BMP on the Juniper MX for EdgeWarden, configuration explained

How to send Juniper MX BGP tables to EdgeWarden over BMP: transport, Loc-RIB, pre-policy, rib-out, groups left out of BMP, and verification.

What BMP gives EdgeWarden

BMP (BGP Monitoring Protocol, RFC 7854) sends the router's BGP tables to the collector in real time. In EdgeWarden they show up under BGP → BMP Station, a read-only screen: nothing there writes to the router.

RIBWhat it showsQuestion it answers
in preEverything the neighbor announces, before your import filterIs the neighbor sending me this prefix?
in postWhat passed the import filterDid my filter drop the prefix?
out preWhat would go to the neighbor, before the export policyWhat would I announce without the policy?
out postWhat is actually announced to the neighborWhat do I announce to this carrier?
loc-ribThe effective table, the result of the BGP decisionWhich path is in use?

Three automations use this table to act safely: IXP and peering link probing, route confirmation in Traffic Steering, and path validation for failover. Without BMP, they run without that confirmation.

The addresses in this article are documentation addresses: collector 192.0.2.10, MX loopback 198.51.100.1.

Prerequisites

  • Enterprise license: without it, EdgeWarden's BMP receiver doesn't start and the log records why. After upgrading, restart the collector.
  • Junos with rib-out (from 19.1R1) and loc-rib (from 19.2R1). This configuration is validated in production on an MX running Junos 20.4R3.8, with all three RIBs at once.
  • Port 11019/TCP open on the EdgeWarden server, only to your routers' IPs. EdgeWarden opens the port and waits: the router always initiates the connection.
  • If lo0 has a Routing Engine protection filter (protect-re), it must accept TCP with source port 11019 from the collector. Otherwise the MX tries to connect, the filter drops the reply, and no error shows up anywhere.

The three BMP hierarchies in Junos

Junos spreads BMP across three places, and each one controls a part:

  • routing-options bmp station-address and station-port: transport in the legacy, unnamed form.
  • routing-options bmp station <name>: transport for a named station, and the only place where Loc-RIB is enabled.
  • protocols bgp bmp: what is sent. This is where pre-policy, post-policy, and rib-out actually work.

Having route-monitoring rib-out post-policy only under routing-options bmp is not enough. Inside a station, the line is accepted and commits without error, but in what we verified in production (MX running Junos 20.4R3.8), on its own it sent no rib-out routes. out post arrived with the line also under protocols bgp bmp (step 2). This is the trap that costs the most time.

Step 1: transport and Loc-RIB

Junos: transport and Loc-RIB in routing-options
set routing-options bmp priority high
set routing-options bmp monitor enable
set routing-options bmp route-monitoring rib-out post-policy
set routing-options bmp station-address 192.0.2.10
set routing-options bmp station-port 11019
set routing-options bmp statistics-timeout 15
set routing-options bmp station BMP local-address 198.51.100.1
set routing-options bmp station BMP connection-mode active
set routing-options bmp station BMP monitor enable
set routing-options bmp station BMP route-monitoring loc-rib
set routing-options bmp station BMP route-monitoring rib-out post-policy
set routing-options bmp station BMP routing-instance default
  • priority high: BMP's priority among the routing process (rpd) tasks. With high, messages go out with less delay; watch the Routing Engine CPU after turning it on.
  • monitor enable: turns BMP on in the legacy form.
  • route-monitoring rib-out post-policy: requests post-policy rib-out in the legacy form. It stays as is; what guarantees out post is sent is the step 2 line, under protocols bgp bmp.
  • station-address 192.0.2.10 and station-port 11019: the EdgeWarden collector, on the default port.
  • statistics-timeout 15: the MX sends statistics reports (per-neighbor counters) every 15 s. They feed the Estatísticas (statistics) tab of the BMP Station screen.
  • station BMP local-address 198.51.100.1: the session source is the loopback. This IP becomes the router's identity in EdgeWarden; use the same IP as the device record, so BMP lines up with SNMP and flows. Without it, the source is whichever interface happens to reach the collector, and a route change makes the router reappear as if it were a different one.
  • station BMP connection-mode active: the MX opens the TCP connection. Required, because EdgeWarden only listens.
  • station BMP monitor enable: turns the named station on.
  • station BMP route-monitoring loc-rib: sends the Loc-RIB, the router's effective table. It only works on the named station.
  • station BMP route-monitoring rib-out post-policy: the same rib-out request, inside the station. It also stays as is; in our validation, without the step 2 line, it sent no rib-out.
  • station BMP routing-instance default: the station uses the main table (the default instance) to reach the collector and monitor BGP.

The MX may open two BMP sessions to the same collector, one through the legacy form and one through the named station. EdgeWarden identifies the router by source IP and treats both as the same router; if one drops, the router stays on the list while the other is alive.

Step 2: what is sent

Junos: pre-policy and rib-out in protocols bgp
set protocols bgp precision-timers
set protocols bgp log-updown
set protocols bgp bmp monitor enable
set protocols bgp bmp route-monitoring pre-policy
set protocols bgp bmp route-monitoring rib-out post-policy
  • bmp monitor enable: turns BMP on for every BGP group. Step 3 removes the groups you don't need.
  • bmp route-monitoring pre-policy: sends in pre, everything each neighbor announces before the import filter.
  • bmp route-monitoring rib-out post-policy: sends out post, what the MX actually announces to each neighbor. This is the line that makes rib-out work.
  • precision-timers and log-updown aren't BMP, but they help alongside it. precision-timers keeps BGP keepalives on time even when rpd is busy, and BMP adds load to rpd. log-updown logs each neighbor going up or down to syslog, to compare with the Eventos de Peers (peer events) tab.

Step 3: leaving groups out of BMP

Turn BMP on globally and switch it off per group. Keep transit, IXP, and peering groups on: they answer "what do I announce to each carrier". Switch off customer groups, especially those receiving a full table.

Junos: customer group out of BMP
set protocols bgp group CLIENTES_FULL_ROUTER bmp monitor disable

The line applies to the whole group; the rest of the group configuration (import, export, prefix-limit, neighbors) doesn't change:

Junos: full customer group, for reference
set protocols bgp group CLIENTES_FULL_ROUTER type external
set protocols bgp group CLIENTES_FULL_ROUTER import Import_CLIENTES_FULL_ROUTER
set protocols bgp group CLIENTES_FULL_ROUTER family inet unicast prefix-limit maximum 50000
set protocols bgp group CLIENTES_FULL_ROUTER family inet unicast prefix-limit teardown 80
set protocols bgp group CLIENTES_FULL_ROUTER family inet unicast prefix-limit teardown idle-timeout 15
set protocols bgp group CLIENTES_FULL_ROUTER export Export_CLIENTES_FULL_ROUTER
set protocols bgp group CLIENTES_FULL_ROUTER tcp-mss 1000
set protocols bgp group CLIENTES_FULL_ROUTER bmp monitor disable
set protocols bgp group CLIENTES_FULL_ROUTER neighbor 203.0.113.50 description CLIENTE-A
set protocols bgp group CLIENTES_FULL_ROUTER neighbor 203.0.113.50 peer-as 65010

Why it matters: in one of our measurements, with BMP on for every group, the volume was 23,388 rows per second. Leaving customer groups out brought it down to 98.5 per second. The rib-out of a customer receiving a full table generates millions of rows per hour, with no value for traffic engineering.

Don't try the opposite, enabling rib-out only on some groups. set protocols bgp group <group> bmp route-monitoring rib-out post-policy is accepted, commits, and sends nothing. At group level, only bmp monitor disable works.

Verification

Junos: BMP and Routing Engine status
show bgp bmp
show chassis routing-engine
  • show bgp bmp shows the stations, the connection state, and what is being monitored.
  • show chassis routing-engine shows whether the Routing Engine handles the load. In the measurement above, with customer groups left out, the RE (RE-S-1600x8) stayed 95% idle.

On the EdgeWarden server, check the TCP session:

EdgeWarden server: BMP sessions
ss -tn state established '( sport = :11019 )'

In the interface, under BGP → BMP Station:

  1. The Roteadores (routers) tab shows the MX by IP 198.51.100.1, with its system name. The router only joins the list once it sends the BMP opening message (Initiation); a TCP connection that doesn't speak BMP doesn't show up.
  2. The Route Feed tab shows in pre, loc-rib, and out post in the RIB column. If out post is missing, check that the bmp route-monitoring rib-out post-policy line is under protocols bgp.
  3. The Eventos de Peers tab shows neighbors going up and down.

Open 11019/TCP on the server only to your routers' IPs. Anyone who connects to that port and speaks BMP joins the router list and can send forged routes to the automations that depend on BMP.

EdgeWarden processes IPv4 unicast and, in multiprotocol announcements, only IPv6 unicast. VPN, L2VPN, and FlowSpec arriving over BMP are ignored on purpose.

Full configuration

The configuration as it runs in production. Replace the collector, loopback, and groups with your own.

Junos: full BMP for EdgeWarden
set routing-options bmp priority high
set routing-options bmp monitor enable
set routing-options bmp route-monitoring rib-out post-policy
set routing-options bmp station-address 192.0.2.10
set routing-options bmp station-port 11019
set routing-options bmp statistics-timeout 15
set routing-options bmp station BMP local-address 198.51.100.1
set routing-options bmp station BMP connection-mode active
set routing-options bmp station BMP monitor enable
set routing-options bmp station BMP route-monitoring loc-rib
set routing-options bmp station BMP route-monitoring rib-out post-policy
set routing-options bmp station BMP routing-instance default
set protocols bgp precision-timers
set protocols bgp log-updown
set protocols bgp bmp monitor enable
set protocols bgp bmp route-monitoring pre-policy
set protocols bgp bmp route-monitoring rib-out post-policy
set protocols bgp group CLIENTES_FULL_ROUTER bmp monitor disable

Next steps

BMP complements flows: for IPFIX export on the same MX, see How to export IPFIX from a Juniper MX to EdgeWarden and the IPFIX configuration explained line by line. For the BGP fields that arrive over IPFIX (next hop, VRF), see Advanced IPFIX: VRF, BGP next hop, tunnels and DPI in EdgeWarden. Server ports and firewall are in the installation guide.

Related articles

All articles
  • Intermediate

    Juniper MX IPFIX configuration explained line by line

    A real inline J-Flow configuration on an edge MX with two EdgeWarden collectors, explained block by block: FPC, templates, sampling, and interfaces.

    Juniper#ipfix#juniper#jflow#netflow
  • Intermediate

    How to export IPFIX from a Juniper MX to EdgeWarden

    Inline J-Flow on the Juniper MX step by step: IPv4 and IPv6 IPFIX templates, sampling instance, timeouts, and verification on the router and in EdgeWarden.

    Juniper#ipfix#juniper#jflow#netflow
  • Advanced

    BMP on the Huawei NE for EdgeWarden, configuration explained

    An edge Huawei NE BMP configuration line by line: session, Adj-RIB-In, Adj-RIB-Out, and Local-RIB for IPv4 and IPv6, what reaches EdgeWarden, and verification.

    Huawei#bmp#bgp#huawei

Want to see these flows in EdgeWarden?

Create your account in the Customer area and generate the demo license: 7 days with every Enterprise feature, on your own server. Then follow the installation guide to bring up the collector.