OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 23.7 Legacy Series »
  • Updating BGP ASN List?
« previous next »
  • Print
Pages: [1]

Author Topic: Updating BGP ASN List?  (Read 1162 times)

NateroniPizza

  • Newbie
  • *
  • Posts: 6
  • Karma: 0
    • View Profile
Updating BGP ASN List?
« on: December 08, 2023, 04:20:08 pm »
Hello, all,

I had a situation where my BGP ASN aliases would not update. I'd replaced a failing SSD, reinstalled (got 23.7.9 on there now), and imported the configuration. Unfortunately, my ISP had decided that would be a good time to bring our internet connection down for maintenance, so OPNSense was unable to download the asn.gz file (the logs showed a DNS resolution error when trying to do so).

When the internet came back up, I couldn't get my BGP-based aliases to update. I tried rebooting, I tried deleting and manually re-creating the aliases, I tried setting up a Cron job to update aliases, and I tried flushing the aliases under Diagnostics>Aliases. Nothing would get it to update. Finally, since I knew that it would re-download the asn.gz file after a configuration restore, I just restored to the configuration again - and success.

My question now is how does one manually trigger the update for this file? (re-downloading https://rulesets.opnsense.org/alias/asn.gz) And does it do it automatically periodically download an updated version? I suspect that the alias updates don't actually tie into the mechanism for downloading the asn.gz file, so they're just looking at the old (or in my case, non-existent) asn.gz file. Given I couldn't manually trigger an update, I'm concerned that it may not be automatically updating either.

Thank you
« Last Edit: December 08, 2023, 04:23:18 pm by NateroniPizza »
Logged

meyergru

  • Hero Member
  • *****
  • Posts: 1757
  • Karma: 171
  • IT Aficionado
    • View Profile
    • congenio
Re: Updating BGP ASN List?
« Reply #1 on: December 08, 2023, 04:42:35 pm »
The time-to-live for the ASN file is 1 day, but that depends on how often the update is called.

I use the cron job for that called "Update and reload firewall aliases". The timestamp for /usr/local/share/bgp/asn.csv shows Dec 8, 10:32 am, so this seems to work.
Logged
Intel N100, 4 x I226-V, 16 GByte, 256 GByte NVME, ZTE F6005

1100 down / 440 up, Bufferbloat A+

NateroniPizza

  • Newbie
  • *
  • Posts: 6
  • Karma: 0
    • View Profile
Re: Updating BGP ASN List?
« Reply #2 on: December 09, 2023, 04:57:56 am »
Quote from: meyergru on December 08, 2023, 04:42:35 pm
The time-to-live for the ASN file is 1 day, but that depends on how often the update is called.

I use the cron job for that called "Update and reload firewall aliases". The timestamp for /usr/local/share/bgp/asn.csv shows Dec 8, 10:32 am, so this seems to work.

Thanks for the response. That was the cron job I was using to try and force it to re-download, but it did not seem to work. Note that I didn't know where that file was located, so it may have been something further down the line failing (I was just checking the logs, which weren't showing anything related to the BGP/ASN stuff, and the contents of the aliases). I'll keep an eye on that file and make sure it's updating successfully at this point.
Logged

zszs73

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: Updating BGP ASN List?
« Reply #3 on: November 09, 2024, 11:21:05 am »
Hi,
I know that this is an old topic but this info might help someone.
Simply changing and appying the alias to ASN 0 (non-existent) will trigger the update. Changing it back to the right ASN number the update will be triggered again with the correct result.
All aliases are in separate files under
Code: [Select]
ls -al /var/db/aliastables



Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 23.7 Legacy Series »
  • Updating BGP ASN List?
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2