From dc211bec430b0b4578d392222265615f1365bf5a Mon Sep 17 00:00:00 2001 From: David Naylor Date: Wed, 23 Sep 2026 17:32:33 -0700 Subject: [PATCH] [Cloudflare WAN, Magic Transit] Update BGP hold time Three changes to Cloudflare WAN/Magic Transit BGP over tunnels docs: - Cloudflare now advertises a hold time of 240s, not 90s - Customers must now configure a hold time of 30s or greater - Cloudflare recommends a hold time of at least 90s --- .../cloudflare-wan/configuration/how-to/configure-routes.mdx | 2 +- .../connectors/cloudflare-wan/reference/traffic-steering.mdx | 4 ++-- .../cloudflare-wan/configuration/how-to/configure-routes.mdx | 2 +- .../docs/cloudflare-wan/reference/traffic-steering.mdx | 4 ++-- .../configure-tunnels-routes/configure-routes.mdx | 2 +- src/content/docs/magic-transit/how-to/configure-routes.mdx | 2 +- src/content/docs/magic-transit/reference/traffic-steering.mdx | 4 ++-- 7 files changed, 10 insertions(+), 10 deletions(-) diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/configuration/how-to/configure-routes.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/configuration/how-to/configure-routes.mdx index 50206c0d758..4a299682a3f 100644 --- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/configuration/how-to/configure-routes.mdx +++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/configuration/how-to/configure-routes.mdx @@ -388,7 +388,7 @@ If you are configuring BGP peering for a tunnel (GRE or IPsec) you must be aware :::caution If the tunnel is to an Azure VPN gateway, the tunnel interface address must not be in the link-local range. Azure will not initiate BGP sessions to peers using link-local addresses. Use an RFC 1918 address for your tunnel interface address instead. ::: -- Hold time must be greater than 0 seconds (BGP `KEEPALIVE` messages are required). Cloudflare recommends at least 45 seconds. Cloudflare advertises a hold time of 90 seconds for GRE/IPsec tunnels. If you set a value greater than 90 seconds, the negotiated hold time will be 90 seconds, according to the standard way BGP has of negotiating hold times. +- Hold time must be 30 seconds or greater. Cloudflare recommends at least 90 seconds. Cloudflare advertises a hold time of 240 seconds, so if you set a value greater than 240 seconds, the negotiated hold time will be 240 seconds. - Connect retry time should be low (for example, five or 10 seconds). - Your CPE may advertise up to 5,000 prefixes on one BGP session. - MD5 authentication is optional. You can use a maximum of 80 characters. Supported characters include ``a-zA-Z0-9'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`` diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/reference/traffic-steering.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/reference/traffic-steering.mdx index f380b5cad1d..351b04da8ba 100644 --- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/reference/traffic-steering.mdx +++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/reference/traffic-steering.mdx @@ -577,11 +577,11 @@ Cloudflare uses the following timers, which are not configurable: | Setting | Description | | -------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| **Hold timer** | 240 seconds for CNI and 90 seconds for GRE and IPsec tunnels
(_To establish a session, Cloudflare compares its hold timer and the peer's hold timer, and uses the smaller of the two values to establish the BGP session._) | +| **Hold timer** | 240 seconds
_(To establish a session, Cloudflare compares its hold timer and the peer's hold timer, and uses the smaller of the two values to establish the BGP session.)_ | | **Keepalive timer** | One third of the hold timer. | | **Graceful restart** | 120 seconds (currently, only supported on CNI) | -- **Hold timer**: Specifies the maximum amount of time that a BGP peer waits to receive a keepalive, update, or notification message before declaring the BGP session down. Cloudflare uses the smaller of this default hold timer and that received from the peer in the open message. +- **Hold timer**: Specifies the maximum amount of time that a BGP peer waits to receive a KEEPALIVE, UPDATE, or NOTIFICATION message before declaring the BGP session down. Cloudflare uses the smaller of this default hold timer and that received from the peer in the OPEN message. - **Keepalive timer**: BGP systems exchange keepalive messages to determine whether the peer router is reachable. If keepalive messages are not received within the hold timer, the session is assumed to be down, indicating that the peer is no longer reachable at the BGP protocol level. - **Graceful restart timer**: Tracks how long a router waits for a peer to re-establish a BGP session after the peer initiates a graceful restart. If the peer does not reconnect within this time, the router declares the session down and removes stale routes. diff --git a/src/content/docs/cloudflare-wan/configuration/how-to/configure-routes.mdx b/src/content/docs/cloudflare-wan/configuration/how-to/configure-routes.mdx index 35acaa7a2e8..df043508386 100644 --- a/src/content/docs/cloudflare-wan/configuration/how-to/configure-routes.mdx +++ b/src/content/docs/cloudflare-wan/configuration/how-to/configure-routes.mdx @@ -407,7 +407,7 @@ If you are configuring BGP peering for a tunnel (GRE or IPsec) you must be aware :::caution If the tunnel is to an Azure VPN gateway, the tunnel interface address must not be in the link-local range. Azure will not initiate BGP sessions to peers using link-local addresses. Use an RFC 1918 address for your tunnel interface address instead. ::: -- Hold time must be greater than 0 seconds (BGP `KEEPALIVE` messages are required). Cloudflare recommends at least 45 seconds. Cloudflare advertises a hold time of 90 seconds for GRE/IPsec tunnels. If you set a value greater than 90 seconds, the negotiated hold time will be 90 seconds, according to the standard way BGP has of negotiating hold times. +- Hold time must be 30 seconds or greater. Cloudflare recommends at least 90 seconds. Cloudflare advertises a hold time of 240 seconds, so if you set a value greater than 240 seconds, the negotiated hold time will be 240 seconds. - Connect retry time should be low (for example, five or 10 seconds). - Your CPE may advertise up to 5,000 prefixes on one BGP session. - MD5 authentication is optional. You can use a maximum of 80 characters. Supported characters include ``a-zA-Z0-9'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`` diff --git a/src/content/docs/cloudflare-wan/reference/traffic-steering.mdx b/src/content/docs/cloudflare-wan/reference/traffic-steering.mdx index 3b121a8cbf2..cda8839452d 100644 --- a/src/content/docs/cloudflare-wan/reference/traffic-steering.mdx +++ b/src/content/docs/cloudflare-wan/reference/traffic-steering.mdx @@ -578,11 +578,11 @@ Cloudflare uses the following timers, which are not configurable: | Setting | Description | | -------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| **Hold timer** | 240 seconds for CNI and 90 seconds for GRE and IPsec tunnels
(_To establish a session, Cloudflare compares its hold timer and the peer's hold timer, and uses the smaller of the two values to establish the BGP session._) | +| **Hold timer** | 240 seconds
_(To establish a session, Cloudflare compares its hold timer and the peer's hold timer, and uses the smaller of the two values to establish the BGP session.)_ | | **Keepalive timer** | One third of the hold timer. | | **Graceful restart** | 120 seconds (currently, only supported on CNI) | -- **Hold timer**: Specifies the maximum amount of time that a BGP peer waits to receive a keepalive, update, or notification message before declaring the BGP session down. Cloudflare uses the smaller of this default hold timer and that received from the peer in the open message. +- **Hold timer**: Specifies the maximum amount of time that a BGP peer waits to receive a KEEPALIVE, UPDATE, or NOTIFICATION message before declaring the BGP session down. Cloudflare uses the smaller of this default hold timer and that received from the peer in the OPEN message. - **Keepalive timer**: BGP systems exchange keepalive messages to determine whether the peer router is reachable. If keepalive messages are not received within the hold timer, the session is assumed to be down, indicating that the peer is no longer reachable at the BGP protocol level. - **Graceful restart timer**: Tracks how long a router waits for a peer to re-establish a BGP session after the peer initiates a graceful restart. If the peer does not reconnect within this time, the router declares the session down and removes stale routes. diff --git a/src/content/docs/learning-paths/data-center-protection/configure-tunnels-routes/configure-routes.mdx b/src/content/docs/learning-paths/data-center-protection/configure-tunnels-routes/configure-routes.mdx index 83f27cc9023..bf377e96b2a 100644 --- a/src/content/docs/learning-paths/data-center-protection/configure-tunnels-routes/configure-routes.mdx +++ b/src/content/docs/learning-paths/data-center-protection/configure-tunnels-routes/configure-routes.mdx @@ -353,7 +353,7 @@ If you are configuring BGP peering for a tunnel (GRE or IPsec) you must be aware :::caution If the tunnel is to an Azure VPN gateway, the tunnel interface address must not be in the link-local range. Azure will not initiate BGP sessions to peers using link-local addresses. Use an RFC 1918 address for your tunnel interface address instead. ::: -- Hold time must be greater than 0 seconds (BGP `KEEPALIVE` messages are required). Cloudflare recommends at least 45 seconds. Cloudflare advertises a hold time of 90 seconds for GRE/IPsec tunnels. If you set a value greater than 90 seconds, the negotiated hold time will be 90 seconds, according to the standard way BGP has of negotiating hold times. +- Hold time must be 30 seconds or greater. Cloudflare recommends at least 90 seconds. Cloudflare advertises a hold time of 240 seconds, so if you set a value greater than 240 seconds, the negotiated hold time will be 240 seconds. - Connect retry time should be low (for example, five or 10 seconds). - Your CPE may advertise up to 5,000 prefixes on one BGP session. - MD5 authentication is optional. You can use a maximum of 80 characters. Supported characters include ``a-zA-Z0-9'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`` diff --git a/src/content/docs/magic-transit/how-to/configure-routes.mdx b/src/content/docs/magic-transit/how-to/configure-routes.mdx index df72e817499..98d49b151bc 100644 --- a/src/content/docs/magic-transit/how-to/configure-routes.mdx +++ b/src/content/docs/magic-transit/how-to/configure-routes.mdx @@ -359,7 +359,7 @@ If you are configuring BGP peering for a tunnel (GRE or IPsec) you must be aware :::caution If the tunnel is to an Azure VPN gateway, the tunnel interface address must not be in the link-local range. Azure will not initiate BGP sessions to peers using link-local addresses. Use an RFC 1918 address for your tunnel interface address instead. ::: -- Hold time must be greater than 0 seconds (BGP `KEEPALIVE` messages are required). Cloudflare recommends at least 45 seconds. Cloudflare advertises a hold time of 90 seconds for GRE/IPsec tunnels. If you set a value greater than 90 seconds, the negotiated hold time will be 90 seconds, according to the standard way BGP has of negotiating hold times. +- Hold time must be 30 seconds or greater. Cloudflare recommends at least 90 seconds. Cloudflare advertises a hold time of 240 seconds, so if you set a value greater than 240 seconds, the negotiated hold time will be 240 seconds. - Connect retry time should be low (for example, five or 10 seconds). - Your CPE may advertise up to 5,000 prefixes on one BGP session. - MD5 authentication is optional. You can use a maximum of 80 characters. Supported characters include ``a-zA-Z0-9'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`` diff --git a/src/content/docs/magic-transit/reference/traffic-steering.mdx b/src/content/docs/magic-transit/reference/traffic-steering.mdx index 55ec8c219b3..8547edae43e 100644 --- a/src/content/docs/magic-transit/reference/traffic-steering.mdx +++ b/src/content/docs/magic-transit/reference/traffic-steering.mdx @@ -476,11 +476,11 @@ Cloudflare uses the following timers, which are not configurable: | Setting | Description | | -------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| **Hold timer** | 240 seconds for CNI and 90 seconds for GRE and IPsec tunnels
(_To establish a session, Cloudflare compares its hold timer and the peer's hold timer, and uses the smaller of the two values to establish the BGP session._) | +| **Hold timer** | 240 seconds
_(To establish a session, Cloudflare compares its hold timer and the peer's hold timer, and uses the smaller of the two values to establish the BGP session.)_ | | **Keepalive timer** | One third of the hold timer. | | **Graceful restart** | 120 seconds (currently, only supported on CNI) | -- **Hold timer**: Specifies the maximum amount of time that a BGP peer waits to receive a keepalive, update, or notification message before declaring the BGP session down. Cloudflare uses the smaller of this default hold timer and that received from the peer in the open message. +- **Hold timer**: Specifies the maximum amount of time that a BGP peer waits to receive a KEEPALIVE, UPDATE, or NOTIFICATION message before declaring the BGP session down. Cloudflare uses the smaller of this default hold timer and that received from the peer in the OPEN message. - **Keepalive timer**: BGP systems exchange keepalive messages to determine whether the peer router is reachable. If keepalive messages are not received within the hold timer, the session is assumed to be down, indicating that the peer is no longer reachable at the BGP protocol level. - **Graceful restart timer**: Tracks how long a router waits for a peer to re-establish a BGP session after the peer initiates a graceful restart. If the peer does not reconnect within this time, the router declares the session down and removes stale routes.