Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    FRR 7.5 full bgp table very slow and AS paths not working

    FRR
    4
    7
    152
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      archang3l last edited by archang3l

      I'm running pfSense for IPv6 bgp routing. After upgrading to 2.5.0 the VM gets really slow when loading the full table from 2 peers. I checked the running processes and found multiple 'netstat --libxo json -nWr' running for over 10 seconds an more. Sometimes the webinterface times out with "bad gateway". Reducing the number of routes helps. Never had that problem with 2.4.x

      Another problem occured after the update... the service won't start with any configured AS path filters. My guess is it gets inserted in the wrong configuration section.

      Anyone have the same problems?

      C M 2 Replies Last reply Reply Quote 0
      • C
        ccb056 @archang3l last edited by ccb056

        @archang3l

        I'm having a smiliar issue with ipv4 internal networks - have you seen this:

        https://forum.netgate.com/topic/160694/frr-7-3-7-5-bgp-not-announcing-routes

        1 Reply Last reply Reply Quote 0
        • M
          mfld @archang3l last edited by

          @archang3l

          Take a look at this one:

          https://redmine.pfsense.org/issues/11364

          See if your situation matches and if you can help reproduce the issue.

          1 Reply Last reply Reply Quote 0
          • A
            archang3l last edited by

            Thanks for the links. I don't really need the full table on this device, but I'd like to reduce the number of learned routes by using an AS path filter. However here's a bit of my config:

            ...
            neighbor 2001:1:2:3::4 update-source 2001:1:2:3::3
            !
            bgp as-path access-list <peer> permit <peer as>
            address-family ipv6 unicast
            network ....

            I guess the "bgp as-path..." just moved to the wrong position :(

            M viktor_g 2 Replies Last reply Reply Quote 0
            • M
              mfld @archang3l last edited by mfld

              @archang3l

              I have one such instance where the pfSense has 1GB RAM and only needs to announce one IPv6 /48 but the upstream is set to send full tables. pfSense will eventually OOM, start swapping out and web UI will lock up/die. To only receive default route I placed a prefix filter.
              prefix list1.JPG

              This is then attached to the neighbor settings

              neigh.JPG

              This allows this tiny instance to survive being sent full tables. We discard all but the default route. The outbound filter is just a prefix list containing the /48 I want to announce and then deny all else. This is to satisfy the new default of "bgp ebgp-requires-policy"

              Is that what you are looking for ?

              1 Reply Last reply Reply Quote 0
              • viktor_g
                viktor_g Netgate @archang3l last edited by

                @archang3l said in FRR 7.5 full bgp table very slow and AS paths not working:

                Thanks for the links. I don't really need the full table on this device, but I'd like to reduce the number of learned routes by using an AS path filter. However here's a bit of my config:

                ...
                neighbor 2001:1:2:3::4 update-source 2001:1:2:3::3
                !
                bgp as-path access-list <peer> permit <peer as>
                address-family ipv6 unicast
                network ....

                I guess the "bgp as-path..." just moved to the wrong position :(

                Redmine issue created:
                https://redmine.pfsense.org/issues/11445

                1 Reply Last reply Reply Quote 0
                • viktor_g
                  viktor_g Netgate last edited by

                  fixed in FRR 1.1.0_6

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post

                  Products

                  • Platform Overview
                  • TNSR
                  • pfSense
                  • Appliances

                  Services

                  • Training
                  • Professional Services

                  Support

                  • Subscription Plans
                  • Contact Support
                  • Product Lifecycle
                  • Documentation

                  News

                  • Media Coverage
                  • Press
                  • Events

                  Resources

                  • Blog
                  • FAQ
                  • Find a Partner
                  • Resource Library
                  • Security Information

                  Company

                  • About Us
                  • Careers
                  • Partners
                  • Contact Us
                  • Legal
                  Our Mission

                  We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

                  Subscribe to our Newsletter

                  Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

                  © 2021 Rubicon Communications, LLC | Privacy Policy