Static BGP VPNv6 Flow Specification allows BGP VPNv6 Flow Specification routes to be transmitted and traffic filtering policies to be generated. The policies improve security of devices in VPNs.
To deploy static BGP VPNv6 Flow Specification, create a BGP IPv6 VPN Flow Specification route first, and then establish a BGP VPNv6 Flow Specification peer relationship between the device on which the BGP IPv6 VPN Flow Specification route is created and the network ingress to transmit the BGP VPNv6 Flow Specification route.
In an AS with multiple ingresses, a BGP Flow route reflector (Flow RR) can be deployed to reduce the number of BGP VPNv6 Flow Specification peer relationships and save network resources.
If you want to filter traffic based on an address prefix and the BGP VPNv6 Flow Specification route carrying the filtering rule fails to be authenticated, disable the authentication of the BGP VPNv6 Flow Specification routes received from a specified peer.
Before configuring static BGP VPNv6 Flow Specification, configure a VPN instance and bind an interface to the VPN instance.
Before configuring a Flow RR, establish a BGP IPv6 VPN Flow Specification peer relationship between the Flow RR and device on which the BGP IPv6 VPN Flow Specification route is generated and between the Flow RR and every network ingress.
After configuring static BGP VPNv6 Flow Specification, verify the configuration.
Run the display bgp flow vpnv6 all peer [ [ ipv4-address ] verbose ] command to check information about all BGP VPNv6 Flow Specification peers.
Run the display bgp flow vpnv6 { all | route-distinguisher route-distinguisher } routing-table [ reindex ] command to check information about all BGP VPNv6 Flow Specification routes or about the BGP VPNv6 Flow Specification routes with a specified RD.
Run the display bgp flow vpnv6 { all | route-distinguisher route-distinguisher } routing-table statistics command to check statistics about all BGP VPNv6 Flow Specification routes or about the BGP VPNv6 Flow Specification routes with a specified RD.