Esse artigo foi homologado no equipamento CCR2116-12G-4S+, na versão v7.18.2, o uso em uma versão diferente pode não resultar da mesma forma.
Alterar o exemplo para os prefixos da empresa.
/ip/firewall/address-list/add address=99.70.0.0/22 list=BGP-NETWORK comment=!::PREFIXO-EMPRESA
/ip/firewall/address-list/add address=99.70.0.0/23 list=BGP-NETWORK comment=!::PREFIXO-EMPRESA
/ip/firewall/address-list/add address=99.70.2.0/23 list=BGP-NETWORK comment=!::PREFIXO-EMPRESA
/ip/firewall/address-list/add address=99.70.0.0/24 list=BGP-NETWORK comment=!::PREFIXO-EMPRESA
/ip/firewall/address-list/add address=99.70.1.0/24 list=BGP-NETWORK comment=!::PREFIXO-EMPRESA
/ip/firewall/address-list/add address=99.70.2.0/24 list=BGP-NETWORK comment=!::PREFIXO-EMPRESA
/ip/firewall/address-list/add address=99.70.3.0/24 list=BGP-NETWORK comment=!::PREFIXO-EMPRESA
#
/ipv6/firewall/address-list/add address=99:70::/32 list=BGP-NETWORK comment=!::PREFIXO-EMPRESA
/ipv6/firewall/address-list/add address=99:70::/33 list=BGP-NETWORK comment=!::PREFIXO-EMPRESA
/ipv6/firewall/address-list/add address=99:70:8000::/33 list=BGP-NETWORK comment=!::PREFIXO-EMPRESA
/ipv6/firewall/address-list/add address=99:70::/34 list=BGP-NETWORK comment=!::PREFIXO-EMPRESA
/ipv6/firewall/address-list/add address=99:70:4000::/34 list=BGP-NETWORK comment=!::PREFIXO-EMPRESA
/ipv6/firewall/address-list/add address=99:70:8000::/34 list=BGP-NETWORK comment=!::PREFIXO-EMPRESA
/ipv6/firewall/address-list/add address=99:70:c000::/34 list=BGP-NETWORK comment=!::PREFIXO-EMPRESA
#
/ip/route/add blackhole comment=!::PREFIXO-EMPRESA disabled=no dst-address=99.70.0.0/22
/ip/route/add blackhole comment=!::PREFIXO-EMPRESA disabled=no dst-address=99.70.0.0/23
/ip/route/add blackhole comment=!::PREFIXO-EMPRESA disabled=no dst-address=99.70.2.0/23
/ip/route/add blackhole comment=!::PREFIXO-EMPRESA disabled=no dst-address=99.70.0.0/24
/ip/route/add blackhole comment=!::PREFIXO-EMPRESA disabled=no dst-address=99.70.1.0/24
/ip/route/add blackhole comment=!::PREFIXO-EMPRESA disabled=no dst-address=99.70.2.0/24
/ip/route/add blackhole comment=!::PREFIXO-EMPRESA disabled=no dst-address=99.70.3.0/24
#
/ipv6/route/add blackhole comment=!::PREFIXO-EMPRESA disabled=no dst-address=99:70::/32
/ipv6/route/add blackhole comment=!::PREFIXO-EMPRESA disabled=no dst-address=99:70::/33
/ipv6/route/add blackhole comment=!::PREFIXO-EMPRESA disabled=no dst-address=99:70:8000::/33
/ipv6/route/add blackhole comment=!::PREFIXO-EMPRESA disabled=no dst-address=99:70::/34
/ipv6/route/add blackhole comment=!::PREFIXO-EMPRESA disabled=no dst-address=99:70:4000::/34
/ipv6/route/add blackhole comment=!::PREFIXO-EMPRESA disabled=no dst-address=99:70:8000::/34
/ipv6/route/add blackhole comment=!::PREFIXO-EMPRESA disabled=no dst-address=99:70:c000::/34
#
Configurar para aceitar somente rota default.
/ip/firewall/address-list/add address=0.0.0.0/0 list=NLRI comment=!::DEFAULT
/ipv6/firewall/address-list/add address=::/0 list=NLRI comment=!::DEFAULT
#
Utilizar o endereço da loopback pública como router-id.
Alterar o atributo as para o ASN da empresa.
/routing/bgp/template/set default \
as=65001 \
hold-time=30s \
#input.accept-nlri=NLRI \
.affinity=alone \
keepalive-time=3s \
multihop=yes \
output.affinity=alone \
.network=BGP-NETWORK \
router-id=99.70.3.254 \
routing-table=main \
disabled=yes \
#