Configuring Border Gateway Protocol (BGP) must be completed on an existing Secure Connect network. Routing protocol configuration is not available during first-time set up of a Secure Connect network.
Note
BGP peers should advertise specific subnets behind the third-party device to NetCloud SASE. Advertisement of default routes is not supported.
Complete the following steps to configure BGP on an existing Secure Connect network:
Log into NetCloud Manager.
Select in the left-side navigation panel.
Select the Secure Connect network's tile.
Select in the top-right corner of the page.
Select the Configuration tab.
Select the Routing tab.
Select the BGP tab.
Enable Protocol Configuration.
Optional: Select Edit Timers to open the BGP Timer Fields panel.
Enter the Connect Retry value in seconds.
Enter the Hold Time value in seconds.
Enter the Keep Alive Interval value in seconds.
Enter the Advertisement Interval value in seconds.
Optional: Select Use Same Timers for Secondary Service Gateway to use the primary NCX Service Gatewaytimers' values for the secondary service gateway, if needed.
Otherwise, enter the timers' values for the secondary NCX Service Gateway, if needed.
Select .
Enter the Router-ID.
The ID must be unique to the entire BGP domain or autonomous system.
Enter the Local ASN that is associated with the NCX Service Gateway.
Note
Use a private Autonomous System Number (ASN), 64512 to 65535, or one provided by the Internet Assigned Numbers Authority (IANA).
Enter the Multi-hop Value to set the number of BGP connection attempts to external peers residing on networks that are not directly connected.
Complete the following steps to add a BGP neighbor:
Enter the BGP Neighbor IP.
This is the peer address with whom to neighbor for the primary path.
Enter the Peer Remote ASN.
This is the Autonomous System Number (ASN) with which the primary path peers.
Optional: Change the default Weight, if needed.
Weight determines the outbound priority. For more than one neighbor, the Weight value cannot be the same.
Optional: Change the default AS Path value, if needed.
AS Path determines the inbound priority. Enter 0 for no prepending.
Optional: Enter a description for the BGP neighbor.
Select Add Neighbor again and repeat these steps to add up to four neighbors.
Note
A configured BGP neighbor may be disabled by moving the toggle button in front of it.
Optional: Uncheck the Advertise CGNAT range box to advertise only the NCX Service Gateway interface IP address used in the Secure Connect network. Advertise CGNAT range is enabled by default, so that the CGNAT range used for the network is added to the network statement.
Note
If there are more than 20 network statements, Download Network Statements as CSV is displayed, and the list may be downloaded in CSV format.
Optional: Enter an aggregate address in CIDR format for Route Summarization and select .
Note
The route summarization needs to match outbound prefix policies, if they are configured.
Optional: Complete the following steps to add a BGP inbound prefix policy:
Note
Prefix lists control which IP addresses can enter or leave the network. When using BGP, by default there is an explicit deny rule at the bottom of each inbound and outbound set of policies.
Select .
Enter a descriptive name for the policy.
Enter the IP Address in CIDR Format.
The IP address allows for filtering which range is accepted based on the greater than or equal to (GE) and less than or equal to (LE) values.
Enter the GE Value.
Used with the IP address to filter which networks are advertised.
Enter the LE Value.
Used with the IP address to filter which networks are advertised.
Select or in the Permission drop-down menu.
Select .
If needed, hover over the drag handle to drag and drop the listed item to its proper location in the hierarchy.
Optional: Complete the following steps to add a BGP outbound prefix policy:
Select .
Enter a descriptive name for the policy.
Enter the IP Address in CIDR Format.
The IP address allows for filtering which range is advertised based on the GE and LE values.
Enter the GE Value.
Used with the IP address to filter which networks are advertised.
Enter the LE Value.
Used with the IP address to filter which networks are advertised.
Select or in the Permission drop-down menu.
Select .
If needed, hover over the drag handle to drag and drop the listed item to its proper location in the hierarchy.
Select .
Optional: Select and then again in the side panel to view the BGP summary output with the routes being received and advertised by each neighbor.