Using instance-import leak 3 routes from wifiinternet to wifiswu, 1 BGP default route and 2 direct routes.
set security policies default-policy permit-all
set security zones security-zone trust host-inbound-traffic system-services all
set security zones security-zone trust host-inbound-traffic protocols all
set security zones security-zone trust interfaces ge-0/0/0.0
set security zones security-zone trust interfaces ge-0/0/1.0
set security zones security-zone untrust host-inbound-traffic system-services all
set security zones security-zone untrust host-inbound-traffic protocols all
set security zones security-zone untrust interfaces ge-0/0/2.0
set security zones security-zone dmz host-inbound-traffic system-services all
set security zones security-zone dmz host-inbound-traffic protocols all
set security zones security-zone dmz interfaces ge-0/0/3.0
set security zones security-zone vpn host-inbound-traffic system-services all
set security zones security-zone vpn host-inbound-traffic protocols all
set security zones security-zone vpn interfaces st0.0
set interfaces ge-0/0/0 unit 0 family inet address 172.16.1.1/24
set interfaces ge-0/0/1 unit 0 family inet address 172.16.2.1/24
set interfaces ge-0/0/2 unit 0 family inet address 172.16.3.1/24
set interfaces ge-0/0/3 unit 0 family inet address 172.16.4.1/24
set interfaces st0 unit 0 family inet
set policy-options policy-statement wifiswu-import term 1 from instance wifiinternet
set policy-options policy-statement wifiswu-import term 1 from route-filter 0.0.0.0/0 exact
set policy-options policy-statement wifiswu-import term 1 then accept
set policy-options policy-statement wifiswu-import term 2 from instance wifiinternet
set policy-options policy-statement wifiswu-import term 2 from protocol direct
set policy-options policy-statement wifiswu-import term 2 then accept
set policy-options policy-statement wifiswu-import term reject then reject
set routing-instances wifiinternet instance-type virtual-router
set routing-instances wifiinternet interface ge-0/0/0.0
set routing-instances wifiinternet interface ge-0/0/1.0
set routing-instances wifiinternet routing-options router-id 1.1.1.1
set routing-instances wifiinternet routing-options autonomous-system 17421
set routing-instances wifiinternet protocols bgp group ebgp type external
set routing-instances wifiinternet protocols bgp group ebgp local-address 172.16.1.1
set routing-instances wifiinternet protocols bgp group ebgp peer-as 3462
set routing-instances wifiinternet protocols bgp group ebgp neighbor 172.16.1.2
set routing-instances wifiswu instance-type virtual-router
set routing-instances wifiswu interface ge-0/0/2.0
set routing-instances wifiswu routing-options instance-import wifiswu-import
set routing-instances wifiswu protocols ospf area 0.0.0.0 interface ge-0/0/2.0
root@jtac-srx1500-r2072# run show as-path domain
Domain: 1 Primary: 0
References: 7 Paths: 2
Flags: Master
Domain: 3 Primary: 17421
References: 1 Paths: 1
Local AS: 17421 Loops: 1
root@jtac-srx1500-r2072# run show route table wifiswu.inet.0 extensive
wifiswu.inet.0: 8 destinations, 8 routes (8 active, 0 holddown, 0 hidden)
0.0.0.0/0 (1 entry, 1 announced)
TSI:
KRT in-kernel 0.0.0.0/0 -> {172.16.1.2}
*BGP Preference: 170/-101
Next hop type: Router, Next hop index: 609
Address: 0x9db3af0
Next-hop reference count: 4
Source: 172.16.1.2
Next hop: 172.16.1.2 via ge-0/0/0.0, selected
Session Id: 0x0
State: <Secondary Active Ext>
Local AS: 17421 Peer AS: 3462
Age: 1d 0:19:27
Validation State: unverified
Task: BGP_3462_17421.172.16.1.2
Announcement bits (1): 2-KRT
AS path: 17421 3462 I
Accepted
Localpref: 100
Router ID: 2.2.2.2
Primary Routing Table wifiinternet.inet.0
9.9.9.9/32 (1 entry, 1 announced)
KRT in-kernel 9.9.9.9/32 -> {172.16.3.2}
*OSPF Preference: 10
Next hop type: Router, Next hop index: 610
Address: 0x9db3730
Next hop: 172.16.3.2 via ge-0/0/2.0, selected
State: <Active Int>
Age: 1d 0:19:19 Metric: 1
Area: 0.0.0.0
Task: wifiswu-OSPF
AS path: I
172.16.1.0/24 (1 entry, 1 announced)
KRT in-kernel 172.16.1.0/24 -> {Table}
*Direct Preference: 0
Next hop type: Interface, Next hop index: 0
Address: 0x9db37f0
Next-hop reference count: 2
Next hop: via ge-0/0/0.0, selected
State: <Secondary Active Int>
Local AS: 17421
Age: 1d 0:19:34
Task: IF
AS path: 17421 I
172.16.2.0/24 (1 entry, 1 announced)
KRT in-kernel 172.16.2.0/24 -> {Table}
Address: 0x9db3790
Next hop: via ge-0/0/1.0, selected
172.16.3.0/24 (1 entry, 0 announced)
Address: 0x9db3850
Next-hop reference count: 1
Next hop: via ge-0/0/2.0, selected
172.16.3.1/32 (1 entry, 0 announced)
*Local Preference: 0
Next hop type: Local, Next hop index: 0
Address: 0x9524ce4
Next-hop reference count: 6
Next hop:
Interface: ge-0/0/2.0
State: <Active NoReadvrt Int>
172.16.4.0/24 (1 entry, 1 announced)
KRT in-kernel 172.16.4.0/24 -> {172.16.3.2}
Age: 1d 0:19:19 Metric: 2
224.0.0.5/32 (1 entry, 1 announced)
KRT in-kernel 224.0.0.5/32 -> {}
Next hop type: MultiRecv, Next hop index: 0
Address: 0x9525f24
Age: 1d 0:19:35 Metric: 1
Task: OSPF I/O./var/run/ppmd_control
The issue here is after adding below configurations, these 3 routes changed to hidden status and the reason is AS path looped.
set routing-instances DCP_SGi-vr instance-type virtual-router
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_internet type external
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_internet local-address 211.79.47.1
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_internet peer-as 9505
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_internet local-as 17421
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_internet neighbor 211.79.47.2
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_IPSec type external
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_IPSec local-address 211.79.47.5
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_IPSec peer-as 9505
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_IPSec local-as 17421
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_IPSec neighbor 211.79.47.6
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_IPSec-vEPG type external
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_IPSec-vEPG local-address 211.79.47.9
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_IPSec-vEPG hold-time 180
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_IPSec-vEPG peer-as 28852
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_IPSec-vEPG local-as 17421
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_IPSec-vEPG neighbor 211.79.47.10 bfd-liveness-detection minimum-interval 100
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_IPSec-vEPG neighbor 211.79.47.10 bfd-liveness-detection minimum-receive-interval 100
set routing-instances DCP_SGi-vr protocols bgp group eBGP-DCP_SGI_IPSec-vEPG neighbor 211.79.47.10 bfd-liveness-detection multiplier 3
set routing-instances DCP_SGi-vr interface ge-0/0/3.0
root@jtac-srx1500-r2072# show | compare
[edit routing-instances]
+ DCP_SGi-vr {
+ instance-type virtual-router;
+ interface ge-0/0/3.0;
+ protocols {
+ bgp {
+ group eBGP-DCP_SGI_internet {
+ type external;
+ local-address 211.79.47.1;
+ peer-as 9505;
+ local-as 17421;
+ neighbor 211.79.47.2;
+ }
+ group eBGP-DCP_SGI_IPSec {
+ local-address 211.79.47.5;
+ neighbor 211.79.47.6;
+ group eBGP-DCP_SGI_IPSec-vEPG {
+ local-address 211.79.47.9;
+ hold-time 180;
+ peer-as 28852;
+ neighbor 211.79.47.10 {
+ bfd-liveness-detection {
+ minimum-interval 100;
+ minimum-receive-interval 100;
+ multiplier 3;
[edit]
root@jtac-srx1500-r2072# commit
commit complete
References: 8 Paths: 2
root@jtac-srx1500-r2072# run show route table wifiswu.inet.0 hidden extensive
wifiswu.inet.0: 8 destinations, 8 routes (5 active, 0 holddown, 3 hidden)
0.0.0.0/0 (1 entry, 0 announced)
BGP
Next-hop reference count: 3
State: <Secondary Hidden Ext>
Age: 1d 0:24:36
AS path: 17421 3462 I (Looped: 17421)
Hidden reason: reason not available
172.16.1.0/24 (1 entry, 0 announced)
Direct
State: <Secondary Hidden Int>
Age: 1d 0:24:43
AS path: 17421 I (Looped: 17421)
172.16.2.0/24 (1 entry, 0 announced)
The root cause of this issue stems from triggering the loop checking mechanism when import routing entry between different AS-path domains.
AS-path domain output prior to these 3 routing entries been hidden:
Flags: Master -------------------------------------------------- No Local AS list by default.
AS-path domain output when these 3 routing entries been hidden:
Local AS: 17421 Loops: 1 -------------------------- After adding the routing-instance DCP_SGi-vr, Local-AS list generated and AS 17421 included in.
Here we first need to explain the correspondence between the AS-path domain and the routing instance:
With 'routing options autonomous system' statement configured (17421 in this example) for instance wifiinternet, it belongs to a seperate domain (domain 3 in this example).While WITHOUT 'routing options autonomous system' statement configured, the instances (default/wifiswu/ DCP_SGi-vr) belong to domain 1 (the Master domain).
The instance import from routing instance wifiinternet(AS-path domain 3) to wifiswu(AS-path domain 1) is indeed a routing leak action that crosses AS-path domains, then the loop check will be triggered.
When a route is leaked between routing-instances that belong to different independent AS-path-domains, the source routing-instance's autonomous-system number is prepended to the route.
In this case, the Junos will prepend AS 17421 to all these 3 routes which leaked from wifiinternet(AS-path domain 3), and it will compare with the destination AS path domain's AS local list(AS-path domain 1) to check if a loop occurs.
Let's take a look back at this configuration change. After adding routing instance DCP_SGi-vr and configure the local-as 17421 under bgp group level, it will affect the Master domain and caused it to generate a local-as list which include 17421, thus these 3 import routes which has already prepend the AS 17421 will reported AS-path looped and finally been hidden.
The key to resolving this issue is to ensure that all routing instances involved in instance-import belong to the same AS-path domain, this will avoiding cross AS-path domain loop checks. Therefore, any of the following three approaches can effectively address this problem:
Additionally, please note that the loop check mechanism across AS-PATH domains applies not only to BGP routes but also to non-BGP routes.