Academy/VCAP — VCF Networking (3V0-25.25)/BGP Route Maps & Community-Based QoS
This lab targets VCF 9.0

BGP Route Maps & Community-Based QoS

VCF 9.0Intermediatevcap-advanced⏱ 120 min

Objectives

  • Configure Tier-0 BGP with route maps; tag production vs. test pods; verify upstream router receives communities.

Prerequisites

VCF lab environment deployed and operational

Lab Environment

Standard VCF lab environment for Advanced VCF 9.0 Networking (NSX & Advanced Routing)

Tasks

Task 1 BGP Route Maps & Community-Based QoS

Configure Tier-0 BGP with route maps; tag production vs. test pods; verify upstream router receives communities.

Step 1

Configure Tier-0 BGP: ASN 65000, neighbor (upstream) 10.0.0.1 ASN 65001.

Step 2

Create prefix lists: prod-prefixes (10.100.0.0/16), test-prefixes (10.200.0.0/16).

Step 3

Create route-map prod-tag: match prod-prefixes, set community 65000:1000.

Step 4

Apply route-map to outbound BGP advertisements.

Step 5

Monitor BGP neighbor: show bgp neighbor 10.0.0.1 (verify neighbor state established, prefixes advertised).

Step 6

On upstream router, verify received communities: show ip bgp neighbors 10.0.0.1 advertised-routes

Step 7

On upstream, apply QoS: routes with community 65000:1000 get priority queue, 65000:1001 get best-effort.

Step 8

Inject test traffic; capture packets; verify DiffServ markings match community intent.

Validation Gate

Check: Verify lab completion

Expected: Lab exercise completed successfully

Common Errors

BGP route maps not matching expected prefixes due to incorrect prefix-list syntax
Fix: NSX BGP route maps reference prefix lists. Prefix list entry 'ge 24 le 32' matches all subnets from /24 to /32. Missing ge/le parameters match only the exact prefix length. Test route maps with 'get bgp neighbor <IP> advertised-routes' and 'received-routes' on the Edge.
Community strings not propagating across T0-to-physical BGP peering
Fix: BGP community attributes must be explicitly sent: configure 'send community' on the BGP neighbor. Without this, community tags set by route maps are stripped at the peering boundary. Verify with: 'show bgp <prefix> detail' checking for community strings.
Route map applied in wrong direction (in vs out)
Fix: Route maps applied 'in' filter received routes. Applied 'out' filter advertised routes. Applying a deny-all map in the wrong direction blocks all routes. Always verify direction and test with 'show bgp neighbor <IP> advertised-routes'.

Final Validation

Lab completed successfully

✓ All steps completed → No errors observed

Cleanup / Restore

• Revert to snapshot if needed

Design Reflection (VCDX)

BGP design is tested for candidates with network architecture backgrounds. Panelists ask about route filtering, convergence behavior, and how you prevent route leaks between domains.

⚠ Known Pitfalls (from Community KB)

Applying route maps without testing — a misconfigured deny-all blocks all BGP routes.
Forgetting 'send community' — community-based QoS fails silently because tags are stripped.
Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.