Sign inSign up

vnxme/guard

By vnxme

•Updated 1 day ago

Image
Networking
0

2.0K

vnxme/guard repository overview

⁠BGP Guard

A BIRD⁠ route server that publishes the IP prefixes of popular services and countries over BGP, tagged with large communities. Your router peers with it, picks the groups it needs by community, and routes that traffic however you like, for example through a VPN tunnel.

  • Prefixes of 30+ services (Google, Microsoft, Amazon, Cloudflare, Telegram, …) grouped by the AS numbers they announce from
  • Prefixes of countries from the full ISO 3166-1 list, and groups of countries such as EU27
  • Updated automatically every 24 hours from ipverse⁠
  • A prefix that belongs to several groups is sent once, carrying the communities of all of them
  • A web looking glass to browse the routes

Source and full documentation: github.com/vnxme/guard⁠

⁠Quick start

docker run -d --name guard --restart unless-stopped \
  -p 80:80 -p 179:179 \
  -e BIRD_ASN=65000 -e BIRD_IP=203.0.113.10 \
  vnxme/guard

On start the container downloads the prefix lists and loads them into BIRD; until that finishes, peers receive no routes. Open http://<host>/ to see the looking glass.

Warning: BGP sessions are accepted from any address and any AS number other than your own. Peers cannot inject routes, but anyone who reaches port 179 receives the full feed. Restrict access with a firewall if the feed should not be public.

⁠Environment variables

VariableDefaultDescription
BIRD_ASN65000Local AS number (32-bit supported)
BIRD_IP1.2.3.4Router ID, in IPv4 address format

⁠Ports

PortPurpose
80Looking glass web interface
179BGP (passive, multihop eBGP)

⁠Peering

An IPv4 session receives IPv4 routes, an IPv6 session receives IPv6 routes. Graceful restart is enabled, so routers that support it keep the routes for up to 120 seconds while the container restarts. Example for a BIRD client that only takes Google and Russia prefixes:

protocol bgp guard {
	local as 65100;
	neighbor 203.0.113.10 as 65000;
	multihop;
	ipv4 {
		import where (65000, 10, 240) ~ bgp_large_community || (65000, 11, 643) ~ bgp_large_community;
		export none;
	};
}

⁠Communities

Routes carry large communities⁠ (ASN, tag, value). With the default BIRD_ASN=65000:

CommunityMeaning
65000:0:<AS number>Origin AS number, e.g. 65000:0:15169
65000:1:<country ID>Origin country, also when it comes from a group, e.g. 65000:1:276 Germany via EU27
65000:10:<AS group ID>AS group, e.g. 65000:10:240 Google, 65000:10:300 Microsoft
65000:11:<country group ID>Country or group of countries, e.g. 65000:11:643 Russia, 65000:11:1000 EU27
65000:10:100Custom static route

See the full list of AS groups⁠. Countries enabled by default: Belarus, Kazakhstan, Russia, Ukraine. Groups of countries (EU27, EEA, Schengen, CIS, Nordic, Baltic) are included but disabled.

⁠Customization

Mount your own group lists over the defaults:

docker run … \
  -v ./as.mapping.txt:/etc/bird/as.mapping.txt:ro \
  -v ./iso.mapping.txt:/etc/bird/iso.mapping.txt:ro \
  vnxme/guard

Start from the defaults: as.mapping.txt⁠, iso.mapping.txt⁠. The file format, custom static routes and upstream BGP feeds are described in the README⁠.

⁠Tags

TagBuilt from
latestThe newest release
1.2.3, 1.2, 1Release v1.2.3 (and the newest 1.2.x / 1.x)
mainThe newest commit on main
weeklyWeekly rebuild of main with updated base image and packages
sha-<commit>A specific commit

Platforms: linux/amd64, linux/arm64, linux/arm/v7, linux/386. Also available as ghcr.io/vnxme/guard.

Tag summary

Content type

Image

Digest

sha256:cbf1bd1df…

Size

33.9 MB

Last updated

1 day ago

docker pull vnxme/guard