Technical Guide · Networking and Wi-Fi
BGP Multihoming: Prefix Filters and Path Policy
BGP multihoming exchanges reachability with multiple carriers. Local policy selects outbound paths; remote networks decide inbound paths. Local preference influences egress within the…
Technical review:
Architecture and operating model
BGP multihoming exchanges reachability with multiple carriers. Local policy selects outbound paths; remote networks decide inbound paths. Local preference influences egress within the local AS. AS-path prepending is only a signal for inbound traffic, not a guarantee.
Production requires an ASN, allocated prefixes and carrier approval. Do not advertise the lab private ASNs 64512/64513 or documentation prefix 203.0.113.0/24 on the Internet. A network statement requires the matching prefix in the RIB; blindly adding a Null0 route may blackhole traffic.
Define explicit import/export filters per peer. Export only owned prefixes, justify full-table needs against RAM/FIB capacity and size max-prefix around expected routes. If transit is not intended, verify that learned routes do not leak to other carriers.
- 1Peer UPDATE
- 2Import prefix/policy filter
- 3Local best path
- 4RIB/FIB and egress
Design parameters
- Export list
- Match prefixes and lengths exactly; inspect scope expansion introduced by ge/le.
- Imported table
- Default-only, partial and full tables offer different capacity and routing choices.
- Failure detection
- Test physical link, hold timers and BFD separately; upstream failure may occur while the neighbor stays up.
Worked example
In a lab, import default routes from two peers with local preferences 200 and 100. Advertise only 203.0.113.0/24 on both uplinks. Disconnect peer one and measure route convergence and HTTPS recovery separately.
Example commands: replace lab values and confirm permissions and software versions before use.
ip prefix-list LAB-EXPORT seq 10 permit 203.0.113.0/24
router bgp 64512
neighbor 192.0.2.1 remote-as 64513
address-family ipv4
neighbor 192.0.2.1 activate
neighbor 192.0.2.1 prefix-list LAB-EXPORT out
exit-address-family
! IOS-XE lab fragment: add import policy and authorized RIB prefix separately.
show bgp ipv4 unicast summary
Troubleshooting
| Observation | Likely cause / distinction | Verification |
|---|---|---|
| Established but no routes | Import filtering or address-family activation. | Compare received and accepted prefix counts. |
| Inbound traffic unchanged | Remote AS policy outweighs prepend. | Inspect AS paths from multiple external viewpoints. |
Acceptance checks
- Advertise allocated prefixes only.
- Validate import/export filters separately.
- Prevent transit route leaks.
- Test max-prefix alerts in a pilot.
- Test failure of each peer separately.
- Measure application recovery time.
Related concepts
Layer 2 and Layer 3 boundaries
A VLAN creates a separate broadcast domain; routing and access policies govern communication between VLANs. Review trunk allowed lists, access-port assignment and gateway placement together. A network diagram should show where packets are routed and filtered, not merely which cables connect devices. Sharing a switch does not require sharing privileges. When access fails, confirm VLAN and addressing first, then gateway, route and policy matching.
Failover and failback
Failover moves service to another component; failback returns it to the preferred location. Their risks and sequencing may differ. DNS updates, routing, sessions, replication lag and application dependencies determine user interruption. Define failover triggers, false-alarm behaviour and approval for returning service. Simply shutting down a VM does not test every failure type. Measure network, storage and management-plane failures separately.
Availability versus recovery
High availability aims to keep service running through specified failures with a short interruption; backup recovers lost or corrupted data from an earlier point. A cluster can replicate an accidental deletion to another node. HA therefore does not replace backup. Consider DNS, identity, network, storage and power dependencies together. Successful node failover is insufficient by itself: measure user sessions, application writes and external integrations after the transition as well.
Capacity and usable headroom
Raw capacity is not the capacity available to applications. RAID or erasure coding, filesystems, reserved space, metadata, snapshots and growth headroom are separate deductions. TB and TiB representations also change the displayed number. Write calculations with units, establish protected usable capacity, then subtract operating reserves. Track growth rate as well as current utilization. The projected exhaustion date should leave enough time to procure and deploy additional capacity.
Telemetry and time correlation
Telemetry combines logs, metrics and events that explain system behaviour. A log describes an event, a metric shows behaviour over time, and a distributed trace follows a request across components. Clock differences can make one event appear to occur at several times. Use synchronized clocks, reliable source identifiers and consistent time-zone handling. Alarm design should consider duration and user impact alongside thresholds. Monitor gaps in collection separately: absence of logs must not be interpreted as absence of incidents.
Dependencies and restart order
Services commonly depend on identity, DNS, time, networking, databases and licensing. Record a dependency graph describing conditions for operation, not merely an equipment list. Recovery order follows that graph; circular dependencies may require emergency access paths. Distinguish restored infrastructure from resumed business activity. Assign an owner, validation method and alternative access path to each dependency. Test assumptions by deliberately making one component unavailable in a controlled end-to-end exercise.
Primary documentation
Prepared by the Doz Teknoloji technical team using the primary references below. Calculations and lab scenarios state their assumptions; validate the applicable product version before rollout.