- Home
- Documentation
- Networking
- Data Sources
- xcsh_bgp (Data Source)
xcsh_bgp (Data Source)
Retrieves information about a BGP resource in F5 Distributed Cloud for bgp object is the configuration for peering with external bgp servers. it is created by users in system namespace. configuration. This is a read-only data source.
~> Note: For more information, see the F5 Distributed Cloud API documentation.
Example Usage
Section titled “Example Usage”# BGP Data Source Example
terraform { required_version = ">= 1.0"
required_providers { xcsh = { source = "f5-sales-demo/xcsh" version = ">= 0.1.0" } }}
# Look up an existing BGP by namedata "xcsh_bgp" "example" { name = "example-bgp" namespace = "staging"}
output "bgp_id" { value = data.xcsh_bgp.example.id}Argument Reference
Section titled “Argument Reference”-> Syntax Rule: This provider uses OneOf groups for mutually exclusive options. Fields documented as “Optional Block” use block syntax field_name { ... }. Empty OneOf object attributes use field_name = {}; conditional selection uses condition ? {} : null. Boolean attributes (such as add_hsts and http_redirect) use = true or = false.
🔶 High Risk Operations — Some operations on this resource have high danger level. Destructive operations may require confirmation.
Metadata Argument Reference
Section titled “Metadata Argument Reference”• name - Required String
Name of the BGP
• namespace - Required String
Namespace where the BGP exists
Attributes Reference
Section titled “Attributes Reference”In addition to all arguments above, the following attributes are exported:
• annotations - Optional Map
Annotations applied to this resource
• bgp_parameters - Optional String
Configuration parameter for BGP parameters
• description - Optional String
Description of the BGP
• id - Optional String
Unique identifier for the resource
• labels - Optional Map
Labels applied to this resource
• peers - Optional List
Peers. List of peers
• where - Optional String
VirtualSiteSiteRefSelector defines a union of reference to site or reference to virtual_site It used to refer site or a group of sites indicated by virtual site
• asn - Optional Number
ASN. Autonomous System Number
• from_site - Optional Object
Enable this option
• ip_address - Optional String
Use the configured IPv4 Address as Router ID
• local_address - Optional Object
Enable this option
A peers block supports the following:
• bfd_disabled - Optional Object
Enable this option
• bfd_enabled - Optional String
BFD. BFD parameters
• disable_spec - Optional Object
Enable this option
• external - Optional String
External BGP Peer. External BGP Peer parameters
• label - Optional String
Label. Specify whether this peer should be
• metadata - Optional String
MessageMetaType is metadata (common attributes) of a message that only certain messages have. This information is propagated to the metadata of a child object that gets created from the containing message during view processing. The information in this type can be specified by user during
create
• passive_mode_disabled - Optional Object
Enable this option
• passive_mode_enabled - Optional Object
Enable this option
• routing_policies - Optional String
List of rules which can be applied on all or particular nodes
Peers Bfd Disabled
Section titled “Peers Bfd Disabled”A bfd_disabled block (within peers) supports the following:
Peers Bfd Enabled
Section titled “Peers Bfd Enabled”A bfd_enabled block (within peers) supports the following:
• multiplier - Optional Number
Specify Number of missed packets to bring session down’
• receive_interval_milliseconds - Optional Number
BFD receive interval timer, in milliseconds
• transmit_interval_milliseconds - Optional Number
BFD transmit interval timer, in milliseconds
Peers Disable Spec
Section titled “Peers Disable Spec”A disable_spec block (within peers) supports the following:
Peers External
Section titled “Peers External”An external block (within peers) supports the following:
• address - Optional String
Specify IPv4 peer address
• address_ipv6 - Optional String
Specify peer IPv6 address
• asn - Optional Number
ASN. Autonomous System Number for BGP peer
• default_gateway - Optional Object
Configuration parameter for default gateway
• default_gateway_v6 - Optional Object
Configuration parameter for default gateway v6
• disable_spec - Optional Object
Enable this option
• disable_v6 - Optional Object
Enable this option
• external_connector - Optional Object
Configuration parameter for external connector
• family_inet - Optional String
Configuration parameter for family inet
• from_site - Optional Object
Enable this option
• from_site_v6 - Optional Object
Enable this option
• interface - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• interface_list - Optional String
Interface List. List of network interfaces
• md5_auth_key - Optional String
MD5 key for protecting BGP Sessions (RFC 2385)
• no_authentication - Optional Object
Configuration parameter for no authentication
• port - Optional Number
Peer Port. Peer TCP port number
• subnet_begin_offset - Optional Number
Calculate peer address using offset from the beginning of the subnet
• subnet_begin_offset_v6 - Optional Number
Calculate peer address using offset from the beginning of the subnet
• subnet_end_offset - Optional Number
Calculate peer address using offset from the end of the subnet
• subnet_end_offset_v6 - Optional Number
Calculate peer address using offset from the end of the subnet
Peers External Default Gateway
Section titled “Peers External Default Gateway”A default_gateway block (within peers.external) supports the following:
Peers External Default Gateway V6
Section titled “Peers External Default Gateway V6”A default_gateway_v6 block (within peers.external) supports the following:
Peers External Disable Spec
Section titled “Peers External Disable Spec”A disable_spec block (within peers.external) supports the following:
Peers External Disable V6
Section titled “Peers External Disable V6”A disable_v6 block (within peers.external) supports the following:
Peers External External Connector
Section titled “Peers External External Connector”An external_connector block (within peers.external) supports the following:
Peers External Family Inet
Section titled “Peers External Family Inet”A family_inet block (within peers.external) supports the following:
• disable_spec - Optional Object
Enable this option
• enable - Optional String
Unicast IPv4. IPv4 Unicast
Peers External Family Inet Disable Spec
Section titled “Peers External Family Inet Disable Spec”A disable_spec block (within peers.external.family_inet) supports the following:
Peers External Family Inet Enable
Section titled “Peers External Family Inet Enable”An enable block (within peers.external.family_inet) supports the following:
• aggregation - Optional List
BGP aggregation prefixes are shared among all peers, aggregation configured under any peer will take effect on all peers. Aggregation in BGP occurs only when more specific routes exist in the routing table and applies to outbound advertisements
Peers External Family Inet Enable Aggregation
Section titled “Peers External Family Inet Enable Aggregation”An aggregation block (within peers.external.family_inet.enable) supports the following:
• ip_prefix - Optional String
IP Prefix. Specify IPv4 subnet for aggregation
• options - Optional List
Aggregation OPTIONS. Configuration parameter for options
Peers External Family Inet Enable Aggregation Options
Section titled “Peers External Family Inet Enable Aggregation Options”An options block (within peers.external.family_inet.enable.aggregation) supports the following:
• summary_only - Optional String
Configuration parameter for summary only
Peers External Family Inet Enable Aggregation Options Summary Only
Section titled “Peers External Family Inet Enable Aggregation Options Summary Only”Deeply nested Only block collapsed for readability.
Peers External From Site
Section titled “Peers External From Site”A from_site block (within peers.external) supports the following:
Peers External From Site V6
Section titled “Peers External From Site V6”A from_site_v6 block (within peers.external) supports the following:
Peers External Interface
Section titled “Peers External Interface”An interface block (within peers.external) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Peers External Interface List
Section titled “Peers External Interface List”An interface_list block (within peers.external) supports the following:
• interfaces - Optional List
Interface List. List of network interfaces
Peers External Interface List Interfaces
Section titled “Peers External Interface List Interfaces”An interfaces block (within peers.external.interface_list) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Peers External No Authentication
Section titled “Peers External No Authentication”A no_authentication block (within peers.external) supports the following:
Peers Metadata
Section titled “Peers Metadata”A metadata block (within peers) supports the following:
• description_spec - Optional String
Description. Human readable description
• name - Optional String
Name of the message. The value of name has to follow DNS-1035 format
Peers Passive Mode Disabled
Section titled “Peers Passive Mode Disabled”A passive_mode_disabled block (within peers) supports the following:
Peers Passive Mode Enabled
Section titled “Peers Passive Mode Enabled”A passive_mode_enabled block (within peers) supports the following:
Peers Routing Policies
Section titled “Peers Routing Policies”A routing_policies block (within peers) supports the following:
• route_policy - Optional List
Policy configuration for this feature
Peers Routing Policies Route Policy
Section titled “Peers Routing Policies Route Policy”A route_policy block (within peers.routing_policies) supports the following:
• all_nodes - Optional Object
Enable this option
• inbound - Optional Object
Enable this option
• node_name - Optional String
List of nodes on which BGP routing policy has to be applied
• object_refs - Optional List
BGP routing policy. Select route policy to apply
• outbound - Optional Object
Enable this option
Peers Routing Policies Route Policy All Nodes
Section titled “Peers Routing Policies Route Policy All Nodes”An all_nodes block (within peers.routing_policies.route_policy) supports the following:
Peers Routing Policies Route Policy Inbound
Section titled “Peers Routing Policies Route Policy Inbound”An inbound block (within peers.routing_policies.route_policy) supports the following:
Peers Routing Policies Route Policy Node Name
Section titled “Peers Routing Policies Route Policy Node Name”A node_name block (within peers.routing_policies.route_policy) supports the following:
• node - Optional List
Select BGP Session on which policy will be applied
Peers Routing Policies Route Policy Object Refs
Section titled “Peers Routing Policies Route Policy Object Refs”An object_refs block (within peers.routing_policies.route_policy) supports the following:
• kind - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then kind will hold the referred object’s kind (e.g. ‘route’)
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
• uid - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then uid will hold the referred object’s(e.g. Route’s) uid
Peers Routing Policies Route Policy Outbound
Section titled “Peers Routing Policies Route Policy Outbound”An outbound block (within peers.routing_policies.route_policy) supports the following:
A where block supports the following:
• site - Optional String
Specifies a direct reference to a site configuration object
• virtual_site - Optional String
Virtual Site. A reference to virtual_site object
Where Site
Section titled “Where Site”A site block (within where) supports the following:
• disable_internet_vip - Optional Object
Enable this option
• enable_internet_vip - Optional Object
Enable this option
• network_type - Optional String Defaults to VIRTUAL_NETWORK_SITE_LOCAL
Possible values are VIRTUAL_NETWORK_SITE_LOCAL, VIRTUAL_NETWORK_SITE_LOCAL_INSIDE, VIRTUAL_NETWORK_PER_SITE, VIRTUAL_NETWORK_PUBLIC, VIRTUAL_NETWORK_GLOBAL, VIRTUAL_NETWORK_SITE_SERVICE,
VIRTUAL_NETWORK_VER_INTERNAL, VIRTUAL_NETWORK_SITE_LOCAL_INSIDE_OUTSIDE, VIRTUAL_NETWORK_IP_AUTO, VIRTUAL_NETWORK_VOLTADN_PRIVATE_NETWORK, VIRTUAL_NETWORK_SRV6_NETWORK, VIRTUAL_NETWORK_IP_FABRIC, VIRTUAL_NETWORK_SEGMENT, VIRTUAL_NETWORK_MANAGEMENT
[Enum:
VIRTUAL_NETWORK_SITE_LOCAL|VIRTUAL_NETWORK_SITE_LOCAL_INSIDE|VIRTUAL_NETWORK_PER_SITE|VIRTUAL_NETWORK_PUBLIC|VIRTUAL_NETWORK_GLOBAL|VIRTUAL_NETWORK_SITE_SERVICE|VIRTUAL_NETWORK_VER_INTERNAL|VIRTUAL_NETWORK_SITE_LOCAL_INSIDE_OUTSIDE|VIRTUAL_NETWORK_IP_AUTO|VIRTUAL_NETWORK_VOLTADN_PRIVATE_NETWORK|VIRTUAL_NETWORK_SRV6_NETWORK|VIRTUAL_NETWORK_IP_FABRIC|VIRTUAL_NETWORK_SEGMENT|VIRTUAL_NETWORK_MANAGEMENT]
Different types of virtual networks understood by the system Virtual-network of type VIRTUAL_NETWORK_SITE_LOCAL provides connectivity to public (outside) network. This is an insecure network and is connected to public internet via NAT Gateways/firwalls Virtual-network of this type is local to
• ref - Optional List
Reference. A site direct reference
Where Site Disable internet VIP
Section titled “Where Site Disable internet VIP”A disable_internet_vip block (within where.site) supports the following:
Where Site Enable internet VIP
Section titled “Where Site Enable internet VIP”An enable_internet_vip block (within where.site) supports the following:
Where Site Ref
Section titled “Where Site Ref”A ref block (within where.site) supports the following:
• kind - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then kind will hold the referred object’s kind (e.g. ‘route’)
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
• uid - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then uid will hold the referred object’s(e.g. Route’s) uid
Where Virtual Site
Section titled “Where Virtual Site”A virtual_site block (within where) supports the following:
• disable_internet_vip - Optional Object
Enable this option
• enable_internet_vip - Optional Object
Enable this option
• network_type - Optional String Defaults to VIRTUAL_NETWORK_SITE_LOCAL
Possible values are VIRTUAL_NETWORK_SITE_LOCAL, VIRTUAL_NETWORK_SITE_LOCAL_INSIDE, VIRTUAL_NETWORK_PER_SITE, VIRTUAL_NETWORK_PUBLIC, VIRTUAL_NETWORK_GLOBAL, VIRTUAL_NETWORK_SITE_SERVICE, VIRTUAL_NETWORK_VER_INTERNAL,
VIRTUAL_NETWORK_SITE_LOCAL_INSIDE_OUTSIDE, VIRTUAL_NETWORK_IP_AUTO, VIRTUAL_NETWORK_VOLTADN_PRIVATE_NETWORK, VIRTUAL_NETWORK_SRV6_NETWORK, VIRTUAL_NETWORK_IP_FABRIC, VIRTUAL_NETWORK_SEGMENT, VIRTUAL_NETWORK_MANAGEMENT
[Enum:
VIRTUAL_NETWORK_SITE_LOCAL|VIRTUAL_NETWORK_SITE_LOCAL_INSIDE|VIRTUAL_NETWORK_PER_SITE|VIRTUAL_NETWORK_PUBLIC|VIRTUAL_NETWORK_GLOBAL|VIRTUAL_NETWORK_SITE_SERVICE|VIRTUAL_NETWORK_VER_INTERNAL|VIRTUAL_NETWORK_SITE_LOCAL_INSIDE_OUTSIDE|VIRTUAL_NETWORK_IP_AUTO|VIRTUAL_NETWORK_VOLTADN_PRIVATE_NETWORK|VIRTUAL_NETWORK_SRV6_NETWORK|VIRTUAL_NETWORK_IP_FABRIC|VIRTUAL_NETWORK_SEGMENT|VIRTUAL_NETWORK_MANAGEMENT]
Different types of virtual networks understood by the system Virtual-network of type VIRTUAL_NETWORK_SITE_LOCAL provides connectivity to public (outside) network. This is an insecure network and is connected to public internet via NAT Gateways/firwalls Virtual-network of this type is local to
• ref - Optional List
Reference. A virtual_site direct reference
Where Virtual Site Disable internet VIP
Section titled “Where Virtual Site Disable internet VIP”A disable_internet_vip block (within where.virtual_site) supports the following:
Where Virtual Site Enable internet VIP
Section titled “Where Virtual Site Enable internet VIP”An enable_internet_vip block (within where.virtual_site) supports the following:
Where Virtual Site Ref
Section titled “Where Virtual Site Ref”A ref block (within where.virtual_site) supports the following:
• kind - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then kind will hold the referred object’s kind (e.g. ‘route’)
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
• uid - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then uid will hold the referred object’s(e.g. Route’s) uid
Common Types
Section titled “Common Types”The following type definitions are used throughout this resource. See the full definition here rather than repeated inline.
Object Reference {#common-object-reference}
Section titled “Object Reference {#common-object-reference}”Object references establish a direct reference from one configuration object to another in F5 Distributed Cloud. References use the format tenant/namespace/name.
| Field | Type | Description |
|---|---|---|
name | String | Name of the referenced object |
namespace | String | Namespace containing the referenced object |
tenant | String | Tenant of the referenced object (system-managed) |
Transformers {#common-transformers}
Section titled “Transformers {#common-transformers}”Transformers apply transformations to input values before matching. Multiple transformers can be applied in order.
| Value | Description |
|---|---|
LOWER_CASE | Convert to lowercase |
UPPER_CASE | Convert to uppercase |
BASE64_DECODE | Decodebase64 content |
NORMALIZE_PATH | Normalize URL path |
REMOVE_WHITESPACE | Remove whitespace characters |
URL_DECODE | Decode URL-encoded characters |
TRIM_LEFT | Trim leading whitespace |
TRIM_RIGHT | Trim trailing whitespace |
TRIM | Trim both leading and trailing whitespace |
HTTP Methods {#common-http-methods}
Section titled “HTTP Methods {#common-http-methods}”HTTP methods used for request matching.
| Value | Description |
|---|---|
ANY | Match any HTTP method |
GET | HTTP GET request |
HEAD | HTTP HEAD request |
POST | HTTP POST request |
PUT | HTTP PUT request |
DELETE | HTTP DELETE request |
CONNECT | HTTP CONNECT request |
OPTIONS | HTTP OPTIONS request |
TRACE | HTTP TRACE request |
PATCH | HTTP PATCH request |
COPY | HTTP COPY request (WebDAV) |
TLS Fingerprints {#common-tls-fingerprints}
Section titled “TLS Fingerprints {#common-tls-fingerprints}”TLS fingerprint categories for malicious client detection.
| Value | Description |
|---|---|
TLS_FINGERPRINT_NONE | No fingerprint matching |
ANY_MALICIOUS_FINGERPRINT | Match any known malicious fingerprint |
ADWARE | Adware-associated fingerprints |
DRIDEX | Dridex malware fingerprints |
GOOTKIT | Gootkit malware fingerprints |
RANSOMWARE | Ransomware-associated fingerprints |
TRICKBOT | Trickbot malware fingerprints |
IP Threat Categories {#common-ip-threat-categories}
Section titled “IP Threat Categories {#common-ip-threat-categories}”IP address threat categories for security filtering.
| Value | Description |
|---|---|
SPAM_SOURCES | Known spam sources |
WINDOWS_EXPLOITS | Windows exploit sources |
WEB_ATTACKS | Web attack sources |
BOTNETS | Known botnet IPs |
SCANNERS | Network scanner IPs |
REPUTATION | Poor reputation IPs |
PHISHING | Phishing-related IPs |
PROXY | Anonymous proxy IPs |
MOBILE_THREATS | Mobile threat sources |
TOR_PROXY | Tor exit nodes |
DENIAL_OF_SERVICE | DoS attack sources |
NETWORK | Known bad network ranges |