Page MenuHomeVyOS Platform

FRR ISP Profile
Open, NormalPublicFEATURE REQUEST

Description

Add FRR 'isp' configuration profile optimized for full-table internet routing at IXP and ISP scale (set system frr profile isp).
FRR currently provides two configuration profiles selectable in VyOS via:

https://docs.frrouting.org/en/latest/basic.html#profiles
• traditional - reflects defaults adhering mostly to IETF standards or common practices in wide-area internet routing.
• datacenter - reflects a single administrative domain with intradomain links using aggressive timers.

This Feature Request suggests a profile more suitable for ISP and IXP deployments running full-table BGP at large scale, with 100+ peers and full routes IPv4 and IPv6 peerings.

traditional:
BGP keepalive        : 30s
BGP hold timer       : 90s
MRAI eBGP            : 30s
MRAI iBGP            :  5s
ebgp-requires-policy : enabled (RFC 8212)
multipath-relax      : disabled
watchfrr timeout     : 90s
BGP update-delay     : disabled

datacenter:
BGP keepalive        :  3s
BGP hold timer       :  9s
MRAI eBGP            :  0s
MRAI iBGP            :  0s
ebgp-requires-policy : disabled
multipath-relax      : enabled

The 'traditional' profile uses conservative values that predate modern ISP|IXP scale requirements. The 'datacenter' profile uses aggressive timers that are actively harmful for internet-facing routers. A hold timer of 9s will drop all BGP sessions during any reconvergence event that lasts longer than 9s, which is common with 1M+ routes and 100+ peers.

Proposed 'isp' profile

The 'isp' profile builds on the parameters now exposed via T8606 and T8607, consolidating them into a single opinionated profile safe by default for internet routing deployments:

BGP keepalive : 30s    (stable, same as traditional)
BGP hold timer : 90s    (safe under load, same as traditional)
MRAI eBGP : 30s    (prevents UPDATE storms, same as traditional)
MRAI iBGP :  5s    (same as traditional)
ebgp-requires-policy : enabled (RFC 8212, mandatory for internet routers)
multipath-relax : disabled
watchfrr timeout: 120s   (increased from 90s, accommodates full-table reconvergence at IXP scale, T8606)
BGP update-delay : 120s   (enabled, batch reconvergence after restart/boot instead of N parallel bursts, T8607)
BGP establish-wait:  90s   (paired with update-delay)
suppress-fib-pending: enabled (advertise only routes confirmed installed in kernel FIB, prevents blackholing during FIB installation lag at 1M+ route scale)
no bgp fast-convergence (keep sessions up during transient IGP next-hop unreachability, prevents unnecessary session flaps during IGP                                 reconvergence events).
graceful-restart: enabled (RFC 4724, forwarding continues during planned bgpd restarts, complementary to update-delay) log-neighbor-changes : enabled (essential for ISP operations, logs every peer state change with timestamp).
maximum-paths ebgp: 8 (conservative ECMP default operators.
maximum-paths ibgp : 8 can increase up to 128 via CLI).

Proposed VyOS cli

set system frr profile isp

Relationship to existing feature requests

https://vyos.dev/T8606
https://vyos.dev/T8607

Both T8606 and T8607 were originally implemented as individual workarounds for the lack of an ISP-oriented profile in VyOS. The 'isp' profile consolidates these and other ISP-specific default configurations into a single, opinionated config that is "safe-by-default" for large-scale internet routing deployments.

Reference

FRR profile documentation:
https://docs.frrouting.org/en/latest/basic.html#profiles

FRR defaults.h:
https://github.com/FRRouting/frr/blob/master/lib/defaults.h

Details

Version
1.5.0
Is it a breaking change?
Perfectly compatible
Issue type
Feature (new functionality)

Event Timeline

c.faria triaged this task as Normal priority.
c.faria created this object in space S1 VyOS Public.
c.faria created this object with edit policy "All Users".