Loopback0
  activate

! FRR (frr.conf)
router bgp 65000
 bmp targets bmp-collector
 bmp connect 10.0.0.50 port 11019 min-retry 100 max-retry 500
 bmp mirror
bmp targets bmp-collector
 bmp monitor ipv4 unicast pre-policy
 bmp monitor ipv4 unicast post-policy

The initial-refresh parameters matter more than they look: without a spread, every router dumps its full table at the collector in the same second after a session reset. The initial-delay gives the collector time to come up before the flood starts.

Verification

show bmp summary                      ! Junos
show bmp station                      ! Junos
show bgp bmp server summary           ! IOS-XR
show bgp bmp server 1 detail          ! IOS-XR
vtysh -c 'show bgp bmp targets'       ! FRR

An idle station with no messages almost always means a firewall is blocking the TCP port (11019 is a common choice) in the direction router to collector, or the collector is configured passive while the router also expects to be passive - pick one active side.

Sizing and Safety

  • BMP carries full tables. A 1M-route full table multiplied by four peers is 4M route-monitoring messages per session reset: size the collector's storage before enabling it on a transit router.
  • Use a separate routing instance or management VRF for BMP so a full-table refresh never competes with production traffic.
  • Enable BMP on customer-edge or border routers first, and only then on route reflectors.
  • Keep the collector in a different failure domain than the router - a collector that pulls the router's CPU is worse than no collector.

Next steps: how to run the collector itself in self-hosted BMP collectors compared, protocol-level debugging in Junos traceoptions for BGP troubleshooting, and route-injection testing with ExaBGP and GoBGP.

原文链接:https://www.juniper.net/documentation/us/en/software/junos/bgp/topics/topic-map/bgp-monitoring-protocol.html