Advertisement
fakrulalam

junos rpki config

Jan 2nd, 2017
159
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.94 KB | None | 0 0
  1. A. JunOS:
  2. ---------------------------------------------------------------------------------------------------------
  3.  
  4. 1. Establish session with RPKI Validator
  5.  
  6. set routing-options validation group RPKI session 202.125.96.46 refresh-time 120
  7. set routing-options validation group RPKI session 202.125.96.46 hold-time 180
  8. set routing-options validation group RPKI session 202.125.96.46 port 8282
  9. set routing-options validation group RPKI session 202.125.96.46 local-address 202.125.96.254
  10.  
  11. 2. Configure policy to tag ROA
  12.  
  13. set policy-options policy-statement ROUTE-VALIDATION term valid from protocol bgp
  14. set policy-options policy-statement ROUTE-VALIDATION term valid from validation-database valid
  15. set policy-options policy-statement ROUTE-VALIDATION term valid then local-preference 110
  16. set policy-options policy-statement ROUTE-VALIDATION term valid then validation-state valid
  17. set policy-options policy-statement ROUTE-VALIDATION term valid then accept
  18.  
  19. set policy-options policy-statement ROUTE-VALIDATION term invalid from protocol bgp
  20. set policy-options policy-statement ROUTE-VALIDATION term invalid from validation-database invalid
  21. set policy-options policy-statement ROUTE-VALIDATION term invalid then local-preference 90
  22. set policy-options policy-statement ROUTE-VALIDATION term invalid then validation-state invalid
  23. set policy-options policy-statement ROUTE-VALIDATION term invalid then accept
  24.  
  25. set policy-options policy-statement ROUTE-VALIDATION term unknown from protocol bgp
  26. set policy-options policy-statement ROUTE-VALIDATION term unknown from validation-database unknown
  27. set policy-options policy-statement ROUTE-VALIDATION term unknown then local-preference 100
  28. set policy-options policy-statement ROUTE-VALIDATION term unknown then validation-state unknown
  29. set policy-options policy-statement ROUTE-VALIDATION term unknown then accept
  30.  
  31. 3. Push policy to the BGP neighbour
  32.  
  33. set protocols bgp import ROUTE-VALIDATION
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement