Network BGP Diagnostics
Use this skill when a BGP session is down, flapping, established with missing routes, or advertising unexpected prefixes. The default workflow is read-only evidence collection; policy and reset actions belong in a reviewed change window.
When to Use
- BGP neighbors are stuck in Idle, Connect, Active, OpenSent, or OpenConfirm.
- A session is Established but expected prefixes are missing.
- A route-map, prefix-list, max-prefix limit, or AS path policy may be filtering routes.
- You need before/after evidence for a BGP change.
- You are reviewing automation that parses BGP summary output.
Read-Only Triage Flow
- Identify the exact neighbor, address family, VRF, and local/remote ASNs.
- Capture summary state and last reset reason.
- Prove reachability to the peer source address.
- Check route policy references before assuming transport failure.
- Compare advertised, received, and installed routes where the platform supports those commands.
Use platform-specific address-family commands when the device uses VRFs, IPv6, VPNv4, or EVPN. Do not assume global IPv4 unicast.
State Interpretation
Transport Checks
If the peer is sourced from a loopback, confirm both directions route to the loopback addresses and that the neighbor config uses the expected update source.
Avoid disabling ACLs or firewall policy as a diagnostic shortcut. Read hit counters, logs, and path state first.
Route Policy Checks
Some platforms require additional configuration before received-routes is
available. Do not add that configuration during incident triage unless the
operator approves the change.
AS Path And Prefix Review
Use AS-path regex carefully. _65001_ matches AS 65001 as a token. Plain
65001 can match longer ASNs or unrelated text.
Parser Pattern
Prefer structured parser output when available, but store raw output with the incident record because BGP summary formats vary by platform and address family.
Change-Window Only
These actions can affect routing and should not be suggested as automatic diagnostics:
- Clearing a BGP session.
- Changing neighbor authentication, timers, update source, route-maps, or prefix-lists.
- Enabling additional received-route storage.
- Relaxing firewall, ACL, or control-plane policy.
If a reset is approved, prefer the least disruptive soft or route-refresh option supported by the platform and document exactly why it is safe.
Anti-Patterns
- Assuming
Activealways means the remote side is down. - Ignoring VRF, address family, or update-source differences.
- Using broad AS-path regex without token boundaries.
- Hard-resetting a peer before reading last reset reason and logs.
- Treating missing
received-routesoutput as proof that no routes arrived.
See Also
- Skill:
cisco-ios-patterns - Skill:
network-config-validation - Skill:
network-interface-health


