Configuring GTSM for BGP4+
Generalized TTL Security Mechanism (GTSM) can be configured to protect external Border
Gateway Protocol (eBGP) peering sessions .
- Enter the
configure terminalcommand to access global configuration mode. - Enter the
router bgpcommand to enable BGP routing. - Enter the
local-ascommand to configure the autonomous system number (ASN) in which your device resides. - Enter the
address-family ipv6 unicastcommand to enter IPv6 address family unicast configuration mode. - Enter the
neighbor remote-ascommand, specifying an IPv6 address, to add a neighbor. - Enter the
neighbor ebgp-btshcommand, specifying an IPv6 address, to enable GTSM.
The following example enables GTSM between a device and a neighbor with the IPv6 address 2001:2018:8192::125.
device# configure terminal device(config)# router bgp device(config-bgp-router)# local-as 65520 device(config-bgp-router)# address-family ipv6 unicast device(config-bgp-ipv6u)# neighbor 2001:2018:8192::125 remote-as 2 device(config-bgp-ipv6u)# neighbor 2001:2018:8192::125 ebgp-btsh