BGP
BGP connects autonomous systems over TCP sessions, carries policy in path attributes and picks routes by an ordered tie-break list. Interviewers use it for internet routing, anycast and outages.
on this pageshowhide
explore
- Autonomous Systems5 questions
- Peering Session States6 questions
- eBGP and iBGP Sessions6 questions
- Path Attributes4 questions
- Best-Path Selection6 questions
- Route Policy and Filtering6 questions
- Route Leaks and Hijacks5 questions
questions
page 2 of 2A BGP session reaches OpenSent, then drops to Idle with a NOTIFICATION on every retry; what in the OPEN exchange, including capability negotiation, causes that?
basics
~20 sThe peer's OPEN failed a check: wrong AS, an unacceptable hold time, a bad BGP Identifier, an unsupported version or optional parameter, or a required capability missing. The receiver sends an OPEN Message Error NOTIFICATION whose subcode names the problem, then returns to Idle.
Many implementations send eBGP packets with a TTL of 1; why, what does multihop eBGP change, and what does GTSM check instead?
basics
~20 sTTL 1 keeps an eBGP session to a directly connected neighbour; it is an implementation default, not an RFC 4271 rule. Multihop eBGP permits peers several hops away, such as loopbacks. GTSM (RFC 5082) sends TTL 255 and distrusts arrivals below it.
When an AS of 30 iBGP routers moves to BGP route reflectors, where does a reflector send each route, and what stops reflection loops?
basics
~20 sA route reflector (RFC 4456) relays a client's route to all clients and non-clients, and a non-client's route to clients only. ORIGINATOR_ID drops a route returning to its originator; CLUSTER_LIST drops one returning to a cluster that already reflected it.
Your AS plans to drop RPKI-invalid BGP routes at every eBGP edge; what does that buy, what can it break, and how would you roll it out?
basics
~20 sDropping RPKI-invalid routes rejects wrong-origin and too-specific announcements wherever ROAs exist, but proves nothing about the path; it can cut reachability to holders with stale ROAs, so sign your own space, observe first, then enforce in stages.
As routing-security lead for a regional transit AS, how would you weigh ROAs, BGPsec, ASPA, BGP Roles and MANRS by what each proves and costs?
basics
~20 sROAs prove who may originate a prefix; BGPsec proves the path but needs every AS on it signing; BGP Roles and ASPA, still an IETF draft, catch leaks with partial deployment; MANRS is an operator programme, not a protocol.
Why does a BGP speaker compare MED only between paths from the same neighbouring AS, and how can that make its choice depend on comparison order?
basics
~20 sMED is one neighbouring AS's own metric for its entry points, meaningless on another AS's scale, so RFC 4271 compares it only within that AS. That breaks total ordering: pairwise comparison can pick different winners in different orders.
Why did RFC 7606 replace the BGP session reset for many malformed UPDATE messages with treat-as-withdraw, and what does that trade away?
basics
~20 sUnder RFC 4271, any malformed BGP UPDATE reset the whole session, dropping every route on it, often far from the router at fault. For most attribute errors RFC 7606 withdraws only that UPDATE's routes, risking unreachability and inconsistent routing inside an AS.
How does a BGP confederation (RFC 5065) remove the iBGP full mesh, and when would you choose one over route reflectors?
basics
~20 sA confederation splits one AS into member-ASes, each internally meshed, joined by eBGP-like sessions that record member-AS numbers in AS_CONFED_SEQUENCE. Outsiders see one AS. Reflectors deploy more gradually; confederations add policy boundaries and per-member IGPs.
showing 31–38 of 38