Hi everyone,
My Juniper is doing an BGP based VPN tunnel to Azure Gateways, but the BGP is also sending the default route to Azure - causing a forced tunneling setup where all Azure Internet based traffic is sent to my on-premises rather than straight to Internet..
In the BGP policy I have the following configuration, but this does not stop the default route.. any hints?
the policy statement does a couple of things..
1. it needs to pick up and forward the BGP advertised routes from my DC's for AnyCast DNS
2. it needs to forward static routes set on the Juniper (in case I have static routes configured for backend services)
3. it needs to filter out 0.0.0.0/0 - so it will not be sent to neighbor 172.16.9.229, and 172.16.9.228 (The Azure GW's)
But it's still sending 0.0.0.0/0
My Juniper is doing an BGP based VPN tunnel to Azure Gateways, but the BGP is also sending the default route to Azure - causing a forced tunneling setup where all Azure Internet based traffic is sent to my on-premises rather than straight to Internet..
In the BGP policy I have the following configuration, but this does not stop the default route.. any hints?
the policy statement does a couple of things..
1. it needs to pick up and forward the BGP advertised routes from my DC's for AnyCast DNS
2. it needs to forward static routes set on the Juniper (in case I have static routes configured for backend services)
3. it needs to filter out 0.0.0.0/0 - so it will not be sent to neighbor 172.16.9.229, and 172.16.9.228 (The Azure GW's)
Code:
root@GW2# show policy-options policy-statement preprend1
term prependterm1 {
from neighbor [ 172.16.5.120 172.16.5.121 ];
then {
preference subtract 10;
accept;
}
}
term send-direct {
from protocol direct;
then accept;
}
term removeDefault {
from {
route-filter 0.0.0.0/0 through 0.0.0.0/32;
}
to neighbor [ 172.16.9.228 172.16.9.229 ];
then reject;
}
root@GW2# show protocols bgp group azure
type external;
multihop {
ttl 50;
}
local-address 172.16.5.1;
export preprend1;
peer-as 65515;
local-as 65050;
neighbor 172.16.83.254;
neighbor 172.16.160.242;
neighbor 172.16.9.228;
neighbor 172.16.9.229;