mirror of
https://git.dn42.dev/wiki/wiki.git
synced 2024-12-01 14:58:11 +01:00
Updated Bird2 (markdown)
This commit is contained in:
parent
4a2fc6d41a
commit
cb8989b671
@ -171,6 +171,50 @@ include "/etc/bird/peers/*";
|
|||||||
|
|
||||||
The example config above relies on ROA configuration files in `/etc/bird/roa_dn42{,_v6}.conf`. These should be automatically downloaded and updated every so often to prevent BGP highjacking, [see the bird1 page](/howto/Bird#route-origin-authorization) for more details and links to the ROA files.
|
The example config above relies on ROA configuration files in `/etc/bird/roa_dn42{,_v6}.conf`. These should be automatically downloaded and updated every so often to prevent BGP highjacking, [see the bird1 page](/howto/Bird#route-origin-authorization) for more details and links to the ROA files.
|
||||||
|
|
||||||
|
# RPKI / RTR for ROA
|
||||||
|
|
||||||
|
To use an RTR server for ROA information, replace this config in your bird2 configuration file:
|
||||||
|
|
||||||
|
```
|
||||||
|
protocol static {
|
||||||
|
roa4 { table dn42_roa; };
|
||||||
|
include "/etc/bird/roa_dn42.conf";
|
||||||
|
};
|
||||||
|
|
||||||
|
protocol static {
|
||||||
|
roa6 { table dn42_roa_v6; };
|
||||||
|
include "/etc/bird/roa_dn42_v6.conf";
|
||||||
|
};
|
||||||
|
```
|
||||||
|
|
||||||
|
... with this one (by changing address and port so it points to your RTR server)
|
||||||
|
|
||||||
|
```
|
||||||
|
protocol rpki roa_dn42 {
|
||||||
|
roa4 { table dn42_roa; };
|
||||||
|
roa6 { table dn42_roa_v6; };
|
||||||
|
remote 10.1.3.3;
|
||||||
|
port 323;
|
||||||
|
refresh 600;
|
||||||
|
retry 300;
|
||||||
|
expire 7200;
|
||||||
|
}
|
||||||
|
```
|
||||||
|
To reflect changes in the ROA table without a manual reload, **ADD** "import table" switch for both channels in your DN42 BGP template:
|
||||||
|
|
||||||
|
```
|
||||||
|
template bgp dnpeers {
|
||||||
|
ipv4 {
|
||||||
|
...existing configuration
|
||||||
|
import table;
|
||||||
|
};
|
||||||
|
ipv6 {
|
||||||
|
...existing configuration
|
||||||
|
import table;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
# Setting up peers
|
# Setting up peers
|
||||||
|
|
||||||
Please note: This section assumes that you've already got a tunnel to your peering partner setup.
|
Please note: This section assumes that you've already got a tunnel to your peering partner setup.
|
||||||
|
Loading…
Reference in New Issue
Block a user