Application of BGP VPNv6 Flow Specification

This section describes the application of BGP VPNv6 Flow Specification.

Figure 1 Deploying inter-AS transmission of BGP VPNv6 Flow Specification routes

In Figure 1, a BGP VPNv6 Flow Specification EBGP peer relationship is established between PE1 and PE4, and a BGP VPNv6 Flow Specification IBGP peer relationship is established between PE1 and the traffic analysis server. PE2 and PE3 sample traffic and send sampled traffic to the traffic analysis server. If the traffic analysis server identifies sampled traffic as attack traffic, it sends a BGP VPNv6 Flow Specification route to PE1 so that PE1 does not send traffic matching filtering rules in the route to PE2 or PE3. Upon receipt of the BGP VPNv6 Flow Specification route, PE1 advertises the route to its EBGP peer PE4. After receiving the route from PE1, PE4 implements traffic filtering. Inter-AS transmission of BGP VPNv6 Flow Specification routes minimizes the impact of DDoS attacks at a node nearest to the attack source and prevents a waste of network resources.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic