Network Bgp Diagnostics

affaan-m/ECC/skills/network-bgp-diagnostics

作者 affaan-mef648e01899ba3e8dc6371642deaaf64b4477775无许可证275K 个星标收录于 2026年10月9日更新于 2026年10月9日仓库4天前更新

Diagnostics-only BGP troubleshooting patterns for neighbor state, route exchange, prefix policy, AS path inspection, and safe evidence collection. Use when a BGP neighbor is down, routes are missing, or prefix policy and AS path need inspection.

仅含说明DevOps & Cloud
AI 生成的概览

面向邻居状态、路由交换、前缀策略与 AS 路径检查的只读 BGP 排障指引。

功能
提供仅用于诊断的 BGP 问题处理流程:确定邻居、地址族与 ASN,采集汇总状态和最近重置原因,验证对等体可达性,并在假定传输故障前检查路由策略。内容包括状态解读表、只读命令示例、AS 路径正则注意事项,以及用于解析 BGP 汇总输出的 Python 正则解析器。还列出了必须留到已审批变更窗口执行的操作和常见反模式。
适用场景
适用于 BGP 邻居中断、震荡、停留在 Idle、Connect、Active、OpenSent 或 OpenConfirm 状态,或已建立但缺少或出现意外前缀的情况。也适用于怀疑路由映射、前缀列表、最大前缀限制或 AS 路径策略过滤路由,或需要为 BGP 变更留存前后证据时。
运行要求
该技能不附带脚本,仅为说明性指引。需要能够访问网络设备及其 BGP show 命令;若使用其中的解析器示例,还需要带有标准 re 和 typing 模块的 Python 运行环境。预期为只读访问;策略变更和会话重置需在已审批的变更窗口内进行。

Network BGP Diagnostics

Use this skill when a BGP session is down, flapping, established with missing routes, or advertising unexpected prefixes. The default workflow is read-only evidence collection; policy and reset actions belong in a reviewed change window.

When to Use

  • BGP neighbors are stuck in Idle, Connect, Active, OpenSent, or OpenConfirm.
  • A session is Established but expected prefixes are missing.
  • A route-map, prefix-list, max-prefix limit, or AS path policy may be filtering routes.
  • You need before/after evidence for a BGP change.
  • You are reviewing automation that parses BGP summary output.

Read-Only Triage Flow

  1. Identify the exact neighbor, address family, VRF, and local/remote ASNs.
  2. Capture summary state and last reset reason.
  3. Prove reachability to the peer source address.
  4. Check route policy references before assuming transport failure.
  5. Compare advertised, received, and installed routes where the platform supports those commands.
text
show bgp summaryshow bgp neighbors <peer>show ip route <peer>show tcp brief | include <peer>|:179show logging | include BGP|<peer>show running-config | section router bgpshow ip prefix-listshow route-map

Use platform-specific address-family commands when the device uses VRFs, IPv6, VPNv4, or EVPN. Do not assume global IPv4 unicast.

State Interpretation

StateFirst checks
Established with prefix countRoute exchange is up; inspect policy and table selection
Established with zero prefixesCheck inbound policy, max-prefix, advertised routes, and AFI/SAFI
ActiveTCP session is not completing; check routing, source, ACLs, and peer reachability
ConnectTCP connection is in progress; check path and remote listener
OpenSent/OpenConfirmTCP works; check ASN, authentication, timers, capabilities, and logs
IdleNeighbor may be disabled, missing config, blocked by policy, or backoff timer

Transport Checks

text
ping <peer> source <local-source>traceroute <peer> source <local-source>show ip route <peer>show bgp neighbors <peer> | include BGP state|Last reset|Local host|Foreign host

If the peer is sourced from a loopback, confirm both directions route to the loopback addresses and that the neighbor config uses the expected update source.

Avoid disabling ACLs or firewall policy as a diagnostic shortcut. Read hit counters, logs, and path state first.

Route Policy Checks

text
show bgp neighbors <peer> advertised-routesshow bgp neighbors <peer> routesshow ip prefix-list <name>show route-map <name>show bgp <prefix>

Some platforms require additional configuration before received-routes is available. Do not add that configuration during incident triage unless the operator approves the change.

AS Path And Prefix Review

text
show bgp regexp _65001_show bgp regexp ^65001$show bgp <prefix>show bgp neighbors <peer> advertised-routes | include Network|Path|<prefix>

Use AS-path regex carefully. _65001_ matches AS 65001 as a token. Plain 65001 can match longer ASNs or unrelated text.

Parser Pattern

python
import refrom typing import Any
BGP_SUMMARY_RE = re.compile(    r"^(?P<neighbor>\d{1,3}(?:\.\d{1,3}){3})\s+"    r"(?P<version>\d+)\s+"    r"(?P<remote_as>\d+)\s+"    r"(?P<msg_rcvd>\d+)\s+"    r"(?P<msg_sent>\d+)\s+"    r"(?P<table_version>\d+)\s+"    r"(?P<input_queue>\d+)\s+"    r"(?P<output_queue>\d+)\s+"    r"(?P<uptime>\S+)\s+"    r"(?P<state_or_prefixes>\S+)$",    re.M,)
def parse_bgp_summary(raw: str) -> list[dict[str, Any]]:    rows = []    for match in BGP_SUMMARY_RE.finditer(raw):        state_or_prefixes = match.group("state_or_prefixes")        if state_or_prefixes.isdigit():            state = "Established"            prefixes_received = int(state_or_prefixes)        else:            state = state_or_prefixes            prefixes_received = None        rows.append({            "neighbor": match.group("neighbor"),            "remote_as": int(match.group("remote_as")),            "state": state,            "prefixes_received": prefixes_received,            "uptime": match.group("uptime"),        })    return rows

Prefer structured parser output when available, but store raw output with the incident record because BGP summary formats vary by platform and address family.

Change-Window Only

These actions can affect routing and should not be suggested as automatic diagnostics:

  • Clearing a BGP session.
  • Changing neighbor authentication, timers, update source, route-maps, or prefix-lists.
  • Enabling additional received-route storage.
  • Relaxing firewall, ACL, or control-plane policy.

If a reset is approved, prefer the least disruptive soft or route-refresh option supported by the platform and document exactly why it is safe.

Anti-Patterns

  • Assuming Active always means the remote side is down.
  • Ignoring VRF, address family, or update-source differences.
  • Using broad AS-path regex without token boundaries.
  • Hard-resetting a peer before reading last reset reason and logs.
  • Treating missing received-routes output as proof that no routes arrived.

See Also

  • Skill: cisco-ios-patterns
  • Skill: network-config-validation
  • Skill: network-interface-health

来源与署名

来源:affaan-m/ECC位于skills/network-bgp-diagnostics提交ef648e0

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架