- Home
- Documentation
- Networking
- Data Sources
- xcsh_site_bgp_status (Data Source)
xcsh_site_bgp_status (Data Source)
Polls authoritative F5 XC BGP and route observations until they agree with MAC-bound AWS expectations. This is a read-only data source.
~> Note: For more information, see the F5 Distributed Cloud API documentation.
Example Usage
Section titled “Example Usage”# Wait for MAC-correlated BGP peers and both BGP and simplified route views to# converge. Peer addresses and expected routes come from authoritative AWS# TGW Connect resource attributes in a real configuration.
terraform { required_version = ">= 1.0"
required_providers { xcsh = { source = "f5-sales-demo/xcsh" version = ">= 6.0.0" } }}
data "xcsh_site_bgp_status" "site" { namespace = "system" site = "example-smsv2-site"
expected_exported_routes = ["10.40.0.10/32"]
expected_peers = { node_0_slo = { node = "node-0" role = "slo" mac = "02:00:00:00:00:10" peer_address = "169.254.100.1" expected_imported_routes = ["10.20.0.0/16"] } node_0_sli = { node = "node-0" role = "sli" mac = "02:00:00:00:00:11" peer_address = "169.254.101.1" expected_imported_routes = ["10.30.0.0/16"] } }
timeout_seconds = 300 poll_interval_seconds = 10}
output "bgp_converged" { value = data.xcsh_site_bgp_status.site.converged}
output "bgp_peers" { value = data.xcsh_site_bgp_status.site.peers}Argument Reference
Section titled “Argument Reference”-> Syntax Rule: This provider uses OneOf groups for mutually exclusive options. Fields documented as “Optional Block” use block syntax field_name { ... }. Empty OneOf object attributes use field_name = {}; conditional selection uses condition ? {} : null. Boolean attributes (such as add_hsts and http_redirect) use = true or = false.
Metadata Argument Reference
Section titled “Metadata Argument Reference”• namespace - Required String
Spec Argument Reference
Section titled “Spec Argument Reference”• expected_exported_routes - Required Set
Exact prefixes that every expected node must export and carry in the selected SLO or SLI route view
• expected_peers - Required Map
• poll_interval_seconds - Optional Number
• site - Required String
• timeout_seconds - Optional Number
Attributes Reference
Section titled “Attributes Reference”In addition to all arguments above, the following attributes are exported:
• bgp_routes_json - Optional String
• converged - Optional Bool
• id - Optional String
The ID of this resource
• peers - Optional Map
• sli_routes_json - Optional String
• slo_routes_json - Optional String
• expected_imported_routes - Optional Set
Exact prefixes that must be imported from this remote peer on the expected node
• mac - Optional String
• node - Optional String
• peer_address - Optional String
• role - Optional String
A peers block supports the following:
• advertised_prefix_count - Optional Number
• established - Optional Bool
• interface_name - Optional String
• mac - Optional String
• node - Optional String
• peer_address - Optional String
• received_prefix_count - Optional Number
• role - Optional String
• state - Optional String
• state_changed_at - Optional String
Common Types
Section titled “Common Types”The following type definitions are used throughout this resource. See the full definition here rather than repeated inline.
Object Reference {#common-object-reference}
Section titled “Object Reference {#common-object-reference}”Object references establish a direct reference from one configuration object to another in F5 Distributed Cloud. References use the format tenant/namespace/name.
| Field | Type | Description |
|---|---|---|
name | String | Name of the referenced object |
namespace | String | Namespace containing the referenced object |
tenant | String | Tenant of the referenced object (system-managed) |
Transformers {#common-transformers}
Section titled “Transformers {#common-transformers}”Transformers apply transformations to input values before matching. Multiple transformers can be applied in order.
| Value | Description |
|---|---|
LOWER_CASE | Convert to lowercase |
UPPER_CASE | Convert to uppercase |
BASE64_DECODE | Decodebase64 content |
NORMALIZE_PATH | Normalize URL path |
REMOVE_WHITESPACE | Remove whitespace characters |
URL_DECODE | Decode URL-encoded characters |
TRIM_LEFT | Trim leading whitespace |
TRIM_RIGHT | Trim trailing whitespace |
TRIM | Trim both leading and trailing whitespace |
HTTP Methods {#common-http-methods}
Section titled “HTTP Methods {#common-http-methods}”HTTP methods used for request matching.
| Value | Description |
|---|---|
ANY | Match any HTTP method |
GET | HTTP GET request |
HEAD | HTTP HEAD request |
POST | HTTP POST request |
PUT | HTTP PUT request |
DELETE | HTTP DELETE request |
CONNECT | HTTP CONNECT request |
OPTIONS | HTTP OPTIONS request |
TRACE | HTTP TRACE request |
PATCH | HTTP PATCH request |
COPY | HTTP COPY request (WebDAV) |
TLS Fingerprints {#common-tls-fingerprints}
Section titled “TLS Fingerprints {#common-tls-fingerprints}”TLS fingerprint categories for malicious client detection.
| Value | Description |
|---|---|
TLS_FINGERPRINT_NONE | No fingerprint matching |
ANY_MALICIOUS_FINGERPRINT | Match any known malicious fingerprint |
ADWARE | Adware-associated fingerprints |
DRIDEX | Dridex malware fingerprints |
GOOTKIT | Gootkit malware fingerprints |
RANSOMWARE | Ransomware-associated fingerprints |
TRICKBOT | Trickbot malware fingerprints |
IP Threat Categories {#common-ip-threat-categories}
Section titled “IP Threat Categories {#common-ip-threat-categories}”IP address threat categories for security filtering.
| Value | Description |
|---|---|
SPAM_SOURCES | Known spam sources |
WINDOWS_EXPLOITS | Windows exploit sources |
WEB_ATTACKS | Web attack sources |
BOTNETS | Known botnet IPs |
SCANNERS | Network scanner IPs |
REPUTATION | Poor reputation IPs |
PHISHING | Phishing-related IPs |
PROXY | Anonymous proxy IPs |
MOBILE_THREATS | Mobile threat sources |
TOR_PROXY | Tor exit nodes |
DENIAL_OF_SERVICE | DoS attack sources |
NETWORK | Known bad network ranges |