dev tun0
ifconfig 10.0.0.1 10.0.0.2
remote 1.2.3.4
port 1234
float
keepalive 1 10
secret shared.key
# cipher aes-256-cbc
# auth sha256
Protokolle mit PFS werden bevorzugt.
dev tun0
ifconfig 10.0.0.1 10.0.0.2
remote 1.2.3.4
port 1234
float
keepalive 1 10
secret shared.key
# cipher aes-256-cbc
# auth sha256
und das bitte automatisch.
Heute wird nur BGP weiter behandelt.
define my_asn = <ASN>;
define my_ip = <LOCAL_IP>;
router id my_ip;
function my_net() {
return net ~ [<MY_NET>/24+];
}
protocol device {
scan time 10;
}
protocol kernel {
scan time 20;
learn yes;
export all;
}
protocol static {
route <MY_NET>/24 reject;
}
template bgp peers {
local as my_asn;
import where valid() && !my_net();
export where valid();
route limit 10000;
}
protocol bgp <NAME> from peers {
neighbor <PEER_IP> as <PEER_ASN>;
}