diff options
| author | Donatas Abraitis <donatas@opensourcerouting.org> | 2025-01-29 23:03:06 +0200 | 
|---|---|---|
| committer | Donatas Abraitis <donatas@opensourcerouting.org> | 2025-02-05 15:06:56 +0200 | 
| commit | ebf1110cd70a9ef2ace8503be7ec3536865db8b8 (patch) | |
| tree | 84a3e0828c742f34721f1349c0d48ae54789ee94 /bgpd/bgp_network.c | |
| parent | a23b92a8b033a92628277df689920524f15337a4 (diff) | |
bgpd: Do not start BGP session if BGP identifier is not set
If we have IPv6-only network and no IPv4 addresses at all, then by default
0.0.0.0 is created which is treated as malformed according to RFC 6286.
Signed-off-by: Donatas Abraitis <donatas@opensourcerouting.org>
Diffstat (limited to 'bgpd/bgp_network.c')
| -rw-r--r-- | bgpd/bgp_network.c | 17 | 
1 files changed, 16 insertions, 1 deletions
diff --git a/bgpd/bgp_network.c b/bgpd/bgp_network.c index b409cbe706..1411d4d06e 100644 --- a/bgpd/bgp_network.c +++ b/bgpd/bgp_network.c @@ -568,7 +568,7 @@ static void bgp_accept(struct event *thread)  	/* Do not try to reconnect if the peer reached maximum  	 * prefixes, restart timer is still running or the peer -	 * is shutdown. +	 * is shutdown, or BGP identifier is not set (0.0.0.0).  	 */  	if (BGP_PEER_START_SUPPRESSED(peer1)) {  		if (bgp_debug_neighbor_events(peer1)) { @@ -585,6 +585,14 @@ static void bgp_accept(struct event *thread)  		return;  	} +	if (peer1->bgp->router_id.s_addr == INADDR_ANY) { +		zlog_warn("[Event] Incoming BGP connection rejected from %s due missing BGP identifier, set it with `bgp router-id`", +			  peer1->host); +		peer1->last_reset = PEER_DOWN_ROUTER_ID_ZERO; +		close(bgp_sock); +		return; +	} +  	if (bgp_debug_neighbor_events(peer1))  		zlog_debug("[Event] connection from %s fd %d, active peer status %d fd %d",  			   inet_sutop(&su, buf), bgp_sock, connection1->status, @@ -770,6 +778,13 @@ int bgp_connect(struct peer_connection *connection)  	assert(!CHECK_FLAG(connection->thread_flags, PEER_THREAD_READS_ON));  	ifindex_t ifindex = 0; +	if (peer->bgp->router_id.s_addr == INADDR_ANY) { +		peer->last_reset = PEER_DOWN_ROUTER_ID_ZERO; +		zlog_warn("%s: BGP identifier is missing for peer %s, set it with `bgp router-id`", +			  __func__, peer->host); +		return connect_error; +	} +  	if (peer->conf_if && BGP_CONNECTION_SU_UNSPEC(connection)) {  		if (bgp_debug_neighbor_events(peer))  			zlog_debug("Peer address not learnt: Returning from connect");  | 
