BGP 安全问题:伪AS号连接隐藏真实AS
均其他常规配置,AS2隐藏变为65000
R1# E1/0 AS2 ------- AS3 e1/2 R2 e1/7--------R3e1/7
R1
router bgp 2
bgp router-id 1.1.1.1
bgp log-neighbor-changes
neighbor 2.2.2.2 remote-as 3
neighbor 2.2.2.2 local-as 65000 no-prepend replace-as ---路由器R1 邻居加该命令是,用AS 65000替换本地AS 2
neighbor 2.2.2.2 ebgp-multihop 2
neighbor 2.2.2.2 update-source Loopback0
R2
router bgp 3
bgp router-id 2.2.2.2
bgp log-neighbor-changes
neighbor 1.1.1.1 remote-as 65000
neighbor 1.1.1.1 ebgp-multihop 2
neighbor 1.1.1.1 update-source Loopback0