Skip to content

Syntax Reference

Thomas Mangin edited this page Oct 9, 2026 · 6 revisions

Configuration Syntax Reference

Every keyword ExaBGP 6.x reads, section by section, printed from the grammar which reads it

This page is what exabgp configuration syntax prints, so it cannot say a keyword exists which the parser refuses, or miss one it reads. After # is what the keyword is for, its default and whether it is mandatory. a|b is one of them, [...] is optional, <...> is a value you give. The ; ending each statement may be left out at the end of a line (6.0): the line end ends the statement, and a ; still separates two statements written on one line. For examples and explanations see Configuration Syntax and Directives A-Z.

The same grammar prints one section, the help of one statement, and a machine-readable model of the configuration:

exabgp configuration syntax neighbor family       # one section
exabgp configuration syntax neighbor hold-time    # one statement: its syntax, default, examples
exabgp configuration syntax --json                # JSON Schema (2020-12)
exabgp configuration syntax --yang                # YANG 1.1 module

process

process <name> {  # an external program exabgp runs and talks to over the API
    run <program> [<argument> ...];  # the program to run, with its arguments, mandatory
    encoder text|json;  # how messages to the program are written, default text
    respawn true|false;  # restart the program when it exits, default true
    on-exit withdraw|keep;  # what happens to the routes the program announced when it exits; unset, they are kept for a program using API 4 and withdrawn otherwise
}

neighbor

neighbor <ip>[/<mask>] {  # a BGP peer
    peer-address <ip>[/<mask>];  # the peer, or the peers of a range
    local-address <ip>|auto;  # the address to connect from, auto to find it
    local-link-local <ip>;  # the IPv6 link-local address (fe80::/10)
    local-as <asn>|auto;  # our AS, auto to use the peer AS
    peer-as <asn>|auto;  # the peer AS, auto to use ours
    router-id <ipv4>;  # the BGP identifier, the local address by default
    description <description>;  # free text about the neighbor
    host-name <host-name>;  # sent in the hostname capability
    domain-name <domain-name>;  # sent in the hostname capability
    hold-time 0|<3-65535>;  # seconds, 0 disables the hold timer
    rate-limit <number>|disable;  # UPDATE messages per second, 0 or disable for no limit
    passive true|false;  # wait for the peer to connect
    listen <1-65535>;  # the port to listen on
    connect <1-65535>;  # the port to connect to
    source-interface <source-interface>;  # the interface the session is bound to
    outgoing-ttl <0-255>|disable;  # the TTL of the packets sent, for a multihop session or GTSM
    incoming-ttl <0-255>|disable;  # the lowest TTL accepted (GTSM)
    md5-password <md5-password>;  # the TCP MD5 signature key, RFC 2385
    md5-base64 true|false;  # the md5-password is base64 encoded
    md5-ip <ip>;  # the local address the TCP MD5 key is set on, the local-address by default
    as-set withdraw|accept;  # RFC 9774, what to do with a route with an AS_SET
    tunnel-encapsulation auto|filter|accept;  # RFC 9012 11, a received Tunnel Encapsulation attribute: auto filters it on EBGP only
    flow-validation disable|enable|relaxed;  # RFC 8955 6, hold back a received flow with no matching unicast route; relaxed accepts one with no destination
    enforce-first-as true|false;  # RFC 8955 6, withdraw an EBGP route whose AS_PATH does not start with the peer AS
    route-target-filter true|false;  # RFC 4684 5, send VPN routes only for the Route Targets the peer is a member of
    group-updates true|false;  # send routes with the same attributes in one UPDATE
    auto-flush true|false;  # send the routes an API command changes without waiting for a flush
    adj-rib-out true|false;  # keep the routes sent, to send them again on a route refresh or a new session
    adj-rib-in true|false;  # keep the routes received
    manual-eor true|false;  # send the End-of-RIB markers only when the API asks for them
    shutdown true|false;  # start with the session administratively down
    inherit <template>|[ <template> ... ];  # the templates giving the neighbor its defaults: what the neighbor says itself wins, may be repeated
    family {  # the address families to negotiate
        ipv4 unicast|multicast|nlri-mpls|labeled-unicast|mpls-vpn|mcast-vpn|flow|flow-vpn|mup|sr-policy|rtc [prefix-limit <n>];  # an ipv4 family to negotiate, may be repeated
        ipv6 unicast|multicast|nlri-mpls|labeled-unicast|mpls-vpn|mcast-vpn|mup|sr-policy|flow|flow-vpn [prefix-limit <n>];  # an ipv6 family to negotiate, may be repeated
        l2vpn vpls|evpn [prefix-limit <n>];  # an l2vpn family to negotiate, may be repeated
        bgp-ls bgp-ls|bgp-ls-vpn [prefix-limit <n>];  # an bgp-ls family to negotiate, may be repeated
        all;  # every family exabgp knows
    }
    capability {  # the capabilities to negotiate
        nexthop enable|disable|require;  # Extended Next Hop Encoding, RFC 8950
        add-path disable|receive|send|send/receive;  # ADD-PATH, RFC 7911: receive, send or both
        asn4 enable|disable|require;  # four-octet AS numbers, RFC 6793
        graceful-restart <0-4095>|disable;  # Graceful Restart, RFC 4724: the restart time in seconds, 0 for the hold time
        multi-session true|false;  # Multisession, draft-ietf-idr-bgp-multisession: a session per family
        operational enable|disable|require;  # Operational messages, draft-ietf-idr-operational-message
        route-refresh enable|disable|require;  # Route Refresh, RFC 2918, and Enhanced Route Refresh, RFC 7313, both
        route-refresh-normal enable|disable|require;  # Route Refresh, RFC 2918, alone: what route-refresh says of it, overridden
        route-refresh-enhanced enable|disable|require;  # Enhanced Route Refresh, RFC 7313, alone: what route-refresh says of it, overridden
        aigp true|false;  # accept and send the AIGP attribute, RFC 7311; unset: on for iBGP and confederation members
        extended-message enable|disable|require;  # Extended Messages, RFC 8654: messages up to 65535 octets
        software-version enable|disable|require;  # Software Version, draft-ietf-idr-software-version
        link-local-nexthop enable|disable|require;  # Link-Local Next Hop, draft-ietf-idr-linklocal-capability
        multiple-labels <2-255>|disable;  # Multiple Labels, RFC 8277: how many labels on one prefix we take, per labelled family
        link-local-prefer true|false;  # use the link-local IPv6 next-hop when a route has both
    }
    tcp-ao {  # TCP-AO (RFC 5925) authentication
        keyid <0-255>;  # the key identifier
        algorithm hmac-sha-1-96|aes-128-cmac-96|hmac-sha-256;  # the MAC algorithm, RFC 5926
        password <password>;  # the master key
        base64 true|false;  # the password is base64 encoded
    }
    role {  # the RFC 9234 role of this router on the session
        local provider|rs|rs-client|customer|peer;  # our role on the session
        strict enable|disable;  # refuse a peer which does not send its role
        add-meta enable|disable;  # give the roles to the API programs with the routes
    }
    confederation {  # RFC 5065 BGP confederation
        identifier <asn>;  # the AS Confederation Identifier, the AS the world outside sees
        members <asn>|[ <asn> ... ];  # the Member-AS numbers of the confederation, but our own
    }
    add-path {  # the families ADD-PATH is negotiated for, with an optional PATHS-LIMIT
        ipv4 unicast|multicast|nlri-mpls|labeled-unicast|mpls-vpn|mcast-vpn|flow|flow-vpn|mup|sr-policy|rtc [limit <n>];  # an ipv4 family to negotiate ADD-PATH for, may be repeated
        ipv6 unicast|multicast|nlri-mpls|labeled-unicast|mpls-vpn|mcast-vpn|mup|sr-policy|flow|flow-vpn [limit <n>];  # an ipv6 family to negotiate ADD-PATH for, may be repeated
        l2vpn vpls|evpn [limit <n>];  # an l2vpn family to negotiate ADD-PATH for, may be repeated
        bgp-ls bgp-ls|bgp-ls-vpn [limit <n>];  # an bgp-ls family to negotiate ADD-PATH for, may be repeated
        all;  # every family the neighbor negotiates
    }
    nexthop {  # the families whose next-hop may be of the other address family (RFC 8950)
        ipv4 unicast|multicast|nlri-mpls|labeled-unicast|mpls-vpn ipv6;  # an ipv4 family whose next-hop may be of the other address family, may be repeated
        ipv6 unicast|multicast|nlri-mpls|labeled-unicast|mpls-vpn ipv4;  # an ipv6 family whose next-hop may be of the other address family, may be repeated
    }
    api [<name>] {  # which API programs hear about this neighbor, and what they hear
        processes [ <process> ... ];  # the programs, by name, which hear about the neighbor
        processes-match [ <regex> ... ];  # the programs whose name matches one of these regular expressions
        neighbor-changes true|false;  # tell the programs when the session goes up or down
        negotiated true|false;  # tell the programs what the OPEN messages negotiated
        fsm true|false;  # tell the programs each change of the state machine
        signal true|false;  # tell the programs about the signals exabgp receives
        send {  # the messages sent which are given to the program
            parsed true|false;  # the messages decoded
            packets true|false;  # the messages as their bytes
            consolidate true|false;  # the decoded and raw forms of a message together
            open true|false;  # the OPEN messages
            update true|false;  # the UPDATE messages
            notification true|false;  # the NOTIFICATION messages
            keepalive true|false;  # the KEEPALIVE messages
            refresh true|false;  # the ROUTE-REFRESH messages
            operational true|false;  # the OPERATIONAL messages
        }
        receive {  # the messages received which are given to the program
            parsed true|false;  # the messages decoded
            packets true|false;  # the messages as their bytes
            consolidate true|false;  # the decoded and raw forms of a message together
            open true|false;  # the OPEN messages
            update true|false;  # the UPDATE messages
            notification true|false;  # the NOTIFICATION messages
            keepalive true|false;  # the KEEPALIVE messages
            refresh true|false;  # the ROUTE-REFRESH messages
            operational true|false;  # the OPERATIONAL messages
        }
    }
    static {  # routes to announce
        route <prefix> next-hop <ip>|self [<attribute> <value> ...];  # a route, on one line, may be repeated
        attributes <attribute> <value> ... nlri <prefix> ...;  # the same attributes for several prefixes, may be repeated
        attribute <attribute> <value> ... nlri <prefix> ...;  # the same attributes for several prefixes, as attributes, may be repeated
        route <prefix> {  # a route, its values one per statement
            next-hop <ip>|self;  # the next-hop, or self for the local address
            path-information <number>|<ipv4>;  # the ADD-PATH path identifier
            rd <asn>:<n>|<ipv4>:<n>;  # the route distinguisher, making it a VPN route
            route-distinguisher <asn>:<n>|<ipv4>:<n>;
            label <label>|[ <label> ... ];  # the MPLS label stack
            bgp-prefix-sid [ <label-index> ] | [ <label-index>, [ ( <base>,<range> ) ... ] ];
            bgp-prefix-sid-srv6 ( l3-service|l2-service <ipv6> [<behavior> [ [ <LBL>, <LNL>, <FL>, <AL>, <len>, <offset> ] ]] );
            attribute [ 0x<code> 0x<flag> 0x<data> ];  # any attribute, as its wire bytes, but 14, 15, 17 and 18, which exabgp makes
            origin igp|egp|incomplete;
            otc <asn>|self|<role>;  # RFC 9234 Only-to-Customer
            med <0-4294967295>;
            as-path <asn>|[ <asn> ... ] ( <asn> ... ) confed-sequence [ ... ] confed-set [ ... ];
            local-preference <0-4294967295>;
            atomic-aggregate;
            aggregator ( <asn>:<router-id> );
            originator-id <ipv4>;
            cluster-list <ipv4>|[ <ipv4> ... ];
            community <asn>:<value>|[ <asn>:<value> ... ];  # may be repeated
            large-community <asn>:<value>:<value>|[ <asn>:<value>:<value> ... ];  # may be repeated
            extended-community <type>:<value>|[ <type>:<value> ... ];  # may be repeated
            aigp <number>|0x<hex>;
            name <name>;  # a name for the route, kept by exabgp
            split /<length>;  # announce the prefix as its more specifics of this length
            watchdog <name>;  # the watchdog which announces and withdraws the route
            withdraw;  # start with the route withdrawn
        }
        rtc ...;  # a route target membership route, RFC 4684, may be repeated
        sr-policy distinguisher <n> color <n> endpoint <ip> next-hop <ip> [<sub-tlv> ...];  # an SR policy route, may be repeated
    }
    announce {  # routes by address family
        ipv4 {  # the ipv4 routes, by subsequent address family
            unicast <prefix> next-hop <ip>|self [<attribute> <value> ...];  # a ipv4 unicast route, may be repeated
            multicast <prefix> next-hop <ip>|self [<attribute> <value> ...];  # a ipv4 multicast route, may be repeated
            nlri-mpls <prefix> next-hop <ip>|self [<attribute> <value> ...];  # a ipv4 nlri-mpls route, may be repeated
            mpls-vpn <prefix> next-hop <ip>|self [<attribute> <value> ...];  # a ipv4 mpls-vpn route, may be repeated
            rtc ...;  # a ipv4 rtc route, may be repeated
            flow <match> <value> ... <action> <value> ...;  # a ipv4 flow rule, RFC 8955, may be repeated
            flow-vpn <match> <value> ... <action> <value> ...;  # a ipv4 flow-vpn rule, RFC 8955, may be repeated
            mup mup-isd|mup-dsd|mup-t1st|mup-t2st ...;  # a Mobile User Plane route, draft-mpmz-bess-mup-safi, may be repeated
            mcast-vpn source-ad|source-join|shared-join ...;  # a multicast VPN route, RFC 6514, may be repeated
            sr-policy distinguisher <n> color <n> endpoint <ip> next-hop <ip> [<sub-tlv> ...];  # an SR policy route, RFC 9830, may be repeated
        }
        ipv6 {  # the ipv6 routes, by subsequent address family
            unicast <prefix> next-hop <ip>|self [<attribute> <value> ...];  # a ipv6 unicast route, may be repeated
            multicast <prefix> next-hop <ip>|self [<attribute> <value> ...];  # a ipv6 multicast route, may be repeated
            nlri-mpls <prefix> next-hop <ip>|self [<attribute> <value> ...];  # a ipv6 nlri-mpls route, may be repeated
            mpls-vpn <prefix> next-hop <ip>|self [<attribute> <value> ...];  # a ipv6 mpls-vpn route, may be repeated
            flow <match> <value> ... <action> <value> ...;  # a ipv6 flow rule, RFC 8955, may be repeated
            flow-vpn <match> <value> ... <action> <value> ...;  # a ipv6 flow-vpn rule, RFC 8955, may be repeated
            mup mup-isd|mup-dsd|mup-t1st|mup-t2st ...;  # a Mobile User Plane route, draft-mpmz-bess-mup-safi, may be repeated
            mcast-vpn source-ad|source-join|shared-join ...;  # a multicast VPN route, RFC 6514, may be repeated
            sr-policy distinguisher <n> color <n> endpoint <ip> next-hop <ip> [<sub-tlv> ...];  # an SR policy route, RFC 9830, may be repeated
        }
        l2vpn {  # the l2vpn routes
            vpls endpoint <n> base <n> offset <n> size <n> rd <rd> next-hop <ip> [...];  # a VPLS route, RFC 4761, may be repeated
        }
    }
    flow {  # FlowSpec routes (RFC 8955, RFC 8956)
        route <match> <value> ... <action> <value> ...;  # may be repeated
        route [<name>] {  # a flow route, what it matches and what it does
            match {  # what the route matches
                source <ip>/<mask>[/<offset>];  # the source prefix, RFC 8955 type 2
                source-ipv4 <ip>/<mask>[/<offset>];  # the source prefix, as source
                source-ipv6 <ip>/<mask>[/<offset>];  # the source prefix, as source
                destination <ip>/<mask>[/<offset>];  # the destination prefix, RFC 8955 type 1
                destination-ipv4 <ip>/<mask>[/<offset>];  # the destination prefix, as destination
                destination-ipv6 <ip>/<mask>[/<offset>];  # the destination prefix, as destination
                protocol <op><value>[&...] | [ ... ];  # the IP protocol, RFC 8955 type 3, may be repeated
                next-header <op><value>[&...] | [ ... ];  # the IPv6 next header, RFC 8956 type 3, may be repeated
                port <op><value>[&...] | [ ... ];  # the source or destination port, RFC 8955 type 4, may be repeated
                destination-port <op><value>[&...] | [ ... ];  # the destination port, RFC 8955 type 5, may be repeated
                source-port <op><value>[&...] | [ ... ];  # the source port, RFC 8955 type 6, may be repeated
                icmp-type <op><value>[&...] | [ ... ];  # the ICMP type, RFC 8955 type 7, may be repeated
                icmp-code <op><value>[&...] | [ ... ];  # the ICMP code, RFC 8955 type 8, may be repeated
                tcp-flags <op><value>[&...] | [ ... ];  # the TCP flags, RFC 8955 type 9, may be repeated
                packet-length <op><value>[&...] | [ ... ];  # the packet length, RFC 8955 type 10, may be repeated
                dscp <op><value>[&...] | [ ... ];  # the DSCP, RFC 8955 type 11, may be repeated
                traffic-class <op><value>[&...] | [ ... ];  # the IPv6 traffic class, RFC 8956 type 11, may be repeated
                fragment <op><value>[&...] | [ ... ];  # the fragment flags, RFC 8955 type 12, may be repeated
                flow-label <op><value>[&...] | [ ... ];  # the IPv6 flow label, RFC 8956 type 13, may be repeated
            }
            then {  # what is done with what matches
                accept;  # no action: the traffic is accepted
                discard;  # drop the traffic, a traffic-rate of 0
                rate-limit <number> [bytes|packets];  # traffic-rate, RFC 8955 7.3: bytes or packets per second, may be repeated
                redirect <asn>:<nn>|<ip>|[<ipv6>]:<nn>;  # redirect to the VRF of a route target, or to an address, may be repeated
                redirect-to-nexthop [<ip>];  # redirect to the next-hop of the route, or to the address given, may be repeated
                redirect-to-nexthop-ietf <ip>;  # redirect to an address, the IETF community
                redirect-to-nexthop-simpson;  # redirect to the next-hop of the UPDATE, the older form
                copy <ip>;  # copy the traffic to an address, the IETF community
                copy-simpson <ip>;  # copy the traffic to an address, the older form
                redirect-simpson <ip>;  # redirect to an address, the older form
                mark <0-63>;  # traffic-marking, RFC 8955 7.5: the DSCP to set, may be repeated
                action sample|terminal|sample-terminal;  # traffic-action, RFC 8955 7.6: sample the traffic, stop at this rule, or both, may be repeated
                community <asn>:<value>|[ <asn>:<value> ... ];  # may be repeated
                large-community <asn>:<value>:<value>|[ <asn>:<value>:<value> ... ];  # may be repeated
                extended-community <type>:<value>|[ <type>:<value> ... ];  # may be repeated
            }
            scope {  # where the route applies
                interface-set <transitive>:<direction>:<asn>:<group>;  # the interfaces the rule applies to, draft-ietf-idr-flowspec-interfaceset
            }
            rd <asn>:<n>|<ipv4>:<n>;
            route-distinguisher <asn>:<n>|<ipv4>:<n>;
            path-information <number>|<ipv4>;
            next-hop <ip>|self;  # the next-hop of the flow route, or self
        }
    }
    l2vpn {  # VPLS routes
        vpls endpoint <n> base <n> offset <n> size <n> rd <rd> next-hop <ip> [...];  # a VPLS route, on one line, may be repeated
        vpls [<name>] {  # a VPLS route, its values one per statement
            next-hop <ip>|self;  # the next-hop, or self for the IPv4 local address
            rd <asn>:<n>|<ipv4>:<n>;
            endpoint <0-65535>;  # the VE ID of the site
            offset <0-65535>;  # the VE block offset
            size <0-65535>;  # the VE block size
            base <0-1048575>;  # the label base
            attribute [ 0x<code> 0x<flag> 0x<data> ];
            origin igp|egp|incomplete;
            med <0-4294967295>;
            as-path <asn>|[ <asn> ... ] ( <asn> ... ) confed-sequence [ ... ] confed-set [ ... ];
            local-preference <0-4294967295>;
            atomic-aggregate;
            aggregator ( <asn>:<router-id> );
            originator-id <ipv4>;
            cluster-list <ipv4>|[ <ipv4> ... ];
            community <asn>:<value>|[ <asn>:<value> ... ];  # may be repeated
            extended-community <type>:<value>|[ <type>:<value> ... ];  # may be repeated
            name <name>;
            split /<length>;
            watchdog <name>;
            withdraw;
        }
    }
    operational {  # the operational messages sent to the peer
        asm afi <afi> safi <safi> advisory <advisory>;  # Advisory State Message, may be repeated
        adm afi <afi> safi <safi> advisory <advisory>;  # Advisory Dump Message, may be repeated
        rpcq afi <afi> safi <safi> sequence <sequence>;  # Reachable Prefix Count Query, may be repeated
        rpcp afi <afi> safi <safi> sequence <sequence> counter <counter>;  # Reachable Prefix Count Reply, may be repeated
        apcq afi <afi> safi <safi> sequence <sequence>;  # Adj-RIB-Out Prefix Count Query, may be repeated
        apcp afi <afi> safi <safi> sequence <sequence> counter <counter>;  # Adj-RIB-Out Prefix Count Reply, may be repeated
        lpcq afi <afi> safi <safi> sequence <sequence>;  # Local Prefix Count Query, may be repeated
        lpcp afi <afi> safi <safi> sequence <sequence> counter <counter>;  # Local Prefix Count Reply, may be repeated
    }
}

template

template {  # defaults shared by neighbors, which their own statements change
    neighbor <name> {  # a template, the defaults of a neighbor which inherits i ... }  # as neighbor
}

Clone this wiki locally