{"id":9,"date":"2011-05-09T17:20:55","date_gmt":"2011-05-09T16:20:55","guid":{"rendered":"http:\/\/openbsd.g7obs.com\/?p=9"},"modified":"2011-05-09T17:20:55","modified_gmt":"2011-05-09T16:20:55","slug":"using-openbsd-as-a-bgp-looking-glass","status":"publish","type":"post","link":"http:\/\/openbsd.g7obs.com\/?p=9","title":{"rendered":"Using OpenBSD as a BGP Looking Glass"},"content":{"rendered":"<p>Since OpenBSD 4.1 there have been some interesting tools that could be used by an ISP, and one of these is <strong>bgplg<\/strong><\/p>\n<p><strong>bgplg <\/strong>is a BGP Looking Glass, which is a piece of software that allows you to inspect a routing table, and see where you are learning the route to a particular network from.<\/p>\n<p>If you have multiple Internet providers, this tool will show you the &#8216;preferred&#8217; provider (the one with the shortest and theoretically fastest) path to a given network.<\/p>\n<p>It is not enabled by default on a stock OpenBSD system, but you can enable it easily enough<\/p>\n<p>You need to make the following changes as root to enable the bgplg system<\/p>\n<pre># chmod 0555 \/var\/www\/cgi-bin\/bgplg<\/pre>\n<pre># chmod 0555 \/var\/www\/bin\/bgpctl<\/pre>\n<pre># mkdir \/var\/www\/etc<\/pre>\n<pre># cp \/etc\/resolv.conf \/var\/www\/etc<\/pre>\n<pre># chmod 4555 \/var\/www\/bin\/ping<\/pre>\n<pre># chmod 4555 \/var\/www\/bin\/ping6<\/pre>\n<pre># chmod 4555 \/var\/www\/bin\/traceroute<\/pre>\n<pre># chmod 4555 \/var\/www\/bin\/traceroute6<\/pre>\n<p>You will also need to start the Border Gateway Protocol daemon with a second, restricted, control socket that can be used from within the chroot(2) environment. If you are not sure how to do this, see bgpd.conf(5) for more information.<br \/>\nFor example, add the following to \/etc\/bgpd.conf to have bgpd(8) open a second, restricted, control socket:<\/p>\n<pre>socket \"\/var\/www\/logs\/bgpd.rsock\" restricted<\/pre>\n<p>Start the Apache HyperText Transfer Protocol server. \u00a0See httpd(8) for more information.<br \/>\nThe Standard output is rather spartan, but can be customised by making some changes to various files in the conf\/ directory<\/p>\n<pre>\r\n\/var\/www\/conf\/bgplg.css \u00a0 \u00a0 Optional bgplg CSS style sheet.<\/pre>\n<pre>\/var\/www\/conf\/bgplg.head \u00a0 \u00a0Optional bgplg HTML header.<\/pre>\n<pre>\/var\/www\/conf\/bgplg.foot \u00a0 \u00a0Optional bgplg HTML footer.<\/pre>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Since OpenBSD 4.1 there have been some interesting tools that could be used by an ISP, and one of these is bgplg bgplg is a BGP Looking Glass, which is a piece of software that allows you to inspect a routing table, and see where you are learning the route to a particular network from. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[7,6],"class_list":["post-9","post","type-post","status-publish","format-standard","hentry","category-openbgpd","tag-bgp","tag-looking-glass"],"_links":{"self":[{"href":"http:\/\/openbsd.g7obs.com\/index.php?rest_route=\/wp\/v2\/posts\/9","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/openbsd.g7obs.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/openbsd.g7obs.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/openbsd.g7obs.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/openbsd.g7obs.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9"}],"version-history":[{"count":5,"href":"http:\/\/openbsd.g7obs.com\/index.php?rest_route=\/wp\/v2\/posts\/9\/revisions"}],"predecessor-version":[{"id":14,"href":"http:\/\/openbsd.g7obs.com\/index.php?rest_route=\/wp\/v2\/posts\/9\/revisions\/14"}],"wp:attachment":[{"href":"http:\/\/openbsd.g7obs.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/openbsd.g7obs.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/openbsd.g7obs.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}