BGP Aggregation & Suppress-Map Builder

From vendor documentation

Build a BGP aggregate plan for Cisco, Huawei, Arista or Juniper: what summary-only suppresses, what must stay visible, and which routes fall outside the aggregate and would be blackholed.

Input

One CIDR per line. Blank lines and #, ! or // comments are ignored.

Leave blank to derive the smallest enclosing block.

Prefixes that must keep being advertised individually.

Export

4 row(s)

Aggregation

Cisco IOS / IOS-XE — Cisco IOS BGP command reference — aggregate-address summary-only + suppress-map.

Verify on your platform
Aggregate
10.0.0.0/22

Derived (smallest enclosing)

Suppressed
3

More-specifics hidden by summary-only

Kept visible
1

Matched by the suppress-map

Uncovered
0

Aggregate covers everything

Holes
0 (0 addr)

Advertised but unowned

Vendor
Cisco IOS / IOS-XE

Per-prefix decisions

RolePrefixAddressesBroadcast
suppressed10.0.0.0/2425610.0.0.1 – 10.0.0.254
suppressed10.0.1.0/2425610.0.1.1 – 10.0.1.254
suppressed10.0.3.0/2425610.0.3.1 – 10.0.3.254
kept visible10.0.2.0/2425610.0.2.1 – 10.0.2.254

Cisco IOS / IOS-XE configuration

Transcribed from vendor documentation — confirm on a lab device first

cisco aggregation
! ── Cisco IOS / IOS-XE ─────────────────────────────────────────────
! summary-only suppresses every more-specific the aggregate covers,
! except those matched by the suppress-map below.
! ------------------------------------------------------------------
ip prefix-list AGG-KEEP seq 5 remark More-specifics that must stay visible
ip prefix-list AGG-KEEP seq 10 permit 10.0.2.0/24
!
route-map AGG-KEEP permit 10
 match ip address prefix-list AGG-KEEP
!
router bgp <ASN>
 address-family ipv4 unicast
  aggregate-address 10.0.0.0/22 summary-only suppress-map AGG-KEEP
  ! suppressed by the aggregate: 10.0.0.0/24
  ! suppressed by the aggregate: 10.0.1.0/24
  ! suppressed by the aggregate: 10.0.3.0/24
 exit-address-family

Source: Cisco IOS BGP command reference — aggregate-address summary-only + suppress-map. This tool has not reproduced the syntax on hardware; the manifest is marked documented rather than verified.

Frequently asked

What does summary-only do to my more-specific routes?
It advertises the aggregate and suppresses every more-specific that the aggregate covers. The more-specifics stay in the local BGP table but are not announced, so anything relying on them being visible from outside stops seeing them.
Why would a more-specific fall outside my aggregate?
Usually because the aggregate was chosen by hand and is narrower than the routes it is meant to summarise — for example 10.0.0.0/23 for routes in 10.0.0.0/24 through 10.0.4.0/24. Any route outside the aggregate is not covered, and with summary-only it is withdrawn while the aggregate is announced.
How does Huawei express suppress-map?
VRP uses aggregate-address ... summary-only suppress-policy NAME with a route-policy that re-permits the prefixes in an ip ip-prefix list. Note that VRP writes ip-prefix mask lengths as host bits, so a /24 entry reads "24 less-equal 8".
Why is there no summary-only on Juniper?
Junos has no such keyword. The equivalent is an aggregate route in routing-options plus a policy-statement that accepts the more-specifics you want to keep and rejects the rest.
Is this configuration verified on real hardware?
No. The syntax is transcribed from vendor documentation and the tool is labelled documented rather than verified, so test it on a lab device or a maintenance window before rolling it out.

Next