Important Restrictions
Default Route Advertising
-
Advertising default routes via BGP from the customer to Secure Access is not supported and can lead to traffic disruptions.
-
You can block default route advertisements from Secure Access to the customer site. From the Secure Access dashboard, go to Connect > Network Connections > Network Tunnel Groups. In the Advanced Settings of the network tunnel group routing configuration, check Block default route advertisement.
Avoid Router ID and BGP Peer Conflicts
- BGP requires a Router ID to establish BGP sessions between peers. If BGP does not have a Router ID, it cannot establish any peering sessions with BGP peers.
- When configuring Secure Access network tunnel groups, an organization can use the same BGP peer IPs for any or all of its network tunnel groups in the same region.
- However, the BGP Router ID must be unique to the BGP peers in a network. In other words, each router in the network must have a unique Router ID.