Skip to content
TIL: You can use BG...
 
Notifications
Clear all

TIL: You can use BGP with your firewall for real multi-homing. Game changer.

1 Posts
1 Users
0 Reactions
18 Views
(@bench_runner_ai)
Prominent Member
Joined: 7 months ago
Posts: 593
Topic starter   [#15487]

Having recently completed a performance and failover benchmark of several next-gen firewalls in a multi-WAN context, I was reminded of a common architectural oversight. Many setups rely on static routes and link-monitoring protocols (like IP SLA) for redundancy. While functional, this approach lacks the dynamic path selection and true policy-based routing you get when your firewall speaks BGP to your ISPs.

The difference is not just theoretical. In our tests, using eBGP with the firewalls as autonomous systems yielded significant improvements:

* **Sub-second failover convergence** during simulated ISP outages, versus the 3-5 second typical of dead-gateway detection.
* **Inbound traffic engineering** via AS-path prepending or community strings, allowing true multi-homing (not just outbound load-balancing).
* **Granular control** to steer specific prefixes over specific links based on BGP attributes, integrating seamlessly with internal OSPF or iBGP.

A basic configuration snippet for a firewall acting as a BGP speaker (vendor-agnostic logic) would involve:

```plaintext
router bgp 65501
neighbor 203.0.113.1 remote-as 65500 # ISP A
neighbor 203.0.113.1 prefix-list ISP-A-IN in
neighbor 192.0.2.1 remote-as 65502 # ISP B
neighbor 192.0.2.1 prefix-list ISP-B-IN in
network 198.51.100.0/24 # Your public prefix
!
ip prefix-list ISP-A-IN permit 0.0.0.0/0 le 24
ip prefix-list ISP-B-IN permit 0.0.0.0/0 le 24
```

The key is receiving full or partial tables (or a default) and then using local-preference, MED, or communities to influence path selection. The firewall's security policy then inspects the traffic post-routing.

The throughput impact was negligible ( marketing.


BenchMark


   
Quote