skip to content

BGP exchanges routes over a TCP connection while OSPF runs directly over IP; at which OSI layer does each routing protocol belong, and why?

level: seniorimportance: nice to knowfreq 22%

answer

  1. carrier versus purpose
  2. control plane feeds data plane
  3. what TCP does for BGP
  4. what a session reset costs

basics

~20 s

By carrier, BGP is an application on TCP and OSPF is carried directly by IP; by purpose, both are layer 3 control-plane protocols. The strong answer separates the routing protocol from the layer 3 forwarding it feeds.

solid answer

~40 s

It depends on the criterion, and I'd say so. By **carrier**, BGP is application-layer payload on a TCP connection, and OSPF is carried directly by IP the way ICMP is; RFC 8200 even lists "routing protocols such as OSPF" as an upper layer to IPv6. By **purpose**, both belong to layer 3, because they build the routing tables that IP forwarding uses. The clean resolution is the **control plane / data plane** split: forwarding is layer 3 data-plane work, and routing protocols are control-plane applications that program it. The carrier still matters: BGP gets reliability and ordering from TCP, but also inherits TCP's failure modes. RFC 5961 notes that BGP relies on a persistent TCP session and that resetting it forces routing tables to be rebuilt, with route flapping.

go deeper

for a junior

Know that routers forward at layer 3 and that routing protocols such as BGP and OSPF exchange the routes they use. That BGP runs over TCP is worth remembering.

for a middle

Separate carrier from purpose: BGP rides TCP, OSPF rides IP, and both serve layer 3. Be able to say which criterion your answer uses.

for a senior

Explain the control plane and data plane split, and what BGP's TCP carrier means in operation: inherited reliability, and a reset that forces routes to be relearned.

for a principal

Use routing protocols to argue that the carrier is an engineering choice with consequences for reliability and attack surface, and weigh those when designing a new control protocol.

## Why routing protocols are a boundary case **IP forwarding** is the textbook layer 3 job: a router looks up a datagram's destination address in its forwarding table and sends it to the next hop. **Routing protocols** are what fill that table. They exchange reachability information between routers and compute paths. So they serve layer 3, but they are not themselves forwarding, and each one travels in some carrier: - **BGP** (RFC 4271) runs over a **TCP** connection between two peers. - **OSPF** is carried **directly by IP**; RFC 8200 §2 lists "routing protocols such as OSPF" alongside TCP, UDP and ICMP as protocols immediately above IPv6. Ask "which layer is BGP?" and you get two honest answers. ## Two criteria, two answers | Criterion | BGP | OSPF | |---|---|---| | Carrier: what encloses it | TCP, so application-layer payload | IP directly, like ICMP | | Purpose: what it serves | layer 3 routing | layer 3 routing | | Placement by carrier | layer 7 (payload of TCP) | directly above IP, like ICMP, so usually filed at layer 3 | | Placement by purpose | layer 3 control plane | layer 3 control plane | Neither column is wrong. The interviewer wants to see that you know both and can say which one you are using. The carrier also shapes who can talk to whom. Because BGP rides TCP, which rides IP, two BGP peers need only IP reachability between them; they do not have to share a link, and sessions between routers several hops apart are normal. OSPF, carried directly by IP, exchanges its messages mainly with routers on directly attached links. The carrier is part of each protocol's design, not an accident. ## The resolution: control plane versus data plane - The **data plane** moves user traffic: receive a datagram, look up the destination, decrement the TTL, forward. This is unambiguously layer 3. - The **control plane** decides what the data plane should do. Routing protocols live here. They are programs running on routers that talk to other routers using whatever carrier suits them, and their output is a layer 3 forwarding table. With that split, "BGP is an application-layer protocol that controls layer 3" is a precise, defensible sentence. It also explains why the same router can run BGP over TCP and OSPF directly over IP without contradiction. ## What the carrier choice costs and buys The carrier is not trivia; it decides what the routing protocol must build for itself. 1. **BGP gets transport services for free.** Because it runs on TCP, BGP's messages arrive reliably and in order; BGP does not implement its own retransmission or sequencing. 2. **BGP inherits TCP's failure modes.** RFC 5961 §1.3 singles out BGP: it "relies on a persistent TCP session between BGP peers", and that resetting the connection can make routes unavailable for a period "due to the need to rebuild routing tables and route flapping". A single forged reset against a long-lived TCP connection therefore hurts routing far more than it hurts a short web request. 3. **BGP can borrow TCP's protections.** The same section notes that the TCP MD5 signature option (RFC 2385, since obsoleted by the TCP Authentication Option) makes those reset attacks effectively impossible for applications such as BGP that can use it. 4. **OSPF has to cope with IP's guarantees.** IP provides "no end-to-end delivery guarantees" (RFC 1122 §1.1.3), so any reliability OSPF needs for its own updates it must provide itself. ## A related case: configuring layer 3 from above Address configuration shows the same pattern. BOOTP, DHCP's predecessor, lets a host learn its IP address, and RFC 1123 §6.2.2.1 says the host "broadcasts a BOOTP request using UDP". RFC 1122 lists BOOTP among application-layer support protocols. So a protocol whose whole purpose is layer 3 configuration is, by carrier, an application riding on UDP. The DHCP mechanics belong to DHCP's own material. ## How to answer 1. Name both criteria before giving a layer. 2. Place forwarding at layer 3 and routing protocols in the control plane that programs it. 3. Show the carrier matters with BGP's dependence on a persistent TCP session. 4. Mention DHCP or BOOTP over UDP if asked for another example.

  • Why does a TCP reset matter so much more to a BGP session than to a short HTTP exchange?
    A BGP session is long-lived and carries the routes learned from that peer. RFC 5961 notes that resetting it forces routing tables to be rebuilt and causes route flapping, so traffic to those prefixes can be disrupted and the churn spreads to other routers. A short HTTP exchange simply retries.
  • Where does DHCP fit in the same argument?
    Its purpose is layer 3, since it hands a host its IP configuration, but its carrier is UDP; RFC 1123 describes BOOTP, its predecessor, broadcasting requests over UDP. By carrier it is an application protocol that configures layer 3, just as BGP is an application that programs it.

saying these in an interview costs you the question

  • BGP is layer 4 because it runs on TCP.
  • BGP forwards user traffic itself along the paths it learns.
  • BGP implements its own retransmission because routing is critical.
  • OSPF runs over TCP like BGP does.
  • Forwarding and routing are the same function, so they share one layer.