Configuring GTSM for BGP4+

Generalized TTL Security Mechanism (GTSM) can be configured to protect external Border Gateway Protocol (eBGP) peering sessions .
  1. Enter the configure terminal command to access global configuration mode.
    device# configure terminal
  2. Enter the router bgp command to enable BGP routing.
    device(config)# router bgp
  3. Enter the local-as command to configure the autonomous system number (ASN) in which your device resides.
    device(config-bgp-router)# local-as 65520
  4. Enter the address-family ipv6 unicast command to enter IPv6 address family unicast configuration mode.
    device(config-bgp-router)# address-family ipv6 unicast
  5. Enter the neighbor remote-as command, specifying an IPv6 address, to add a neighbor.
    device(config-bgp-ipv6u)# neighbor 2001:2018:8192::125 remote-as 2
  6. Enter the neighbor ebgp-btsh command, specifying an IPv6 address, to enable GTSM.
    device(config-bgp-ipv6u)# neighbor 2001:2018:8192::125 ebgp-btsh

The following example enables GTSM between a device and a neighbor with the IPv6 address 2001:2018:8192::125.

device# configure terminal
device(config)# router bgp
device(config-bgp-router)# local-as 65520
device(config-bgp-router)# address-family ipv6 unicast
device(config-bgp-ipv6u)# neighbor 2001:2018:8192::125 remote-as 2
device(config-bgp-ipv6u)# neighbor 2001:2018:8192::125 ebgp-btsh