04-14-2017 07:59 AM - edited 03-05-2019 08:21 AM
Just curious if anyone is using their ASA to peer via BGP with an ISP and receiving full internet routes. I currently have a set of 5545's (only running static routing) and am in the process of moving to a set of Firepower 4100's running ASA code. I would like to push dynamic routing down to the firewalls, but just not sure that they will handle the full table.
04-14-2017 08:14 AM
Hi
I think it is not good idea to receive all the internet routes, your device could become in a transit device and overload the CPU. Please check these links:
http://www.cisco.com/c/en/us/support/docs/ip/border-gateway-protocol-bgp/23675-27.html
http://www.burningnode.com/2013/07/20/bgp-prevent-being-a-transit-as/
https://networklessons.com/bgp/bgp-prevent-transit-as/
You could use advertise a default route to devices behind the firewall.
Hope it is useful
:-)
04-17-2017 09:59 AM
Is this BGP with a single ISP? Or BGP with multiple ISP? Full table from one or full table from more than one? What is the reason that you are interested in receiving a full table? It seems to me that it is a large step to go from static routing to BGP with the full table and I wonder what leads to the interest in receiving the full table?
HTH
Rick
04-17-2017 11:27 AM
Thanks for the questions and feedback. I was was more asking the question to see if from a performance point could ASA on Firepower 4100 handle a full Internet routing table. My design requirement for this was to dynamically re-route traffic on partial far end ISP failures. I have since had more time to review my design and have come up with a better solution which does not require running BGP down into my firewalls.
04-17-2017 11:36 AM
Thanks for the update. It is good to know that you have found a solution that does not require running BGP down into your firewalls.
HTH
Rick
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide