R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
448
Ste
p
Command
Remarks
3. Enable 4-byte AS number
suppression.
peer { group-name | ip-address }
capability-advertise
suppress-4-byte-as
Disabled by default.
NOTE:
If the peer device supports 4-byte AS numbers, do not enable the 4-byte AS number suppression function;
otherwise, the BGP peer relationship cannot be established.
Enabling quick EBGP session reestablishment
If the router receives no keepalive messages from a BGP peer within the holdtime, it disconnects from the
peer.
With quick EBGP connection reestablishment enabled, the router, when the link to a directly connected
EBGP peer is down, will reestablish a session to the EBGP peer immediately.
To enable quick EBGP session reestablishment:
Ste
p
Command
Remarks
1. Enter system view
system-view N/A
2. Enter BGP view
bgp as-number N/A
3. Enable quick EBGP session
reestablishment
EBGP-interface-sensitive
Optional.
Not enabled by default.
Enabling MD5 authentication for TCP connections
BGP employs TCP as the transport protocol. To enhance security, you can configure BGP to perform MD5
authentication when establishing a TCP connection. The two parties must have the same password
configured to establish TCP connections.
BGP MD5 authentication is not for BGP packets, but for TCP connections. If the authentication fails, no
TCP connection can be established.
To enable MD5 authentication for TCP connections:
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Enter BGP view. bgp as-number N/A
3. Enable MD5 authentication
when establishing a TCP
connection to the peer/peer
group.
peer { group-name | ip-address }
password { cipher | simple }
password
Optional.
Not enabled by default.
Configuring BGP load balancing
If multiple paths to a destination exist, you can configure load balancing over such paths to improve link
utilization.
To configure BGP load balancing: