The region-validation command enables regional validation of BGP routes.
The undo region-validation command disables regional validation of BGP routes.
The region-validation confed-check strict command configures strict regional validation of BGP routes.
The undo region-validation confed-check strict command restores the default configuration.
By default, regional validation of BGP routes is not enabled.
Usage Scenario
Internet security events are emerging one after another. Route hijacking and leakage events may cause route blackholes, traffic eavesdropping, and large-scale denial of service (DoS) attacks, greatly affecting the normal running of the Internet. Avoiding or alleviating route hijacking and leaking has become one of the most urgent requirements of carriers and equipment vendors.
Regional validation is a solution that combines multiple trusted ASs into a region and multiple regions into a regional confederation. By checking whether the routes received from EBGP peers in external regions belong to the local region, regional validation prevents external regions from hijacking routes in the local region. After the region-validation command is run to enable regional validation, the local device checks the routes received from EBGP peers based on the following rules:Precautions
To enable regional confederation, you also need to add ASs to a region or add regions to a confederation. If no AS exists in a region, regional confederation does not take effect.
<HUAWEI> system-view [~HUAWEI] bgp 100 [*HUAWEI-bgp] ipv4-family unicast [*HUAWEI-bgp-af-ipv4] region-validation
<HUAWEI> system-view [~HUAWEI] bgp 100 [*HUAWEI-bgp] ipv4-family unicast [*HUAWEI-bgp-af-ipv4] region-validation confed-check strict