What BMP gives EdgeWarden
BMP (BGP Monitoring Protocol, RFC 7854) sends the router's BGP tables to the collector in real time. In EdgeWarden they show up under BGP → BMP Station, a read-only screen: nothing there writes to the router.
| RIB | What it shows | Question it answers |
|---|---|---|
in pre | Everything the neighbor announces, before your import filter | Is the neighbor sending me this prefix? |
in post | What passed the import filter | Did my filter drop the prefix? |
out pre | What would go to the neighbor, before the export policy | What would I announce without the policy? |
out post | What is actually announced to the neighbor | What do I announce to this carrier? |
loc-rib | The effective table, the result of the BGP decision | Which path is in use? |
Three automations use this table to act safely: IXP and peering link probing, route confirmation in Traffic Steering, and path validation for failover. Without BMP, they run without that confirmation.
The addresses in this article are documentation addresses: collector 192.0.2.10, MX loopback 198.51.100.1.
Prerequisites
- Enterprise license: without it, EdgeWarden's BMP receiver doesn't start and the log records why. After upgrading, restart the collector.
- Junos with
rib-out(from 19.1R1) andloc-rib(from 19.2R1). This configuration is validated in production on an MX running Junos 20.4R3.8, with all three RIBs at once. - Port 11019/TCP open on the EdgeWarden server, only to your routers' IPs. EdgeWarden opens the port and waits: the router always initiates the connection.
- If
lo0has a Routing Engine protection filter (protect-re), it must accept TCP with source port 11019 from the collector. Otherwise the MX tries to connect, the filter drops the reply, and no error shows up anywhere.
The three BMP hierarchies in Junos
Junos spreads BMP across three places, and each one controls a part:
routing-options bmp station-addressandstation-port: transport in the legacy, unnamed form.routing-options bmp station <name>: transport for a named station, and the only place where Loc-RIB is enabled.protocols bgp bmp: what is sent. This is where pre-policy, post-policy, and rib-out actually work.
Having route-monitoring rib-out post-policy only under routing-options bmp is not enough. Inside a station, the line is accepted and commits without error, but in what we verified in production (MX running Junos 20.4R3.8), on its own it sent no rib-out routes. out post arrived with the line also under protocols bgp bmp (step 2). This is the trap that costs the most time.
Step 1: transport and Loc-RIB
set routing-options bmp priority high
set routing-options bmp monitor enable
set routing-options bmp route-monitoring rib-out post-policy
set routing-options bmp station-address 192.0.2.10
set routing-options bmp station-port 11019
set routing-options bmp statistics-timeout 15
set routing-options bmp station BMP local-address 198.51.100.1
set routing-options bmp station BMP connection-mode active
set routing-options bmp station BMP monitor enable
set routing-options bmp station BMP route-monitoring loc-rib
set routing-options bmp station BMP route-monitoring rib-out post-policy
set routing-options bmp station BMP routing-instance defaultpriority high: BMP's priority among the routing process (rpd) tasks. Withhigh, messages go out with less delay; watch the Routing Engine CPU after turning it on.monitor enable: turns BMP on in the legacy form.route-monitoring rib-out post-policy: requests post-policy rib-out in the legacy form. It stays as is; what guaranteesout postis sent is the step 2 line, underprotocols bgp bmp.station-address 192.0.2.10andstation-port 11019: the EdgeWarden collector, on the default port.statistics-timeout 15: the MX sends statistics reports (per-neighbor counters) every 15 s. They feed the Estatísticas (statistics) tab of the BMP Station screen.station BMP local-address 198.51.100.1: the session source is the loopback. This IP becomes the router's identity in EdgeWarden; use the same IP as the device record, so BMP lines up with SNMP and flows. Without it, the source is whichever interface happens to reach the collector, and a route change makes the router reappear as if it were a different one.station BMP connection-mode active: the MX opens the TCP connection. Required, because EdgeWarden only listens.station BMP monitor enable: turns the named station on.station BMP route-monitoring loc-rib: sends the Loc-RIB, the router's effective table. It only works on the named station.station BMP route-monitoring rib-out post-policy: the same rib-out request, inside the station. It also stays as is; in our validation, without the step 2 line, it sent no rib-out.station BMP routing-instance default: the station uses the main table (the default instance) to reach the collector and monitor BGP.
The MX may open two BMP sessions to the same collector, one through the legacy form and one through the named station. EdgeWarden identifies the router by source IP and treats both as the same router; if one drops, the router stays on the list while the other is alive.
Step 2: what is sent
set protocols bgp precision-timers
set protocols bgp log-updown
set protocols bgp bmp monitor enable
set protocols bgp bmp route-monitoring pre-policy
set protocols bgp bmp route-monitoring rib-out post-policybmp monitor enable: turns BMP on for every BGP group. Step 3 removes the groups you don't need.bmp route-monitoring pre-policy: sendsin pre, everything each neighbor announces before the import filter.bmp route-monitoring rib-out post-policy: sendsout post, what the MX actually announces to each neighbor. This is the line that makes rib-out work.precision-timersandlog-updownaren't BMP, but they help alongside it.precision-timerskeeps BGP keepalives on time even when rpd is busy, and BMP adds load to rpd.log-updownlogs each neighbor going up or down to syslog, to compare with the Eventos de Peers (peer events) tab.
Step 3: leaving groups out of BMP
Turn BMP on globally and switch it off per group. Keep transit, IXP, and peering groups on: they answer "what do I announce to each carrier". Switch off customer groups, especially those receiving a full table.
set protocols bgp group CLIENTES_FULL_ROUTER bmp monitor disableThe line applies to the whole group; the rest of the group configuration (import, export, prefix-limit, neighbors) doesn't change:
set protocols bgp group CLIENTES_FULL_ROUTER type external
set protocols bgp group CLIENTES_FULL_ROUTER import Import_CLIENTES_FULL_ROUTER
set protocols bgp group CLIENTES_FULL_ROUTER family inet unicast prefix-limit maximum 50000
set protocols bgp group CLIENTES_FULL_ROUTER family inet unicast prefix-limit teardown 80
set protocols bgp group CLIENTES_FULL_ROUTER family inet unicast prefix-limit teardown idle-timeout 15
set protocols bgp group CLIENTES_FULL_ROUTER export Export_CLIENTES_FULL_ROUTER
set protocols bgp group CLIENTES_FULL_ROUTER tcp-mss 1000
set protocols bgp group CLIENTES_FULL_ROUTER bmp monitor disable
set protocols bgp group CLIENTES_FULL_ROUTER neighbor 203.0.113.50 description CLIENTE-A
set protocols bgp group CLIENTES_FULL_ROUTER neighbor 203.0.113.50 peer-as 65010Why it matters: in one of our measurements, with BMP on for every group, the volume was 23,388 rows per second. Leaving customer groups out brought it down to 98.5 per second. The rib-out of a customer receiving a full table generates millions of rows per hour, with no value for traffic engineering.
Don't try the opposite, enabling rib-out only on some groups. set protocols bgp group <group> bmp route-monitoring rib-out post-policy is accepted, commits, and sends nothing. At group level, only bmp monitor disable works.
Verification
show bgp bmp
show chassis routing-engineshow bgp bmpshows the stations, the connection state, and what is being monitored.show chassis routing-engineshows whether the Routing Engine handles the load. In the measurement above, with customer groups left out, the RE (RE-S-1600x8) stayed 95% idle.
On the EdgeWarden server, check the TCP session:
ss -tn state established '( sport = :11019 )'In the interface, under BGP → BMP Station:
- The Roteadores (routers) tab shows the MX by IP
198.51.100.1, with its system name. The router only joins the list once it sends the BMP opening message (Initiation); a TCP connection that doesn't speak BMP doesn't show up. - The Route Feed tab shows
in pre,loc-rib, andout postin the RIB column. Ifout postis missing, check that thebmp route-monitoring rib-out post-policyline is underprotocols bgp. - The Eventos de Peers tab shows neighbors going up and down.
Open 11019/TCP on the server only to your routers' IPs. Anyone who connects to that port and speaks BMP joins the router list and can send forged routes to the automations that depend on BMP.
EdgeWarden processes IPv4 unicast and, in multiprotocol announcements, only IPv6 unicast. VPN, L2VPN, and FlowSpec arriving over BMP are ignored on purpose.
Full configuration
The configuration as it runs in production. Replace the collector, loopback, and groups with your own.
set routing-options bmp priority high
set routing-options bmp monitor enable
set routing-options bmp route-monitoring rib-out post-policy
set routing-options bmp station-address 192.0.2.10
set routing-options bmp station-port 11019
set routing-options bmp statistics-timeout 15
set routing-options bmp station BMP local-address 198.51.100.1
set routing-options bmp station BMP connection-mode active
set routing-options bmp station BMP monitor enable
set routing-options bmp station BMP route-monitoring loc-rib
set routing-options bmp station BMP route-monitoring rib-out post-policy
set routing-options bmp station BMP routing-instance default
set protocols bgp precision-timers
set protocols bgp log-updown
set protocols bgp bmp monitor enable
set protocols bgp bmp route-monitoring pre-policy
set protocols bgp bmp route-monitoring rib-out post-policy
set protocols bgp group CLIENTES_FULL_ROUTER bmp monitor disableNext steps
BMP complements flows: for IPFIX export on the same MX, see How to export IPFIX from a Juniper MX to EdgeWarden and the IPFIX configuration explained line by line. For the BGP fields that arrive over IPFIX (next hop, VRF), see Advanced IPFIX: VRF, BGP next hop, tunnels and DPI in EdgeWarden. Server ports and firewall are in the installation guide.