BGP FlowSpec Operational Commands

BGP Show Commands

show bgp peer

The 'show bgp peer' commands display information on BGP peers.

Syntax:

show bgp peer <option> …​

Option Description

-

Without any option, the commands display all BGP peers in all instances in a summary table format.

detail

Detailed information on all BGP peers in all instances in a list view.

<peer-name>

Detailed information on the peer with the given name.

history

Displays BGP peer history information such as the peer state down reasons.

history <peer-address>

Displays BGP peer history information such as the peer state down reasons for a specified peer.

address <peer-address>

Detailed information on the peer with the given IP address.

instance <instance-name>

Summary of all BGP peers in the given instance.

instance <instance-name> detail

Detailed information on all BGP peers in the given instance.

instance <instance-name> detail <peer-name>

Detailed information on the peer with the given name in the given instance.

instance <instance-name> detail address <peer-address>

Detailed information on the peer with the given IP address in the given instance.

statistics

Received and sent BGP prefixes per AFI/SAFI for all peers in all instances.

statistics peer <peer-name>

Received and sent BGP prefixes per AFI/SAFI for the peer with the given name.

statistics peer address <peer-address>

Received and sent BGP prefixes per AFI/SAFI for the peer with the given IP address.

statistics instance <instance-name> peer <peer-name>

Received and sent BGP prefixes per AFI/SAFI for the peer with the given name in the given instance.

statistics instance <instance-name> peer address <peer-address>

Received and sent BGP prefixes per AFI/SAFI for the peer with the given IP address in the given instance

Example 1: BGP Peer Summary View

supervisor@rtbrick: op> show bgp peer
Instance: default
  Peer                                     Remote AS    State         Up/Down Time               PfxRcvd              PfxSent
  PE2                                      65542        Established   0d:00h:00m:21s             8                    17
  SN-STD-2-3966602                         65549        Established   0d:00h:00m:23s             3                    3

Example 2: BGP Peer Detail View

supervisor@rtbrick: op> show bgp peer detail
Peer: PE2, Peer IP: 192.0.2.2, Remote AS: 65542, Local IP: 192.0.2.1, Local AS: 65541, Any AS: False
  Type: ebgp, State: Established, Up/Down Time: Wed Jul 15 19:25:47 GMT +0000 2026
  Discovered on interface: -
  Last transition: Wed Jul 15 19:25:47 GMT +0000 2026, Flap count: 0
  Peer ID        : 198.51.100.21, Local ID: 198.51.100.11
  Instance       : default, Peer group: PE2
  6PE enabled    : False
  TTL security   : False, TTL limit: -
  Deactivate     : False
  Authentication:
    ID: BGP_AUTH_HMAC-SHA-256-128, Algorithm: HMAC-SHA-256-128
  Timer values:
    Peer keepalive : 30s, Local keepalive: 30s
    Peer holddown  : 90s, Local holddown : 90s
    Connect retry  : 30s
  Timers:
    Connect retry timer : 0
    Keepalive timer     : expires in 6s 536415us
    Holddown timer      : expires in 1m 8s 418579us
  NLRIs:
    Sent           : ['ipv4-unicast', 'ipv6-unicast', 'ipv4-flowspec', 'ipv6-flowspec', 'ipv4-labeled-unicast', 'ipv6-labeled-unicast']
    Received       : ['ipv4-unicast', 'ipv6-unicast', 'ipv4-flowspec', 'ipv6-flowspec', 'ipv4-labeled-unicast', 'ipv6-labeled-unicast']
    Negotiated     : ['ipv4-unicast', 'ipv6-unicast', 'ipv4-flowspec', 'ipv6-flowspec', 'ipv4-labeled-unicast', 'ipv6-labeled-unicast']
  Capabilities:
    Addpath sent                  : None
    Addpath received              : None
    Addpath negotiated            : None
    Extended nexthop sent         : None
    Extended nexthop received     : None
    Extended nexthop negotiated   : None
    Multiple labels sent          : None
    Multiple labels received      : None
    Multiple labels negotiated    : None
    Capabilities:
      Feature                      Sent            Received        Negotiated
      Route refresh                True            True            True
      4 byte AS                    True            True            True
      Graceful restart             False           False           False
      Link local only              False           False           False
  Prefix Limit:
  End of RIB:
    Address family                 Sent                                Received
    IPv4 unicast                   Wed Jul 15 19:25:53 GMT +0000 2026  Wed Jul 15 19:25:53 GMT +0000 2026
    IPv4 labeled-unicast           Wed Jul 15 19:25:53 GMT +0000 2026  Wed Jul 15 19:25:53 GMT +0000 2026
    IPv6 unicast                   Wed Jul 15 19:25:53 GMT +0000 2026  Wed Jul 15 19:25:53 GMT +0000 2026
    IPv6 labeled-unicast           Wed Jul 15 19:25:53 GMT +0000 2026  Wed Jul 15 19:25:53 GMT +0000 2026
    IPv4 VPN-unicast               never                               never
    IPv6 VPN-unicast               never                               never
    IPv4 flowspec                  Wed Jul 15 19:25:53 GMT +0000 2026  Wed Jul 15 19:25:53 GMT +0000 2026
    IPv6 flowspec                  Wed Jul 15 19:25:53 GMT +0000 2026  Wed Jul 15 19:25:53 GMT +0000 2026
    IPv4 VPN-multicast             never                               never
    L2VPN VPLS                     never                               never
    L2VPN EVPN                     never                               never
  RPKI Validation Stats:
    Address family                 Valid    Invalid    Unknown
    IPv4 unicast                       0          0          0
    IPv6 unicast                       0          0          0
  Message stats:
    Session stats:
      Direction              Open          Update       Keepalive          Notify   Route refresh
      Input                     1               8               1               0               0
      Output                    1              11               1               0               0
    Total stats:
      Input                     1               8               1               0               0
      Output                    1              11               1               0               0
    Route stats:
      Address family                        Received            Sent    Prefix limit    Idle timeout
      IPv4 unicast                                 4               7               0               0
      IPv4 labeled-unicast                         0               0               0               0
      IPv6 unicast                                 4               7               0               0
      IPv6 labeled-unicast                         0               0               0               0
      IPv4 VPN-unicast                             0               0               0               0
      IPv6 VPN-unicast                             0               0               0               0
      IPv4 multicast                               0               0               0               0
      IPv4 VPN-multicast                           0               0               0               0
      L2VPN VPLS                                   0               0               0               0
      L2VPN EVPN                                   0               0               0               0
      IPv4 Flowspec                                0               2               0               0
      IPv6 Flowspec                                0               1               0               0
Peer: SN-STD-2-3966602, Peer IP: 192.0.2.102, Remote AS: 65549, Local IP: 192.0.2.101, Local AS: 65541, Any AS: False
  Type: ebgp, State: Established, Up/Down Time: Wed Jul 15 19:25:45 GMT +0000 2026
  Discovered on interface: -
  Last transition: Wed Jul 15 19:25:45 GMT +0000 2026, Flap count: 0
  Peer ID        : 198.51.100.91, Local ID: 198.51.100.11
  Instance       : default, Peer group: FS
  6PE enabled    : False
  TTL security   : False, TTL limit: -
  Authentication:
    ID: , Algorithm: HMAC-SHA-256-128
  Timer values:
    Peer keepalive : 30s, Local keepalive: 30s
    Peer holddown  : 90s, Local holddown : 90s
    Connect retry  : 30s
  Timers:
    Connect retry timer : 0
    Keepalive timer     : expires in 2s 632207us
    Holddown timer      : expires in 1m 6s 383572us
  NLRIs:
    Sent           : ['ipv4-flowspec', 'ipv6-flowspec']
    Received       : ['ipv4-flowspec', 'ipv6-flowspec']
    Negotiated     : ['ipv4-flowspec', 'ipv6-flowspec']
  Capabilities:
    Addpath sent                  : None
    Addpath received              : None
    Addpath negotiated            : None
    Extended nexthop sent         : None
    Extended nexthop received     : ['ipv4-flowspec', 'ipv6-flowspec']
    Extended nexthop negotiated   : None
    Multiple labels sent          : None
    Multiple labels received      : None
    Multiple labels negotiated    : None
    Capabilities:
      Feature                      Sent            Received        Negotiated
      Route refresh                True            True            True
      4 byte AS                    True            True            True
      Graceful restart             False           False           False
      Link local only              False           False           False
  Prefix Limit:
  End of RIB:
    Address family                 Sent                                Received
    IPv4 unicast                   never                               never
    IPv4 labeled-unicast           never                               never
    IPv6 unicast                   never                               never
    IPv6 labeled-unicast           never                               never
    IPv4 VPN-unicast               never                               never
    IPv6 VPN-unicast               never                               never
    IPv4 flowspec                  Wed Jul 15 19:25:51 GMT +0000 2026  Wed Jul 15 19:25:51 GMT +0000 2026
    IPv6 flowspec                  Wed Jul 15 19:25:51 GMT +0000 2026  Wed Jul 15 19:25:51 GMT +0000 2026
    IPv4 VPN-multicast             never                               never
    L2VPN VPLS                     never                               never
    L2VPN EVPN                     never                               never
  Message stats:
    Session stats:
      Direction              Open          Update       Keepalive          Notify   Route refresh
      Input                     1               3               1               0               0
      Output                    1               2               1               0               0
    Total stats:
      Input                     1               3               1               0               0
      Output                    1               2               1               0               0
    Route stats:
      Address family                        Received            Sent    Prefix limit    Idle timeout
      IPv4 unicast                                 0               0               0               0
      IPv4 labeled-unicast                         0               0               0               0
      IPv6 unicast                                 0               0               0               0
      IPv6 labeled-unicast                         0               0               0               0
      IPv4 VPN-unicast                             0               0               0               0
      IPv6 VPN-unicast                             0               0               0               0
      IPv4 multicast                               0               0               0               0
      IPv4 VPN-multicast                           0               0               0               0
      L2VPN VPLS                                   0               0               0               0
      L2VPN EVPN                                   0               0               0               0
      IPv4 Flowspec                                2               2               0               0
      IPv6 Flowspec                                1               1               0               0

Example 3: BGP Peer history for a specified peer

supervisor@rtbrick.net: op> show bgp peer history peer address 192:168::40
Instance: vrf1
  Peer Address               Source Address             Type             Last Reset Reason
  192:168::40                192:168:5::20              FSM Error        FSM Error, Sub-Code: Unexpected message in OpenSent State

show bgp rib-in

This command displays the received routes.

Syntax:

show bgp rib-in <option> …​

Option Description

-

Without any option, the command displays information on the received BGP routing table on all instances in a summary table format.

<afi>

BGP routing table summary for the given address family (AFI), all sub-address families and all instances. Supported AFI values are 'ipv4' and 'ipv6'.

<afi> <safi>

BGP routing table summary for the given address family (AFI) and sub-address family (SAFI), and all instances. Supported SAFI values are 'labeled-unicast', 'unicast', 'vpn-multicast', 'vpn-unicast', ‘evpn-vpws’, ‘evpn’, ‘vpls-vpws’, ‘vpls’, and ‘flowspec’.

<afi> <safi> detail

Detailed list view of the BGP routing table for the given address family (AFI) and sub-address family (SAFI), and all instances.

instance <instance-name> policy-accept

Displays all BGP FlowSpec routes received in the specified address family (ipv4, ipv6, or l2vpn) that were accepted by the BGP import policy.

instance <instance-name> policy-accept detail

Detailed view of the BGP FlowSpec routes received in the specified address family (ipv4, ipv6, or l2vpn) that were accepted by the BGP import policy.

instance <instance-name> policy-deny

Displays all BGP FlowSpec routes received in the specified address family (ipv4, ipv6, or l2vpn) that were denied by the BGP import policy.

instance <instance-name> policy-deny detail

Detailed view of the BGP FlowSpec routes received in the specified address family (ipv4, ipv6, or l2vpn) that were denied by the BGP import policy.

<afi> <safi> <prefix>

BGP routing table entry for the given prefix and all instances.

<afi> <safi> instance <instance-name>

BGP routing table summary for the given AFI, SAFI, and instance.

<afi> <safi> instance <instance-name> detail

Detailed list view of BGP routing table for the given AFI, SAFI, and instance.

<afi> <safi> instance <instance-name> <prefix>

BGP routing table entry for the given prefix and instance.

<afi> <safi> community <community-name>

BGP community details for the given AFI, SAFI, and instance.

<afi> <safi> error

BGP route with error status for the given AFI, SAFI, and instance.

<afi> <safi> peer <name> / peer address <ip>

Peer name or address.

Example 1: Summary view of the BGP rib-in for the ipv4 flowspec address family.

supervisor@rtbrick: op> show bgp rib-in ipv4 flowspec
Instance: default, AFI: ipv4, SAFI: flowspec
  Hostname: SN-STD-2-3966602, Peer IP: 192.0.2.102
  Source IP: 192.0.2.101, Total routes: 2
    Flowspec Hash                                Match                                        Action                        AS Path
    521b87e1                                     dest-prefix : 198.51.100.91/32               rate-limit: 400.0 kBps        65549
                                                        src-prefix  : 198.51.100.92/32
                                                        ip-proto    : [==icmp ]
                                                        port        : [==49152 ]
                                                        dst-port    : [==49152 ]
                                                        src-port    : [==49152 ]
    ad2c54f5                                     dest-prefix : 198.51.100.91/32               rate-limit: 400.0 kBps        65549
                                                        src-prefix  : 198.51.100.92/32
                                                        ip-proto    : [==icmp ]
                                                        dst-port    : [==49152 ]
                                                        src-port    : [==49152 ]

Example 2: Summary view of the BGP rib-in for the ipv6 flowspec address family.

supervisor@rtbrick: op> show bgp rib-in ipv6 flowspec
Instance: default, AFI: ipv6, SAFI: flowspec
  Hostname: SN-STD-2-3966602, Peer IP: 192.0.2.102
  Source IP: 192.0.2.101, Total routes: 1
    Flowspec Hash                                Match                                        Action                        AS Path
    7bfa7233                                     dest-prefix : 2001:db8:0:1::91/128           None                          65549
                                                        src-prefix  : 2001:db8:0:1::92/128
                                                        ip-proto    : [==icmp ]
                                                        src-port    : [==49154 ]

Example 3: Summary view of the BGP rib-in for the IPv4 with the error flag.

supervisor@rtbrick>rtbrick.net: op> show bgp rib-in ipv4
Flags: & - Imported, ! - Error
Instance: default, AFI: ipv4, SAFI: unicast
  Hostname: Local, Peer IP: 0.0.0.0
  Source IP: 0.0.0.0, Total routes: 4
    Flags  Prefix           Next Hop  MED       Lpref       AS Path
           12.0.0.0/24      -         0         100         -
           12.1.0.0/24      -         0         100         -
           192.168.0.10/32  -         0         100         -
           192.168.0.11/32  -         0         100         -
  Hostname: P1, Peer IP: 12.0.0.2
  Source IP: 12.0.0.1, Total routes: 4
    Flags  Prefix           Next Hop  MED       Lpref       AS Path
           12.0.0.0/24      12.0.0.2  0         -           4200000002
           12.1.0.0/24      12.0.0.2  0         -           4200000002
           192.168.0.20/32  12.0.0.2  0         -           4200000002
           192.168.0.21/32  12.0.0.2  0         -           4200000002

show bgp rib-out

This command displays the send routes.

Syntax:

show bgp rib-out <option> …​

Option Description

-

Without any option, the command displays advertised BGP routes for all instances.

<afi>

BGP routing table summary for the given address family (AFI), all sub-address families and all instances. Supported AFI values are 'ipv4' and 'ipv6'.

<afi> <safi>

BGP routing table summary for the given address family (AFI) and sub-address family (SAFI), and all instances. Supported SAFI values are 'unicast', 'labeled-unicast', 'multicast', 'vpn-unicast', ‘evpn’, ‘vpls’, ‘vpls-vpws’, and ‘flowspec’.

<afi> <safi> detail

Detailed list view of the BGP routing table for the given address family (AFI) and sub-address family (SAFI), and all instances.

<afi> <safi> <prefix>

BGP routing table entry for the given prefix and all instances.

<afi> <safi> instance <instance-name>

BGP routing table summary for the given AFI, SAFI, and instance.

<afi> <safi> instance <instance-name> detail

Detailed list view of BGP routing table for the given AFI, SAFI, and instance.

<afi> <safi> instance <instance-name> <prefix>

BGP routing table entry for the given prefix and instance.

<afi> <safi> peer <name> / peer address <ip>

Peer name or address

Example 1: Summary view of the IPv4 FlowSpec routes advertised to a peer

supervisor@rtbrick: op> show bgp rib-out ipv4 flowspec
Flags: N - RPKI Unknown, I - RPKI Invalid, V - RPKI Valid
Instance: default, AFI: ipv4, SAFI: flowspec
  Peer-group: FS, Sent routes: 2
   Flags  Flowspec Hash                Match                                         Action                       Origin
          521b87e1                     dest-prefix : 198.51.100.91/32                None                         Incomplete
                                       src-prefix  : 198.51.100.92/32
                                       ip-proto    : [==icmp ]
                                       port        : [==49152 ]
                                       dst-port    : [==49152 ]
                                       src-port    : [==49152 ]
          ad2c54f5                     dest-prefix : 198.51.100.91/32                None                         Incomplete
                                       src-prefix  : 198.51.100.92/32
                                       ip-proto    : [==icmp ]
                                       dst-port    : [==49152 ]
                                       src-port    : [==49152 ]
  Peer-group: PE2, Sent routes: 2
   Flags  Flowspec Hash                Match                                         Action                       Origin
          521b87e1                     dest-prefix : 198.51.100.91/32                None                         Incomplete
                                       src-prefix  : 198.51.100.92/32
                                       ip-proto    : [==icmp ]
                                       port        : [==49152 ]
                                       dst-port    : [==49152 ]
                                       src-port    : [==49152 ]
          ad2c54f5                     dest-prefix : 198.51.100.91/32                None                         Incomplete
                                       src-prefix  : 198.51.100.92/32
                                       ip-proto    : [==icmp ]
                                       dst-port    : [==49152 ]
                                       src-port    : [==49152 ]

Example 2: Summary view of the IPv6 FlowSpec routes advertised to a peer

supervisor@rtbrick: op> show bgp rib-out ipv6 flowspec
Flags: N - RPKI Unknown, I - RPKI Invalid, V - RPKI Valid
Instance: default, AFI: ipv6, SAFI: flowspec
  Peer-group: FS, Sent routes: 1
   Flags  Flowspec Hash                Match                                         Action                       Origin
          7bfa7233                     dest-prefix : 2001:db8:0:1::91/128            None                         Incomplete
                                       src-prefix  : 2001:db8:0:1::92/128
                                       ip-proto    : [==icmp ]
                                       src-port    : [==49154 ]
  Peer-group: PE2, Sent routes: 1
   Flags  Flowspec Hash                Match                                         Action                       Origin
          7bfa7233                     dest-prefix : 2001:db8:0:1::91/128            None                         Incomplete
                                       src-prefix  : 2001:db8:0:1::92/128
                                       ip-proto    : [==icmp ]
                                       src-port    : [==49154 ]

show bgp fib

The 'show bgp fib' commands display the BGP forwarding table. In contrast to the 'show bgp rib' commands, the output of the 'show bgp fib' commands includes only the selected routes. The BGP route selection occurs between the RIB and the FIB.

Syntax:

show bgp fib <option> …​

Option Description

-

Without any option, the commands display the BGP forwarding table for all address families and all instances in a summary table format.

afi>

BGP forwarding table summary for the given address family (AFI), all sub-address families and all instances. Supported AFI values are 'ipv4' and 'ipv6'.

<afi> <safi>

BGP forwarding table summary for the given address family (AFI) and sub-address family (SAFI), and all instances. Supported SAFI values are 'unicast', 'labeled-unicast', 'vpn-multicast', 'vpn-unicast', ‘evpn-vpws’, ‘vpls’, ‘vpls-vpws’ and ‘flowspec’.

<afi> <safi> detail

Detailed list view of the BGP forwarding table for the given address family (AFI) and sub-address family (SAFI), and all instances.

<afi> <safi> <prefix>

BGP forwarding table entry for the given prefix and all instances.

<afi> <safi> instance <instance-name>

BGP forwarding table summary for the given AFI, SAFI, and instance.

<afi> <safi> instance <instance-name> detail

Detailed list view of BGP forwarding table for the given AFI, SAFI, and instance.

<afi> <safi> instance <instance-name> <prefix>

BGP forwarding table entry for the given prefix and instance.

Example 1: Summary view of the BGP FIB for IPv4 flowspec address family

supervisor@rtbrick: op> show bgp fib ipv4 flowspec
Instance: default, AFI: ipv4, SAFI: flowspec, Total routes: 2
  Flowspec Hash             Match                                         Action                    Priority   Status
  521b87e1                  dest-prefix : 198.51.100.91/32                rate-limit: 400.0 kBps    1501       Ignored
                            src-prefix  : 198.51.100.92/32
                            ip-proto    : [==icmp ]
                            port        : [==49152 ]
                            dst-port    : [==49152 ]
                            src-port    : [==49152 ]
  ad2c54f5                  dest-prefix : 198.51.100.91/32                rate-limit: 400.0 kBps    1502       Valid
                            src-prefix  : 198.51.100.92/32
                            ip-proto    : [==icmp ]
                            dst-port    : [==49152 ]
                            src-port    : [==49152 ]

Example 2: Summary view of the BGP FIB for a specific IPv4 flowspec address family

supervisor@rtbrick: op> show bgp fib ipv4 flowspec ad2c54f5
Instance: default, AFI: ipv4, SAFI: flowspec, Total routes: 1
  Flowspec hash: ad2c54f5
    Match:
      dest-prefix:  198.51.100.91/32
      src-prefix:  198.51.100.92/32
      ip-proto:  [==icmp ]
      dst-port:  [==49152 ]
      src-port:  [==49152 ]
    Action:
      rate-limit: 400.0 kBps
    Extended community:
      ['traffic-rate-bytes:0:400000.000000']
    Priority: 1502
    Status: Valid
    Number of ACL added: 1

Example 3: Summary view of the BGP FIB for IPv6 flowspec address family

supervisor@rtbrick: op> show bgp fib ipv6 flowspec
Instance: default, AFI: ipv6, SAFI: flowspec, Total routes: 1
  Flowspec Hash             Match                                         Action                    Priority   Status
  7bfa7233                  dest-prefix : 2001:db8:0:1::91/128            None                      1501       Valid
                            src-prefix  : 2001:db8:0:1::92/128
                            ip-proto    : [==icmp ]
                            src-port    : [==49154 ]

Example 4: Summary view of the BGP FIB for a specific IPv6 flowspec address family

supervisor@rtbrick: op> show bgp fib ipv6 flowspec 7bfa7233
Instance: default, AFI: ipv6, SAFI: flowspec, Total routes: 1
  Flowspec hash: 7bfa7233
    Match:
      dest-prefix:  2001:db8:0:1::91/128
      src-prefix:  2001:db8:0:1::92/128
      ip-proto:  [==icmp ]
      src-port:  [==49154 ]
    Action:
      None
    Extended community:
      ['None']
    Priority: 1501
    Status: Valid
    Number of ACL added: 1

Show Command Filter Options for RIB-in, RIB-out, and FIB

Syntax

show bgp fib|rib-in|rib-out <afi> flowspec filter <options>

Option Description

<afi> flowspec filter <options>

Filter BGP Flowspec entries across the RIB based on the option specified.

destination-port

Filters based on destination port number.

destination-prefix

Filters based on the destination IP prefix.

instance-name

Filters entries based on the BGP instance. Useful to verify the Flowspec entries specific to one instance in a multi-instance BGP configurations.

ip-proto

Filters based on the protocol.

port

Filters Flowspec entries based on the protocol port number.

source-port

Filters entries based on the source port. Useful to identify different applications or services originating from specific ports.

source-prefix

Filters entries based on the source IP prefix.

Example 1: Filter BGP RIB-in Flowspec entries based on the port

supervisor@rtbrick: op> show bgp rib-in ipv4 flowspec filter port 49152
Instance: default, AFI: ipv4, SAFI: flowspec
  Hostname: SN-STD-2-3966602, Peer IP: 192.0.2.102
  Source IP: 192.0.2.101, Total routes: 1
    Flowspec Hash                                Match                                        Action                        AS Path
    521b87e1                                     dest-prefix : 198.51.100.91/32               rate-limit: 400.0 kBps        65549
                                                        src-prefix  : 198.51.100.92/32
                                                        ip-proto    : [==icmp ]
                                                        port        : [==49152 ]
                                                        dst-port    : [==49152 ]
                                                        src-port    : [==49152 ]

Example 2: Filter BGP RIB-in Flowspec entries based on destination prefix

supervisor@rtbrick: op> show bgp rib-in ipv4 flowspec filter destination-prefix 198.51.100.91/32
Instance: default, AFI: ipv4, SAFI: flowspec
  Hostname: SN-STD-2-3966602, Peer IP: 192.0.2.102
  Source IP: 192.0.2.101, Total routes: 2
    Flowspec Hash                                Match                                        Action                        AS Path
    521b87e1                                     dest-prefix : 198.51.100.91/32               rate-limit: 400.0 kBps        65549
                                                        src-prefix  : 198.51.100.92/32
                                                        ip-proto    : [==icmp ]
                                                        port        : [==49152 ]
                                                        dst-port    : [==49152 ]
                                                        src-port    : [==49152 ]
    ad2c54f5                                     dest-prefix : 198.51.100.91/32               rate-limit: 400.0 kBps        65549
                                                        src-prefix  : 198.51.100.92/32
                                                        ip-proto    : [==icmp ]
                                                        dst-port    : [==49152 ]
                                                        src-port    : [==49152 ]

Example 3: Filter BGP RIB-in Flowspec entries based on source prefix

supervisor@rtbrick: op> show bgp rib-in ipv4 flowspec filter source-prefix 198.51.100.92/32
Instance: default, AFI: ipv4, SAFI: flowspec
  Hostname: SN-STD-2-3966602, Peer IP: 192.0.2.102
  Source IP: 192.0.2.101, Total routes: 2
    Flowspec Hash                                Match                                        Action                        AS Path
    521b87e1                                     dest-prefix : 198.51.100.91/32               rate-limit: 400.0 kBps        65549
                                                        src-prefix  : 198.51.100.92/32
                                                        ip-proto    : [==icmp ]
                                                        port        : [==49152 ]
                                                        dst-port    : [==49152 ]
                                                        src-port    : [==49152 ]
    ad2c54f5                                     dest-prefix : 198.51.100.91/32               rate-limit: 400.0 kBps        65549
                                                        src-prefix  : 198.51.100.92/32
                                                        ip-proto    : [==icmp ]
                                                        dst-port    : [==49152 ]
                                                        src-port    : [==49152 ]

Example 4: Filter BGP RIB-in Flowspec entries based on destination port

supervisor@rtbrick: op> show bgp rib-in ipv4 flowspec filter destination-port 49152
Instance: default, AFI: ipv4, SAFI: flowspec
  Hostname: SN-STD-2-3966602, Peer IP: 192.0.2.102
  Source IP: 192.0.2.101, Total routes: 2
    Flowspec Hash                                Match                                        Action                        AS Path
    521b87e1                                     dest-prefix : 198.51.100.91/32               rate-limit: 400.0 kBps        65549
                                                        src-prefix  : 198.51.100.92/32
                                                        ip-proto    : [==icmp ]
                                                        port        : [==49152 ]
                                                        dst-port    : [==49152 ]
                                                        src-port    : [==49152 ]
    ad2c54f5                                     dest-prefix : 198.51.100.91/32               rate-limit: 400.0 kBps        65549
                                                        src-prefix  : 198.51.100.92/32
                                                        ip-proto    : [==icmp ]
                                                        dst-port    : [==49152 ]
                                                        src-port    : [==49152 ]

Example 5: Filter BGP RIB-in Flowspec entries based on source port

supervisor@rtbrick: op> show bgp rib-in ipv4 flowspec filter source-port 49152
Instance: default, AFI: ipv4, SAFI: flowspec
  Hostname: SN-STD-2-3966602, Peer IP: 192.0.2.102
  Source IP: 192.0.2.101, Total routes: 2
    Flowspec Hash                                Match                                        Action                        AS Path
    521b87e1                                     dest-prefix : 198.51.100.91/32               rate-limit: 400.0 kBps        65549
                                                        src-prefix  : 198.51.100.92/32
                                                        ip-proto    : [==icmp ]
                                                        port        : [==49152 ]
                                                        dst-port    : [==49152 ]
                                                        src-port    : [==49152 ]
    ad2c54f5                                     dest-prefix : 198.51.100.91/32               rate-limit: 400.0 kBps        65549
                                                        src-prefix  : 198.51.100.92/32
                                                        ip-proto    : [==icmp ]
                                                        dst-port    : [==49152 ]
                                                        src-port    : [==49152 ]

Example 6: Filter BGP RIB-in Flowspec entries based on IP protocol

supervisor@rtbrick: op> show bgp rib-in ipv4 flowspec filter ip-proto icmp
Instance: default, AFI: ipv4, SAFI: flowspec
  Hostname: SN-STD-2-3966602, Peer IP: 192.0.2.102
  Source IP: 192.0.2.101, Total routes: 2
    Flowspec Hash                                Match                                        Action                        AS Path
    521b87e1                                     dest-prefix : 198.51.100.91/32               rate-limit: 400.0 kBps        65549
                                                        src-prefix  : 198.51.100.92/32
                                                        ip-proto    : [==icmp ]
                                                        port        : [==49152 ]
                                                        dst-port    : [==49152 ]
                                                        src-port    : [==49152 ]
    ad2c54f5                                     dest-prefix : 198.51.100.91/32               rate-limit: 400.0 kBps        65549
                                                        src-prefix  : 198.51.100.92/32
                                                        ip-proto    : [==icmp ]
                                                        dst-port    : [==49152 ]
                                                        src-port    : [==49152 ]

Validating FlowSpec ACLs

In forwarding, the FlowSpec rules can be validated using the "show acl rule <…​>" command as shown in the example below:

Example: Validate BGP FlowSpec ACL rule

supervisor@rtbrick: op> show acl rule bgp-flowspec-ad2c54f59cf8944514bcfb21a0e2beec40a45efaea900442
Rule: bgp-flowspec-ad2c54f59cf8944514bcfb21a0e2beec40a45efaea900442
  ACL type: ext_l3v4
  Ordinal: 0             Priority: 1502
    Match:
      Direction: external
      Instance: default
      Destination IPv4 prefix: 198.51.100.91/32
      Source IPv4 prefix: 198.51.100.92/32
      Destination L4 port: 49152
      Source L4 port: 49152
      IP protocol: icmp
    Action:
      Policer profile name: bgp-flowspec-ad2c54f59cf8944514bcfb21a0e2beec40a45efaea900442
    Result:
      ACL Handle: 5
      External:
        Value: 80224256
          Is Trap ID: No
          Trap ID: 0
          Trap Strength: 0
          Is QoS: Yes
          Class: 0
          Policer ID: 612

BGP FlowSpec Clear Commands

Clear commands allow to reset operational states.

BGP Peer

This commands resets BGP peerings.

Syntax:

clear bgp peer <option> …​

Option Description

all

Clears all the BGP peers.

all soft-in <afi> <safi>

Sends route refresh to all neighbors.

all soft-out <afi> <safi>

Re-advertises all the routes previously sent to the peer.

all stats

Clears the statistics of all the BGP peers.

instance <instance> <peer-ip>

Clears the peer for the given instance and peer IP address.

instance <instance> <peer-ip> source <src-ip>

Clears a specific peer for the given peer IP address and source IP address in the specified instance.

instance <instance> all

Clears all peers in the given instance.

instance <instance> <peer-ip> source <src-ip> soft-in <afi> <safi>

Sends route refresh to specific peer for the given instance, peer-ip, source-ip and address-family.

instance <instance> <peer-ip> soft-in <afi> <safi>

Sends route refresh to peer for the given instance, peer-ip and address-family.

instance <instance> all soft-in <afi> <safi>

Sends route refresh to all peers for the given instance and address family.

instance <instance> <peer-ip> source <src-ip> soft-out <afi> <safi>

Re-advertises all the routes previously sent to the specific peer for the given instance, peer-ip, source-ip and address-family.

instance <instance> <peer-ip> soft-out <afi> <safi>

Sends route refresh to peer for a given instance, peer-ip and address-family.

instance <instance> all soft-out <afi> <safi>

Sends route update to all peers for given instance and address family.

instance <instance> <peer-ip> source <src-ip> stats

Clears the statistics of a specific peer for a given instance, peer-ip and source-IP.

instance <instance> <peer-ip> stats

Clears the statistics of the peer for a given instance and peer-IP.

instance <instance> all stats

Clears the statistics of all peers for a given instance.

Example: The example below shows how to clear all the BGP peers.

supervisor@rtbrick: op> clear bgp peer all

Example: Route Refresh in IPv4/IPv6 for BGP FlowSpec

supervisor@rtbrick: op> clear bgp peer all soft-out ipv4 flowspec
supervisor@rtbrick: op> clear bgp peer all soft-in ipv6 flowspec