Add FRR 'isp' configuration profile optimized for full-table internet routing at IXP and ISP scale (set system frr profile isp).
FRR currently provides two configuration profiles selectable in VyOS via:
https://docs.frrouting.org/en/latest/basic.html#profiles
• traditional - reflects defaults adhering mostly to IETF standards or common practices in wide-area internet routing.
• datacenter - reflects a single administrative domain with intradomain links using aggressive timers.
This Feature Request suggests a profile more suitable for ISP and IXP deployments running full-table BGP at large scale, with 100+ peers and full routes IPv4 and IPv6 peerings.
traditional: BGP keepalive : 30s BGP hold timer : 90s MRAI eBGP : 30s MRAI iBGP : 5s ebgp-requires-policy : enabled (RFC 8212) multipath-relax : disabled watchfrr timeout : 90s BGP update-delay : disabled datacenter: BGP keepalive : 3s BGP hold timer : 9s MRAI eBGP : 0s MRAI iBGP : 0s ebgp-requires-policy : disabled multipath-relax : enabled
The 'traditional' profile uses conservative values that predate modern ISP|IXP scale requirements. The 'datacenter' profile uses aggressive timers that are actively harmful for internet-facing routers. A hold timer of 9s will drop all BGP sessions during any reconvergence event that lasts longer than 9s, which is common with 1M+ routes and 100+ peers.
Proposed 'isp' profile
The 'isp' profile builds on the parameters now exposed via T8606 and T8607, consolidating them into a single opinionated profile safe by default for internet routing deployments:
BGP keepalive : 30s (stable, same as traditional) BGP hold timer : 90s (safe under load, same as traditional) MRAI eBGP : 30s (prevents UPDATE storms, same as traditional) MRAI iBGP : 5s (same as traditional) ebgp-requires-policy : enabled (RFC 8212, mandatory for internet routers) multipath-relax : disabled watchfrr timeout: 120s (increased from 90s, accommodates full-table reconvergence at IXP scale, T8606) BGP update-delay : 120s (enabled, batch reconvergence after restart/boot instead of N parallel bursts, T8607) BGP establish-wait: 90s (paired with update-delay) suppress-fib-pending: enabled (advertise only routes confirmed installed in kernel FIB, prevents blackholing during FIB installation lag at 1M+ route scale) no bgp fast-convergence (keep sessions up during transient IGP next-hop unreachability, prevents unnecessary session flaps during IGP reconvergence events). graceful-restart: enabled (RFC 4724, forwarding continues during planned bgpd restarts, complementary to update-delay) log-neighbor-changes : enabled (essential for ISP operations, logs every peer state change with timestamp). maximum-paths ebgp: 8 (conservative ECMP default operators. maximum-paths ibgp : 8 can increase up to 128 via CLI).
Proposed VyOS cli
set system frr profile isp
Relationship to existing feature requests
https://vyos.dev/T8606
https://vyos.dev/T8607
Both T8606 and T8607 were originally implemented as individual workarounds for the lack of an ISP-oriented profile in VyOS. The 'isp' profile consolidates these and other ISP-specific default configurations into a single, opinionated config that is "safe-by-default" for large-scale internet routing deployments.
Reference
FRR profile documentation:
https://docs.frrouting.org/en/latest/basic.html#profiles
FRR defaults.h:
https://github.com/FRRouting/frr/blob/master/lib/defaults.h