To deploy
static BGP VPNv4 Flow Specification, a BGP VPN Flow Specification
route needs to be created manually on PE3 based on the characteristics
of common attack traffic. After the BGP Flow-VPNv4 address family
is enabled, PE3 generates a BGP VPNv4 Flow Specification route. Then
a BGP VPNv4 Flow Specification IBGP peer relationship must be established
between PE3 and the ingress PE (PE1) to transmit the BGP VPNv4 Flow
Specification route. As shown in
Figure 2, the working process of static BGP VPNv4 Flow Specification
includes the following steps:
- A BGP VPNv4 Flow Specification route is created manually on PE3,
and a filtering rule and traffic control action are configured based
on the characteristics of the attack traffic.
- The BGP VPNv4 Flow Specification route is advertised to PE1 through
the BGP VPNv4 Flow Specification IBGP connection.
- Upon receipt of the route, PE1 crosses it to VPNA and generates
a traffic control policy based on the route to control traffic matching
the filtering rules.