Wednesday, April 25, 2007

Sample Configurations of BGP Across a PIX Firewall - Cisco Systems

Sample Configurations of BGP Across a PIX Firewall - Cisco Systems

Introduction
This sample configuration demonstrates how to run Border Gateway Protocol (BGP) across a PIX firewall and how to achieve redundancy in a multihomed BGP and PIX environment. With a network diagram as an example, this document explains how to automatically route traffic to Internet service provider B (ISP-B) when AS 10 loses connectivity to ISP-A (or vice versa), through the use of dynamic routing protocols that run between all routers in AS 10.
Because BGP uses unicast TCP packets on port 179 to communicate with its peers, you can configure PIX1 and PIX2 to allow unicast traffic on TCP port 179. This way, BGP peering can be established between the routers that are connected through the firewall. Redundancy and the desired routing policies can be achieved through the manipulation of the BGP attributes.