Getting started
A few prerequisites are needed before you can begin setting up a Threat Protection Routed DSR service to protect your network.
Required
-
This setup requires you to have your own ASN with at least one public /24 and control of your BGP.
-
There must be matching Traffic Configurations in the portal, and an announcement must be made via BGP. We will never create and announce prefixes; we only filter the ones we receive from your routers.
-
Ensure you have designated a contact person for the onboarding process. This person will be the primary contact between the Threat Protection onboarding team and your organization. This could be the primary administrator. We also recommend having a representative from your networking team during the onboarding meeting.
Information we need about your network:
- Tunnel endpoints, preferably two
- Your BGP AS
- If you have an AS-SET you want to use for prefix filtering
- If you want to run BFD and/or MD5 for BGP
After we have received this information, we will provide you with our GRE tunnel endpoints, AS number, and link network.
Recommended
- If you would like to use the Routed DSR services over GRE, we recommend establishing a GRE tunnel and BGP peering with two TPCs for redundancy. All TPCs will still announce and clean your prefixes.