skip to content

BGP

BGP connects autonomous systems over TCP sessions, carries policy in path attributes and picks routes by an ordered tie-break list. Interviewers use it for internet routing, anycast and outages.

on this pageshow

explore

questions

page 1 of 2

In BGP, what is an autonomous system, and what does its AS number do in the routes BGP exchanges?

level: juniorimportance: must knowfreq 55%

answer

  1. a unit of policy, not of ownership
  2. one coherent picture to outsiders
  3. My Autonomous System in the OPEN
  4. AS_PATH lists ASes, not routers
  5. your own number in the path

basics

~20 s

An autonomous system is a network, or group of IP prefixes, run under one clearly defined routing policy. Its AS number identifies it to BGP peers and is prepended to AS_PATH, which BGP uses to compare paths and reject loops.

solid answer

~50 s

RFC 1930 defines an AS as a connected group of IP prefixes, run by one or more operators, with a *single, clearly defined routing policy*; RFC 4271 adds that however many IGPs run inside it, the AS presents one coherent picture of what is reachable through it. BGP treats the AS as its routing unit. A speaker states its ASN in the OPEN message's `My Autonomous System` field, and each AS prepends its number to `AS_PATH` when it advertises a route to an external peer, so a route records the ASes it crossed, not the routers. That list does two jobs: a shorter `AS_PATH` is one of BGP's tie-breakers, and a speaker that finds its own ASN in a received `AS_PATH` excludes the route as a loop. Comparing the peer's ASN with your own also tells you whether a session is external or internal.

go deeper

for a junior

Recall the one-line definition: one routing policy, one number. Say that BGP's AS_PATH lists autonomous systems, not routers.

for a middle

Explain where the ASN appears: the OPEN message, the eBGP/iBGP distinction, AS_PATH prepending and the loop check that drops a route carrying your own number.

for a senior

Show you know policy draws the border: when a site needs no AS, when it needs one, and what goes wrong when two sites of one AS meet only through a provider.

for a principal

Discuss how an organisation should map its routing policies onto ASes, and the cost of splitting or merging ASes once peers and filters are built around the numbers.

## What an autonomous system is An **autonomous system (AS)** is the unit BGP routes between. RFC 4271, the BGP-4 specification, gives the *classic* definition: a set of routers under a single technical administration, using an interior gateway protocol (IGP) and common metrics to route packets inside the AS, and an inter-AS protocol to route packets to other ASes. It then notes that many ASes now run several IGPs and several sets of metrics, and that what still makes them one AS is that the administration *appears to other ASes to have a single coherent interior routing plan* and presents a consistent picture of the destinations reachable through it. RFC 1930 (BCP 6) restates this more sharply: - an AS is **a connected group of one or more IP prefixes run by one or more network operators which has a single and clearly defined routing policy**; - "routing policy" means how routing decisions are made between ASes: which prefixes an AS announces to a neighbour, and which announcements it accepts; - **without exception, an AS must have only one routing policy** — it is not a convenient label for everything one organisation owns. ## Policy, not ownership, draws the border Because the AS is the unit of policy, the org chart does not decide how many ASes you have: - a site connected to a single provider shares that provider's policy, so RFC 1930 says it needs no AS of its own — its prefixes belong in the provider's AS; - a network connected to two providers has a policy of its own (which provider to prefer, what to announce where), so it needs its own AS; - one organisation may run more than one AS if parts of it genuinely follow different policies, though RFC 1930 calls this rare. Each AS has a number, the **ASN**, which RFC 1930 describes as both the identifier of the AS and the value used when exchanging routing information between neighbouring ASes. ## What the AS number does on the wire | Where the ASN appears | What BGP does with it | |---|---| | OPEN message, `My Autonomous System` (a 2-octet field) | The peer checks it against the ASN it expects; an unacceptable value is answered with a NOTIFICATION whose error subcode is **Bad Peer AS**. A 4-octet ASN travels in a capability instead (RFC 6793). | | Session classification | A peer in a different AS is an *external* peer (eBGP); a peer in the same AS is an *internal* peer (iBGP). | | `AS_PATH` attribute | When a route is advertised to an external peer, the advertising AS prepends its own number, so the path lists every AS the announcement crossed, newest first. | | Loop detection | RFC 4271 §9.1.2: if the local ASN already appears in a received `AS_PATH`, the route is excluded from the decision process. | | Path comparison | Among routes of equal preference, the one with the shorter `AS_PATH` wins a tie-break (the full decision order is its own subject). | Two details of origination matter. A speaker that originates a route sends an `AS_PATH` holding **one `AS_SEQUENCE` segment containing only its own ASN** to external peers, and an **empty** `AS_PATH` to internal peers, because no AS boundary has been crossed yet. ## A worked trace Using documentation ASNs (RFC 5398) and a documentation prefix: 1. Enterprise AS 64500 originates `203.0.113.0/24` to its provider AS 64496 with `AS_PATH` = `64500`. 2. AS 64496 advertises it to AS 64497, prepending itself: `64496 64500`. 3. AS 64497 advertises it to its own neighbours as `64497 64496 64500`. 4. If that announcement ever comes back to AS 64500, the enterprise finds `64500` in the path and discards the route: an AS loop. Inside each AS, an IGP still decides which router and link a packet uses; BGP's view stays at the level of "which sequence of ASes leads to this prefix". ## Common misreadings - **"An AS is a company's network."** It is a policy domain; a company may have none, one or several. - **"AS_PATH records the routers a route passed."** It records ASes only; ten routers inside one AS add one entry. - **"Seeing your own ASN just makes a path longer."** It makes the route ineligible. Accepting it anyway is an implementation option that RFC 4271 places outside its scope and RFC 7454 advises operators against enabling. - **"Every Internet-connected site needs an ASN."** A single-homed site does not.

  • Does an organisation need one autonomous system per site or per business unit?
    No. RFC 1930 ties an AS to routing policy, not to the org chart: prefixes that share one policy belong in one AS, and a site single-homed to one provider shares that provider's policy, so it needs no AS of its own. A separate AS is justified by a genuinely different policy, multihoming to several providers being the usual case.
  • If BGP rejects routes containing its own AS number, how do two sites of one AS that meet only through a provider learn each other's prefixes?
    By default they cannot: each site drops the other's routes because the shared ASN is already in AS_PATH. Options are giving the sites separate ASNs, using a default route toward the provider, or an implementation feature that accepts the local ASN in the path. RFC 4271 leaves that acceptance outside its scope, and RFC 7454 advises against overriding the default without a reason.

AS_PATH works like the exit stamps in a traveller's passport: every country stamps it on the way out, and a border officer who finds his own country's stamp already there turns the traveller away as someone who has gone round in a circle.

saying these in an interview costs you the question

  • An autonomous system is simply every network one company owns.
  • AS_PATH lists every router the route passed through.
  • Every site connected to the Internet needs its own AS number.
  • An AS must run exactly one IGP inside it.
  • Finding your own ASN in AS_PATH only makes the path longer, not invalid.
open as a page

How does a BGP speaker use the AS_PATH attribute to keep routes from looping between autonomous systems?

level: juniorimportance: must knowfreq 45%

basics

~20 s

Each AS adds its own number to AS_PATH when advertising a route to an external peer. A BGP speaker that finds its own AS number in a received AS_PATH treats the route as a loop and does not use it.

open as a page

Why does BGP run its sessions over TCP port 179, and what are the four message types a BGP-4 session exchanges?

level: juniorimportance: must knowfreq 46%

basics

~20 s

BGP runs over TCP port 179 so TCP supplies retransmission, ordering and sequencing for it. A BGP-4 session uses four messages: OPEN starts it, UPDATE advertises and withdraws routes, NOTIFICATION reports an error and closes it, KEEPALIVE shows the peer is alive.

open as a page

In BGP, what distinguishes an eBGP session from an iBGP session, and how does each one treat the routes it passes on?

level: juniorimportance: must knowfreq 55%

basics

~20 s

eBGP joins speakers in different autonomous systems, iBGP speakers in the same one. eBGP prepends the sender's AS number and normally rewrites NEXT_HOP; iBGP changes neither and, outside route reflection, does not relay one iBGP peer's routes to another.

open as a page

What makes a BGP autonomous system stub, multihomed or transit, and when does an enterprise need an AS number of its own?

level: middleimportance: must knowfreq 45%

basics

~20 s

A stub AS has one neighbouring AS; a multihomed AS has several but, as an enterprise, carries only its own traffic; a transit AS carries traffic between other ASes. An enterprise mainly needs its own ASN to multihome.

open as a page

When a BGP speaker holds several paths to the same prefix, in what order does it compare them to select one best path?

level: middleimportance: must knowfreq 45%

basics

~20 s

Unusable paths go first (unresolvable NEXT_HOP, own AS in AS_PATH). Then: highest LOCAL_PREF, shortest AS_PATH, lowest ORIGIN, lowest MED from one neighbouring AS, eBGP over iBGP, lowest IGP cost to NEXT_HOP, lowest BGP Identifier, lowest peer address.

open as a page

What are BGP's four path-attribute categories, and how does each decide whether a speaker must recognise, send and pass on an attribute?

level: middleimportance: must knowfreq 40%

basics

~20 s

Well-known mandatory attributes (ORIGIN, AS_PATH, NEXT_HOP) are understood by every speaker and carried on every route; well-known discretionary ones (LOCAL_PREF, ATOMIC_AGGREGATE) are understood but sent only when relevant; unrecognised optional transitive ones are passed on, unrecognised non-transitive ones dropped.

open as a page

In BGP, what do import and export policies decide on an eBGP session, and what does RFC 8212 require when none is configured?

level: middleimportance: must knowfreq 42%

basics

~20 s

A BGP import policy decides which routes from a neighbour are eligible, with what attributes; an export policy decides which selected routes are announced to it. RFC 8212 makes an eBGP session without explicit policy accept and announce nothing.

open as a page

In BGP, what is the difference between a prefix hijack and a route leak, and why do BGP speakers accept either one?

level: middleimportance: must knowfreq 38%

basics

~20 s

A prefix hijack announces address space, or a path to it, that the announcer has no right to claim; a route leak passes a genuine route beyond its intended scope. Base BGP verifies neither, so neighbours believe both.

open as a page

Which states does the BGP finite state machine pass through from Idle to Established, and what moves a session from each to the next?

level: middleimportance: must knowfreq 40%

basics

~20 s

A BGP session goes Idle, Connect (TCP attempt), OpenSent (TCP up, OPEN sent), OpenConfirm (peer's OPEN accepted, KEEPALIVE sent) and Established (peer's KEEPALIVE received). Active means it is waiting for a TCP connection; most errors return it to Idle.

open as a page

Why does a new BGP session sit in the Active state and never reach Established, and what does Active actually mean?

level: middleimportance: must knowfreq 38%

basics

~20 s

In BGP, Active means the speaker has no TCP connection to its peer yet: it listens, and redials when ConnectRetryTimer expires. Stuck there means TCP never completes: no route, wrong peer or source address, port 179 filtered, or mismatched authentication.

open as a page

Why may a BGP speaker not pass a route learned over iBGP to another iBGP peer, and why does that force a full mesh?

level: middleimportance: must knowfreq 42%

basics

~20 s

Inside one AS the AS_PATH is never changed, so BGP's loop check cannot catch a route circulating between internal peers. RFC 4271 therefore forbids relaying iBGP-learned routes to iBGP peers, so in base BGP every speaker must peer with every other one: n(n-1)/2 sessions.

open as a page

In a multihomed AS running BGP, why does LOCAL_PREF control traffic leaving the AS while MED and AS_PATH length only influence traffic entering it?

level: seniorimportance: must knowfreq 35%

basics

~20 s

Outbound traffic follows your own routers' decision, where LOCAL_PREF is compared first. Inbound traffic follows other ASes' decisions: MED and a longer AS_PATH are hints they weigh only after their own LOCAL_PREF, and MED only among routes from your AS.

open as a page

A BGP transit provider is onboarding a customer AS that holds one /22; what should the import filter on that eBGP session accept and reject?

level: seniorimportance: must knowfreq 30%

basics

~20 s

Accept only the customer's verified /22 and its agreed more-specifics down to /24, on AS paths made solely of the customer's ASN; reject everything else, drop RPKI-invalid routes, and cap the session with a maximum-prefix limit.

open as a page

What does RPKI route origin validation prove about a BGP route, and why does a forged-origin hijack still pass it?

level: seniorimportance: must knowfreq 30%

basics

~20 s

Origin validation proves only that a route's origin AS, the rightmost AS in its path, is authorized by a ROA to originate that prefix at that length. Nothing checks the rest of the path, so a hijacker who appends the real origin passes.

open as a page

Why does a BGP speaker not simply pick the path with the fewest autonomous systems, the way an IGP picks the lowest metric?

level: juniorimportance: should knowfreq 38%

basics

~20 s

BGP's decision is policy first: a route's degree of preference, carried as LOCAL_PREF inside an AS, is compared before AS_PATH length. And AS_PATH length counts networks, not routers, bandwidth or delay, so it is only a rough tie-breaker.

open as a page

How do 4-byte AS numbers work in BGP, and how does a 4-byte-ASN speaker peer with an old 2-byte-only speaker?

level: middleimportance: should knowfreq 22%

basics

~20 s

RFC 6793 widens AS numbers from 16 to 32 bits, negotiated by a BGP capability. Toward a speaker without it, any ASN above 65535 becomes AS_TRANS (23456) in 2-byte fields, and the true path rides in the optional transitive AS4_PATH.

open as a page

Which AS numbers are reserved for private use in BGP, and what must happen to them before routes reach the public Internet?

level: middleimportance: should knowfreq 35%

basics

~10 s

RFC 6996 reserves 64512-65534 and 4200000000-4294967294 for private use. Because they are not globally unique, private ASNs must be removed from AS_PATH, and AS4_PATH, before routes are advertised to the global Internet.

open as a page

As a BGP route for 203.0.113.0/24 crosses two eBGP borders and an iBGP mesh, which path attributes change, and where?

level: middleimportance: should knowfreq 28%

basics

~20 s

At each eBGP border AS_PATH gains the sender's AS and NEXT_HOP is normally rewritten; LOCAL_PREF never crosses and is set afresh inside each AS; a received MED stops at the next AS; ORIGIN stays; COMMUNITIES pass unless policy edits them.

open as a page

What does the BGP COMMUNITIES attribute carry, and how do the well-known communities NO_EXPORT and NO_ADVERTISE limit a route's spread?

level: middleimportance: should knowfreq 22%

basics

~20 s

COMMUNITIES is an optional transitive attribute holding a set of 32-bit tags whose meaning operators agree on. A route tagged NO_EXPORT must not be advertised outside the receiving AS or confederation; one tagged NO_ADVERTISE must not be advertised to any peer.

open as a page

In BGP routing policy, what do a prefix list, an AS-path filter and a route map each match, and how do they combine?

level: middleimportance: should knowfreq 33%

basics

~20 s

A BGP prefix list matches the prefix and its length range, an AS-path filter matches the AS_PATH with a regular expression, and a route map is an ordered list of match-and-set clauses that combines them into a session's policy.

open as a page

How do two BGP peers settle on a hold time, how often should KEEPALIVEs flow, and what happens when the hold timer expires?

level: middleimportance: should knowfreq 30%

basics

~20 s

Each BGP peer proposes a hold time in its OPEN and both use the smaller, which must be zero or at least 3 seconds. KEEPALIVEs flow about every third of it; if nothing arrives in time, the session closes with Hold Timer Expired.

open as a page

When an iBGP router receives an eBGP-learned route whose NEXT_HOP its IGP cannot reach, what happens, and how do next-hop-self and IGP advertisement fix it?

level: middleimportance: should knowfreq 33%

basics

~20 s

iBGP leaves NEXT_HOP pointing at the external neighbour, so an interior router without an IGP route to that address must exclude the route from selection. Fix it at the border with next-hop-self, or by carrying the external link's subnet in the IGP.

open as a page

A multihomed enterprise running BGP to two ISPs starts carrying traffic between them; how did its AS become transit, and why is that harmful?

level: seniorimportance: should knowfreq 28%

basics

~20 s

It announced routes learned from one ISP to the other, so the second ISP, often preferring customer routes, sent traffic for the first ISP's destinations through it. Its links fill with others' traffic; RFC 7908 calls this a route leak.

open as a page

A dual-homed enterprise's BGP border router learns 203.0.113.0/24 over eBGP with AS_PATH 64501 64510 64511 and over iBGP with AS_PATH 64502 64511; which path wins, and why?

level: seniorimportance: should knowfreq 25%

basics

~20 s

If both NEXT_HOPs resolve and LOCAL_PREF is equal, the iBGP path wins on the shorter AS_PATH, two ASes against three, before eBGP-over-iBGP is reached. An unresolvable iBGP NEXT_HOP or a higher LOCAL_PREF on the eBGP path reverses that.

open as a page

BGP's decision process selects one best path per prefix; under what conditions can a BGP speaker still install several paths for load sharing?

level: seniorimportance: should knowfreq 20%

basics

~20 s

RFC 4271 installs one path; multipath is an implementation extension. Paths qualify when they tie through interior cost to the NEXT_HOP — same LOCAL_PREF, AS_PATH length, ORIGIN, MED, session type and IGP cost — usually from the same neighbouring AS.

open as a page

How does a BGP provider use communities set on import so its export policy never sends peer-learned routes to an upstream?

level: seniorimportance: should knowfreq 22%

basics

~20 s

Each eBGP session's import policy tags routes with a community recording the relationship they came from; export policy toward peers and upstreams permits only customer-tagged and own routes, and inbound scrubbing stops neighbours forging those tags.

open as a page

A BGP network announces its /22 over two upstream links; how do AS-path prepending and more-specific announcements compare for steering inbound traffic?

level: seniorimportance: should knowfreq 25%

basics

~20 s

Prepending lengthens the AS_PATH on the less-wanted link and only nudges remote choices, since their LOCAL_PREF comes first; a more-specific on the wanted link wins by longest-prefix match but grows the global table and needs the aggregate kept as fallback.

open as a page

Why does a more-specific BGP hijack draw traffic from nearly every network that hears it, while an exact-prefix origin hijack captures only part of the Internet?

level: seniorimportance: should knowfreq 24%

basics

~20 s

An exact-prefix hijack competes with the real route in each AS's best-path decision, so the Internet splits between them. A more-specific is a different prefix with no rival, and longest-prefix match forwards to it wherever it is accepted.

open as a page

What is the valley-free rule in BGP routing, and how do RFC 9234's BGP Roles and Only-to-Customer attribute stop leaks that break it?

level: seniorimportance: should knowfreq 16%

basics

~20 s

A valley-free path climbs customer-to-provider links, crosses at most one peer link, then only descends: routes from a provider or peer go only to customers. BGP Roles confirm each session's relationship, and the OTC attribute marks routes that may only travel down.

open as a page

showing 1–30 of 38