-
Notifications
You must be signed in to change notification settings - Fork 463
Syntax Reference
Thomas Mangin edited this page Sep 29, 2026
·
1 revision
Every keyword ExaBGP 6.x reads, section by section, printed from the grammar which reads it
This page is what exabgp configuration syntax prints, so it cannot say a keyword exists
which the parser refuses, or miss one it reads. After # is what the keyword is for, its
default and whether it is mandatory. a|b is one of them, [...] is optional, <...> is a
value you give. For examples and explanations see Configuration Syntax
and Directives A-Z.
The same grammar prints a machine-readable model of the configuration:
exabgp configuration syntax --json # JSON Schema (2020-12)
exabgp configuration syntax --yang # YANG 1.1 module
exabgp configuration syntax neighbor family # one sectionprocess <name> { # an external program exabgp runs and talks to over the API
run <program> [<argument> ...]; # the program to run, with its arguments, mandatory
encoder text|json; # how messages to the program are written, default text
respawn true|false; # restart the program when it exits, default true
on-exit withdraw|keep; # what happens to the routes the program announced when it exits, default withdraw
}
neighbor <ip>[/<mask>] { # a BGP peer
peer-address <ip>[/<mask>]; # the peer, or the peers of a range
local-address <ip>|auto; # the address to connect from, auto to find it
local-link-local <ip>; # the IPv6 link-local address (fe80::/10)
local-as <asn>|auto; # our AS, auto to use the peer AS
peer-as <asn>|auto; # the peer AS, auto to use ours
router-id <ipv4>; # the BGP identifier, the local address by default
description <description>; # free text about the neighbor
host-name <host-name>; # sent in the hostname capability
domain-name <domain-name>; # sent in the hostname capability
hold-time 0|<3-65535>; # seconds, 0 disables the hold timer
rate-limit <number>; # UPDATE messages per second
passive true|false; # wait for the peer to connect
listen <1-65535>; # the port to listen on
connect <1-65535>; # the port to connect to
source-interface <source-interface>; # the interface the session is bound to
outgoing-ttl <0-255>|disable; # the TTL of the packets sent, for a multihop session or GTSM
incoming-ttl <0-255>|disable; # the lowest TTL accepted (GTSM)
md5-password <md5-password>; # the TCP MD5 signature key, RFC 2385
md5-base64 true|false; # the md5-password is base64 encoded
md5-ip <ip>; # the local address the TCP MD5 key is set on, the local-address by default
as-set withdraw|accept; # RFC 9774, what to do with a route with an AS_SET
tunnel-encapsulation auto|filter|accept; # RFC 9012 11, a received Tunnel Encapsulation attribute: auto filters it on EBGP only
flow-validation disable|enable|relaxed; # RFC 8955 6, hold back a received flow with no matching unicast route; relaxed accepts one with no destination
enforce-first-as true|false; # RFC 8955 6, withdraw an EBGP route whose AS_PATH does not start with the peer AS
route-target-filter true|false; # RFC 4684 5, send VPN routes only for the Route Targets the peer is a member of
group-updates true|false; # send routes with the same attributes in one UPDATE
auto-flush true|false; # send the routes an API command changes without waiting for a flush
adj-rib-out true|false; # keep the routes sent, to send them again on a route refresh or a new session
adj-rib-in true|false; # keep the routes received
manual-eor true|false; # send the End-of-RIB markers only when the API asks for them
shutdown true|false; # start with the session administratively down
inherit <template>|[ <template> ... ]; # the templates whose statements the neighbor takes
family { # the address families to negotiate
ipv4 unicast|multicast|nlri-mpls|labeled-unicast|mpls-vpn|mcast-vpn|flow|flow-vpn|mup|sr-policy|rtc [prefix-limit <n>]; # an ipv4 family to negotiate, may be repeated
ipv6 unicast|nlri-mpls|labeled-unicast|mpls-vpn|mcast-vpn|mup|sr-policy|flow|flow-vpn [prefix-limit <n>]; # an ipv6 family to negotiate, may be repeated
l2vpn vpls|evpn [prefix-limit <n>]; # an l2vpn family to negotiate, may be repeated
bgp-ls bgp-ls|bgp-ls-vpn [prefix-limit <n>]; # an bgp-ls family to negotiate, may be repeated
all; # every family exabgp knows, may be repeated
}
capability { # the capabilities to negotiate
nexthop enable|disable|require; # Extended Next Hop Encoding, RFC 8950
add-path disable|receive|send|send/receive; # ADD-PATH, RFC 7911: receive, send or both
asn4 enable|disable|require; # four-octet AS numbers, RFC 6793
graceful-restart <0-4095>|disable; # Graceful Restart, RFC 4724: the restart time in seconds, 0 for the hold time
multi-session true|false; # Multisession, draft-ietf-idr-bgp-multisession: a session per family
operational enable|disable|require; # Operational messages, draft-ietf-idr-operational-message
route-refresh enable|disable|require; # Route Refresh, RFC 2918, and Enhanced Route Refresh, RFC 7313, both
route-refresh-normal enable|disable|require; # Route Refresh, RFC 2918, alone: what route-refresh says of it, overridden
route-refresh-enhanced enable|disable|require; # Enhanced Route Refresh, RFC 7313, alone: what route-refresh says of it, overridden
aigp true|false; # accept and send the AIGP attribute, RFC 7311
extended-message enable|disable|require; # Extended Messages, RFC 8654: messages up to 65535 octets
software-version enable|disable|require; # Software Version, draft-ietf-idr-software-version
link-local-nexthop enable|disable|require; # Link-Local Next Hop, draft-ietf-idr-linklocal-capability
multiple-labels <2-255>|disable; # Multiple Labels, RFC 8277: how many labels on one prefix we take, per labelled family
link-local-prefer true|false; # use the link-local IPv6 next-hop when a route has both
}
tcp-ao { # TCP-AO (RFC 5925) authentication
keyid <0-255>; # the key identifier
algorithm hmac-sha-1-96|aes-128-cmac-96|hmac-sha-256; # the MAC algorithm, RFC 5926
password <password>; # the master key
base64 true|false; # the password is base64 encoded
}
role { # the RFC 9234 role of this router on the session
local provider|rs|rs-client|customer|peer; # our role on the session
strict enable|disable; # refuse a peer which does not send its role
add-meta enable|disable; # give the roles to the API programs with the routes
otc;
}
confederation { # RFC 5065 BGP confederation
identifier <asn>; # the AS Confederation Identifier, the AS the world outside sees
members <asn>|[ <asn> ... ]; # the Member-AS numbers of the confederation, but our own
}
add-path { # the families ADD-PATH is negotiated for, with an optional PATHS-LIMIT
ipv4 unicast|multicast|nlri-mpls|labeled-unicast|mpls-vpn|mcast-vpn|flow|flow-vpn|mup|sr-policy|rtc [limit <n>]; # an ipv4 family to negotiate ADD-PATH for, may be repeated
ipv6 unicast|nlri-mpls|labeled-unicast|mpls-vpn|mcast-vpn|mup|sr-policy|flow|flow-vpn [limit <n>]; # an ipv6 family to negotiate ADD-PATH for, may be repeated
l2vpn vpls|evpn [limit <n>]; # an l2vpn family to negotiate ADD-PATH for, may be repeated
bgp-ls bgp-ls|bgp-ls-vpn [limit <n>]; # an bgp-ls family to negotiate ADD-PATH for, may be repeated
all; # no family, ADD-PATH is negotiated for none, may be repeated
}
nexthop { # the families whose next-hop may be of the other address family (RFC 8950)
ipv4 unicast|multicast|nlri-mpls|labeled-unicast|mpls-vpn ipv6; # an ipv4 family whose next-hop may be of the other address family, may be repeated
ipv6 unicast|multicast|nlri-mpls|labeled-unicast|mpls-vpn ipv4; # an ipv6 family whose next-hop may be of the other address family, may be repeated
}
api [<name>] { # which API programs hear about this neighbor, and what they hear
processes [ <process> ... ]; # the programs, by name, which hear about the neighbor
processes-match [ <regex> ... ]; # the programs whose name matches one of these regular expressions
neighbor-changes true|false; # tell the programs when the session goes up or down
negotiated true|false; # tell the programs what the OPEN messages negotiated
fsm true|false; # tell the programs each change of the state machine
signal true|false; # tell the programs about the signals exabgp receives
send { # the messages sent which are given to the program
parsed true|false; # the messages decoded
packets true|false; # the messages as their bytes
consolidate true|false; # the decoded and raw forms of a message together
open true|false; # the OPEN messages
update true|false; # the UPDATE messages
notification true|false; # the NOTIFICATION messages
keepalive true|false; # the KEEPALIVE messages
refresh true|false; # the ROUTE-REFRESH messages
operational true|false; # the OPERATIONAL messages
}
receive { # the messages received which are given to the program
parsed true|false; # the messages decoded
packets true|false; # the messages as their bytes
consolidate true|false; # the decoded and raw forms of a message together
open true|false; # the OPEN messages
update true|false; # the UPDATE messages
notification true|false; # the NOTIFICATION messages
keepalive true|false; # the KEEPALIVE messages
refresh true|false; # the ROUTE-REFRESH messages
operational true|false; # the OPERATIONAL messages
}
}
static { # routes to announce
route <prefix> next-hop <ip>|self [<attribute> <value> ...]; # a route, on one line, may be repeated
attributes <attribute> <value> ... nlri <prefix> ...; # the same attributes for several prefixes, may be repeated
attribute <attribute> <value> ... nlri <prefix> ...; # the same attributes for several prefixes, as attributes, may be repeated
route <prefix> { # a route, its values one per statement
next-hop <ip>|self; # the next-hop, or self for the local address, may be repeated
path-information <number>|<ipv4>; # the ADD-PATH path identifier, may be repeated
rd <asn>:<n>|<ipv4>:<n>; # the route distinguisher, making it a VPN route, may be repeated
route-distinguisher <asn>:<n>|<ipv4>:<n>; # may be repeated
label <label>|[ <label> ... ]; # the MPLS label stack, may be repeated
bgp-prefix-sid [ <label-index> ] | [ <label-index>, [ ( <base>,<range> ) ... ] ]; # may be repeated
bgp-prefix-sid-srv6 ( l3-service|l2-service <ipv6> [<behavior> [ [ <LBL>, <LNL>, <FL>, <AL>, <len>, <offset> ] ]] ); # may be repeated
attribute [ 0x<code> 0x<flag> 0x<data> ]; # any attribute, as its wire bytes, may be repeated
origin igp|egp|incomplete; # may be repeated
otc <asn>|self|<role>; # RFC 9234 Only-to-Customer, may be repeated
med <0-4294967295>; # may be repeated
as-path <asn>|[ <asn> ... ] ( <asn> ... ) confed-sequence [ ... ] confed-set [ ... ]; # may be repeated
local-preference <0-4294967295>; # may be repeated
atomic-aggregate; # may be repeated
aggregator ( <asn>:<router-id> ); # may be repeated
originator-id <ipv4>; # may be repeated
cluster-list <ipv4>|[ <ipv4> ... ]; # may be repeated
community <asn>:<value>|[ <asn>:<value> ... ]; # may be repeated
large-community <asn>:<value>:<value>|[ <asn>:<value>:<value> ... ]; # may be repeated
extended-community <type>:<value>|[ <type>:<value> ... ]; # may be repeated
aigp <number>|0x<hex>; # may be repeated
name <name>; # a name for the route, kept by exabgp, may be repeated
split /<length>; # announce the prefix as its more specifics of this length, may be repeated
watchdog <name>; # the watchdog which announces and withdraws the route, may be repeated
withdraw; # start with the route withdrawn, may be repeated
}
rtc ...; # a route target membership route, RFC 4684, may be repeated
sr-policy distinguisher <n> color <n> endpoint <ip> next-hop <ip> [<sub-tlv> ...]; # an SR policy route, may be repeated
}
announce { # routes by address family
ipv4 { # the ipv4 routes, by subsequent address family
unicast <prefix> next-hop <ip>|self [<attribute> <value> ...]; # a ipv4 unicast route, may be repeated
multicast <prefix> next-hop <ip>|self [<attribute> <value> ...]; # a ipv4 multicast route, may be repeated
nlri-mpls <prefix> next-hop <ip>|self [<attribute> <value> ...]; # a ipv4 nlri-mpls route, may be repeated
mpls-vpn <prefix> next-hop <ip>|self [<attribute> <value> ...]; # a ipv4 mpls-vpn route, may be repeated
rtc ...; # a ipv4 rtc route, may be repeated
flow <match> <value> ... <action> <value> ...; # a ipv4 flow rule, RFC 8955, may be repeated
flow-vpn <match> <value> ... <action> <value> ...; # a ipv4 flow-vpn rule, RFC 8955, may be repeated
mup mup-isd|mup-dsd|mup-t1st|mup-t2st ...; # a Mobile User Plane route, draft-mpmz-bess-mup-safi, may be repeated
mcast-vpn source-ad|source-join|shared-join ...; # a multicast VPN route, RFC 6514, may be repeated
sr-policy distinguisher <n> color <n> endpoint <ip> next-hop <ip> [<sub-tlv> ...]; # an SR policy route, RFC 9830, may be repeated
labeled-unicast;
}
ipv6 { # the ipv6 routes, by subsequent address family
unicast <prefix> next-hop <ip>|self [<attribute> <value> ...]; # a ipv6 unicast route, may be repeated
multicast <prefix> next-hop <ip>|self [<attribute> <value> ...]; # a ipv6 multicast route, may be repeated
nlri-mpls <prefix> next-hop <ip>|self [<attribute> <value> ...]; # a ipv6 nlri-mpls route, may be repeated
mpls-vpn <prefix> next-hop <ip>|self [<attribute> <value> ...]; # a ipv6 mpls-vpn route, may be repeated
flow <match> <value> ... <action> <value> ...; # a ipv6 flow rule, RFC 8955, may be repeated
flow-vpn <match> <value> ... <action> <value> ...; # a ipv6 flow-vpn rule, RFC 8955, may be repeated
mup mup-isd|mup-dsd|mup-t1st|mup-t2st ...; # a Mobile User Plane route, draft-mpmz-bess-mup-safi, may be repeated
mcast-vpn source-ad|source-join|shared-join ...; # a multicast VPN route, RFC 6514, may be repeated
sr-policy distinguisher <n> color <n> endpoint <ip> next-hop <ip> [<sub-tlv> ...]; # an SR policy route, RFC 9830, may be repeated
labeled-unicast;
}
l2vpn { # the l2vpn routes
vpls endpoint <n> base <n> offset <n> size <n> rd <rd> next-hop <ip> [...]; # a VPLS route, RFC 4761, may be repeated
}
}
flow { # FlowSpec routes (RFC 8955, RFC 8956)
route <match> <value> ... <action> <value> ...; # may be repeated
route [<name>] { # a flow route, what it matches and what it does
match { # what the route matches
source <ip>/<mask>[/<offset>]; # the source prefix, RFC 8955 type 2, may be repeated
source-ipv4 <ip>/<mask>[/<offset>]; # the source prefix, as source, may be repeated
source-ipv6 <ip>/<mask>[/<offset>]; # the source prefix, as source, may be repeated
destination <ip>/<mask>[/<offset>]; # the destination prefix, RFC 8955 type 1, may be repeated
destination-ipv4 <ip>/<mask>[/<offset>]; # the destination prefix, as destination, may be repeated
destination-ipv6 <ip>/<mask>[/<offset>]; # the destination prefix, as destination, may be repeated
protocol <op><value>[&...] | [ ... ]; # the IP protocol, RFC 8955 type 3, may be repeated
next-header <op><value>[&...] | [ ... ]; # the IPv6 next header, RFC 8956 type 3, may be repeated
port <op><value>[&...] | [ ... ]; # the source or destination port, RFC 8955 type 4, may be repeated
destination-port <op><value>[&...] | [ ... ]; # the destination port, RFC 8955 type 5, may be repeated
source-port <op><value>[&...] | [ ... ]; # the source port, RFC 8955 type 6, may be repeated
icmp-type <op><value>[&...] | [ ... ]; # the ICMP type, RFC 8955 type 7, may be repeated
icmp-code <op><value>[&...] | [ ... ]; # the ICMP code, RFC 8955 type 8, may be repeated
tcp-flags <op><value>[&...] | [ ... ]; # the TCP flags, RFC 8955 type 9, may be repeated
packet-length <op><value>[&...] | [ ... ]; # the packet length, RFC 8955 type 10, may be repeated
dscp <op><value>[&...] | [ ... ]; # the DSCP, RFC 8955 type 11, may be repeated
traffic-class <op><value>[&...] | [ ... ]; # the IPv6 traffic class, RFC 8956 type 11, may be repeated
fragment <op><value>[&...] | [ ... ]; # the fragment flags, RFC 8955 type 12, may be repeated
flow-label <op><value>[&...] | [ ... ]; # the IPv6 flow label, RFC 8956 type 13, may be repeated
}
then { # what is done with what matches
accept; # no action: the traffic is accepted, may be repeated
discard; # drop the traffic, a traffic-rate of 0, may be repeated
rate-limit <number> [bytes|packets]; # traffic-rate, RFC 8955 7.3: bytes or packets per second, may be repeated
redirect <asn>:<nn>|<ip>|[<ipv6>]:<nn>; # redirect to the VRF of a route target, or to an address, may be repeated
redirect-to-nexthop [<ip>]; # redirect to the next-hop of the route, or to the address given, may be repeated
redirect-to-nexthop-ietf <ip>; # redirect to an address, the IETF community, may be repeated
redirect-to-nexthop-simpson; # redirect to the next-hop of the UPDATE, the older form, may be repeated
copy <ip>; # copy the traffic to an address, the IETF community, may be repeated
copy-simpson <ip>; # copy the traffic to an address, the older form, may be repeated
redirect-simpson <ip>; # redirect to an address, the older form, may be repeated
mark <0-63>; # traffic-marking, RFC 8955 7.5: the DSCP to set, may be repeated
action sample|terminal|sample-terminal; # traffic-action, RFC 8955 7.6: sample the traffic, stop at this rule, or both, may be repeated
community <asn>:<value>|[ <asn>:<value> ... ]; # may be repeated
large-community <asn>:<value>:<value>|[ <asn>:<value>:<value> ... ]; # may be repeated
extended-community <type>:<value>|[ <type>:<value> ... ]; # may be repeated
}
scope { # where the route applies
interface-set <transitive>:<direction>:<asn>:<group>; # the interfaces the rule applies to, draft-ietf-idr-flowspec-interfaceset, may be repeated
}
rd <asn>:<n>|<ipv4>:<n>; # may be repeated
route-distinguisher <asn>:<n>|<ipv4>:<n>; # may be repeated
path-information <number>|<ipv4>; # may be repeated
next-hop <ip>|self; # the next-hop of the flow route, or self, may be repeated
}
}
l2vpn { # VPLS routes
vpls endpoint <n> base <n> offset <n> size <n> rd <rd> next-hop <ip> [...]; # a VPLS route, on one line, may be repeated
vpls [<name>] { # a VPLS route, its values one per statement
next-hop <ip>|self; # the next-hop, or self for the IPv4 local address, may be repeated
rd <asn>:<n>|<ipv4>:<n>; # may be repeated
endpoint <0-65535>; # the VE ID of the site, may be repeated
offset <0-65535>; # the VE block offset, may be repeated
size <0-65535>; # the VE block size, may be repeated
base <0-65535>; # the label base, may be repeated
attribute [ 0x<code> 0x<flag> 0x<data> ]; # may be repeated
origin igp|egp|incomplete; # may be repeated
med <0-4294967295>; # may be repeated
as-path <asn>|[ <asn> ... ] ( <asn> ... ) confed-sequence [ ... ] confed-set [ ... ]; # may be repeated
local-preference <0-4294967295>; # may be repeated
atomic-aggregate; # may be repeated
aggregator ( <asn>:<router-id> ); # may be repeated
originator-id <ipv4>; # may be repeated
cluster-list <ipv4>|[ <ipv4> ... ]; # may be repeated
community <asn>:<value>|[ <asn>:<value> ... ]; # may be repeated
extended-community <type>:<value>|[ <type>:<value> ... ]; # may be repeated
name <name>; # may be repeated
split /<length>; # may be repeated
watchdog <name>; # may be repeated
withdraw; # may be repeated
}
next-hop;
rd;
endpoint;
offset;
size;
base;
attribute [ 0x<code> 0x<flag> 0x<data> ]; # may be repeated
origin igp|egp|incomplete; # may be repeated
med <0-4294967295>; # may be repeated
as-path <asn>|[ <asn> ... ] ( <asn> ... ) confed-sequence [ ... ] confed-set [ ... ]; # may be repeated
local-preference <0-4294967295>; # may be repeated
atomic-aggregate; # may be repeated
aggregator ( <asn>:<router-id> ); # may be repeated
originator-id <ipv4>; # may be repeated
cluster-list <ipv4>|[ <ipv4> ... ]; # may be repeated
community <asn>:<value>|[ <asn>:<value> ... ]; # may be repeated
extended-community <type>:<value>|[ <type>:<value> ... ]; # may be repeated
name <name>; # may be repeated
split /<length>; # may be repeated
watchdog <name>; # may be repeated
withdraw; # may be repeated
}
operational { # the operational messages sent to the peer
asm afi <afi> safi <safi> advisory <advisory>; # Advisory State Message, may be repeated
adm afi <afi> safi <safi> advisory <advisory>; # Advisory Dump Message, may be repeated
rpcq afi <afi> safi <safi> sequence <sequence>; # Reachable Prefix Count Query, may be repeated
rpcp afi <afi> safi <safi> sequence <sequence> counter <counter>; # Reachable Prefix Count Reply, may be repeated
apcq afi <afi> safi <safi> sequence <sequence>; # Adj-RIB-Out Prefix Count Query, may be repeated
apcp afi <afi> safi <safi> sequence <sequence> counter <counter>; # Adj-RIB-Out Prefix Count Reply, may be repeated
lpcq afi <afi> safi <safi> sequence <sequence>; # Local Prefix Count Query, may be repeated
lpcp afi <afi> safi <safi> sequence <sequence> counter <counter>; # Local Prefix Count Reply, may be repeated
}
}
template { # statements shared by neighbors
neighbor <name> { # a template, the statements of a neighbor which inherits i ... } # as neighbor
}
Getting Started
Configuration
- Configuration Syntax
- Neighbor Configuration
- Directives A-Z
- Syntax Reference
- Templates
- Environment Variables
- Process Configuration
API
- API Overview
- Text API Reference
- JSON API Reference
- API Commands
- Writing API Programs
- Error Handling
- Production Best Practices
Address Families
- Overview
- IPv4 Unicast
- IPv6 Unicast
- FlowSpec
- EVPN
- L3VPN
- BGP-LS
- VPLS
- SRv6 / MUP
- Multicast
- RT Constraint
Features
Use Cases
Tools
Operations
Reference
- Architecture
- Design
- Attribute Reference
- Command Reference
- BGP State Machine
- Capabilities
- Communities
- Examples Index
- Glossary
- RFC Support
Integration
Migration
Community
External