Page MenuHomeVyOS Platform

bgp: bmp: Add update-source / source-interface support for BMP targets
Closed, ResolvedPublicFEATURE REQUEST

Description

Here's the filled-in form:


Summary
Add update-source node under protocols bgp bmp target <name> to allow pinning the source interface for outbound BMP connections.


Use case
When a router has multiple interfaces or a dedicated management/peering address, BMP outbound connections to a collector may egress from the wrong source IP. FRR's bmpd already supports a source-interface argument on the bmp connect statement, but it is not exposed through the VyOS CLI. This is particularly relevant when the BMP collector enforces source IP filtering (e.g. firewall ACLs or BMP session authentication by peer address).

Without this node, the only workaround is to apply the option directly in vtysh, which is not persisted in the VyOS config tree and is lost on reboot or after any commit.


Additional information
FRR 10.x syntax:

bmp connect <host> port <port> [min-retry <ms>] [max-retry <ms>] [source-interface <ifname>]

Proposed VyOS CLI node:

set protocols bgp bmp target <name> update-source <interface>

The fix would be a small addition to the BGP Jinja2 template to conditionally emit source-interface when the node is present. Related task: T4163 (original BMP implementation).

Details

Version
VyOS 2026.05.04-0041-rolling
Is it a breaking change?
Perfectly compatible
Issue type
Feature (new functionality)

Event Timeline

Lucas created this object in space S1 VyOS Public.

Ran into this on a rolling build (FRR 10.5.2). Without any source binding, the session stays stuck in Connecting with (unspec) as local address:

lsn-prc-br-v01# show bmp
BMP state for BGP VRF default:
  Route Mirroring         0 bytes (0 messages) pending
                          0 bytes maximum buffer used
  Targets "bgproutes":
    Route Mirroring disabled
    Route Monitoring IPv4 unicast pre-policy
    Route Monitoring IPv6 unicast pre-policy
    Listeners:
    Outbound connections:
 remote               state           timer   local
 --------------------------------------------------------
 88.99.xx.xx:45678   Connecting              (unspec)
    0 connected clients:
 remote   uptime   MonSent   MirrSent   MirrLost   ByteSent   ByteQ   ByteQKernel

The CLI node to fix this is missing:

lucas@lsn-prc-br-v01# set protocols bgp bmp target bgproutes update-source 185.20.xx.xx
  Configuration path: protocols bgp bmp target bgproutes [update-source] is not valid
  Set failed

Workaround was to apply the option directly in vtysh:

lsn-prc-br-v01# configure terminal
lsn-prc-br-v01(config)# router bgp <ASN>
lsn-prc-br-v01(config-router)# bmp targets bgproutes
lsn-prc-br-v01(config-bgp-bmp)# bmp connect 88.99.xx.xx port 45678 min-retry 100 max-retry 10000 source-interface eth0

After applying this, the session came up correctly:

lsn-prc-br-v01# show bmp
BMP state for BGP VRF default:
  Route Mirroring         0 bytes (0 messages) pending
                          0 bytes maximum buffer used
  Targets "bgproutes":
    Route Mirroring disabled
    Route Monitoring IPv4 unicast pre-policy
    Route Monitoring IPv6 unicast pre-policy
    Listeners:
    Outbound connections:
 remote               state                        timer      local
 ----------------------------------------------------------------------------
 88.99.211.56:45678   Up      88.99.xx.xx:45678   00:01:47   185.20.3.254
    1 connected clients:
 remote               uptime     MonSent   MirrSent   MirrLost   ByteSent    ByteQ   ByteQKernel
 --------------------------------------------------------------------------------------------------
 88.99.xx.xx:45678   00:01:47   2671295   0          0          410032256   0       0

The local column confirms the correct source address (185.20.xx.xx) once set via vtysh. This config is not persisted across reboots or commits.

natali-rs1985 changed the task status from Open to In progress.Jun 23 2026, 2:16 PM
natali-rs1985 claimed this task.
natali-rs1985 changed Is it a breaking change? from Unspecified (possibly destroys the router) to Perfectly compatible.

FRR has a bug where no bmp connect HOSTNAME port PORT min-retry MSEC max-retry MSEC source-interface WORD always fails with "No such active connection found" even when the parameters match the active connection. Deletion only works when source-interface is omitted from the command.

Upstream FRR PR: https://github.com/FRRouting/frr/pull/22469
vyos-build patch: https://github.com/vyos/vyos-build/pull/1225

Viacheslav moved this task from Need Triage to Completed on the VyOS Rolling board.

Smoketests are failing:

DEBUG - ======================================================================
DEBUG - FAIL: test_bgp_99_bmp (__main__.TestProtocolsBGP.test_bgp_99_bmp)
DEBUG - ----------------------------------------------------------------------
DEBUG - Traceback (most recent call last):
DEBUG -   File "/usr/libexec/vyos/tests/smoke/cli/test_protocols_bgp.py", line 2030, in test_bgp_99_bmp
DEBUG -     self.assertNotIn('source-interface', frrconfig)
DEBUG - AssertionError: 'source-interface' unexpectedly found in 'router bgp 64512\n no bgp ebgp-requires-policy\n no bgp reject-as-sets\n no bgp default ipv4-unicast\n no bgp network import-check\n !\n bmp mirror buffer-limit 32000000\n !\n bmp targets instance-bmp\n  bmp mirror\n  bmp monitor ipv4 unicast pre-policy\n  bmp monitor ipv4 unicast loc-rib\n  bmp monitor ipv6 unicast pre-policy\n  bmp monitor ipv6 unicast loc-rib\n  bmp connect 127.0.0.1 port 5000 min-retry 1024 max-retry 2048 source-interface eth0\n exit\nexit'

Seems that the deletion of source-interface in the test (https://github.com/vyos/vyos-1x/blob/rolling/smoketest/scripts/cli/test_protocols_bgp.py#L2021-L2030) isn't taking effect.

@natali-rs1985 You're right, looks like it's not being included in the package build! I'll investigate further, thanks!