{"id":24865,"date":"2026-10-05T13:24:34","date_gmt":"2026-10-05T13:24:34","guid":{"rendered":"https:\/\/atalnetworks.com\/?p=24865"},"modified":"2026-10-05T13:24:34","modified_gmt":"2026-10-05T13:24:34","slug":"bgp-established-but-prefix-unreachable-causes-and-fixes","status":"publish","type":"post","link":"https:\/\/atalnetworks.com\/nl\/bgp-established-but-prefix-unreachable-causes-and-fixes\/","title":{"rendered":"BGP Established but Prefix Unreachable: Causes and Fixes"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">A BGP neighbor can show <\/span><b>Established<\/b><span style=\"font-weight: 400;\"> while the network behind that neighbor remains unreachable. This happens because the BGP session state confirms the control-plane connection between two peers, not end-to-end packet delivery.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The affected prefix may never enter BGP. It may be blocked by an export or import policy, have an inaccessible next hop, lose best-path selection, fail to enter the routing table, or reach the FIB while packets still fail because of a firewall, VLAN, or missing return route.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The fastest way to troubleshoot this problem is to follow the prefix through its full path:<\/span><\/p>\n<p><b>Origin \u2192 BGP table \u2192 export policy \u2192 peer \u2192 import policy \u2192 best path \u2192 RIB \u2192 FIB \u2192 destination \u2192 return path<\/b><\/p>\n<p><span style=\"font-weight: 400;\">This order prevents network teams from changing BGP configuration when the real fault sits somewhere else.<\/span><\/p>\n<h2><b>Does an Established BGP Session Mean the Prefix Is Reachable?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">No.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The BGP <\/span><span style=\"font-weight: 400;\">Established<\/span><span style=\"font-weight: 400;\"> state means the peers completed session setup and can exchange BGP messages. RFC 4271 states that peers in the Established state can exchange UPDATE, KEEPALIVE, and NOTIFICATION messages. UPDATE messages carry routing information between BGP peers.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It does not prove that a specific route:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">was originated<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">was advertised<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">passed routing policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">was accepted by the peer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">has a reachable next hop<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">became the best path<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">entered the IP routing table<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">reached the forwarding table<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">can carry traffic in both directions<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">That distinction should be the starting point for every case where BGP is up but the prefix is unreachable.<\/span><\/p>\n<h2><b>Find Where the BGP Prefix Disappears First<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Before changing configuration, identify the last stage where the route still exists.<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><b>Check<\/b><\/td>\n<td><b>Result<\/b><\/td>\n<td><b>Likely fault<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Prefix absent from source routing table<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Missing<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Local route or interface<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Prefix absent from local BGP table<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Missing<\/span><\/td>\n<td><span style=\"font-weight: 400;\">BGP origination<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Prefix not advertised to peer<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Missing<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Export policy<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Peer never receives prefix<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Missing<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Address family or advertisement<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Peer receives but rejects prefix<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Rejected<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Import policy, AS path, RPKI<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Prefix exists but has no best path<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Present<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Next-hop or path eligibility<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Best path exists, but route is absent from RIB<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Present<\/span><\/td>\n<td><span style=\"font-weight: 400;\">RIB installation<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Route exists in RIB but not FIB<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Present<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Forwarding programming<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Route exists in FIB, but host is unreachable<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Present<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Data plane or return path<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">A useful rule is simple:<\/span><\/p>\n<p><b>Start with the prefix itself, then follow it one stage at a time. Do not use BGP neighbor state as proof that the route works.<\/b><\/p>\n<h2><b>1. Verify the Prefix Exists in the Source Routing Table<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">A router cannot advertise a prefix through the intended BGP origination method if the required source route does not exist.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">First inspect the local routing table.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A route might come from:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">a connected interface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">a static route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IS-IS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">another routing protocol<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">an aggregate<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">a discard or Null route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">redistribution<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Suppose you want to advertise:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">203.0.113.0\/24<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Confirm that the required route exists in the correct routing table or VRF.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A common mistake is having:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">203.0.113.0\/25<\/span><\/p>\n<p><span style=\"font-weight: 400;\">203.0.113.128\/25<\/span><\/p>\n<p><span style=\"font-weight: 400;\">while the BGP configuration expects an exact <\/span><span style=\"font-weight: 400;\">\/24<\/span><span style=\"font-weight: 400;\"> route through a <\/span><span style=\"font-weight: 400;\">network<\/span><span style=\"font-weight: 400;\"> statement on a platform that requires that exact route to exist.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Check the prefix and mask, not only the first few octets.<\/span><\/p>\n<h3><b>Also Check Interface State<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">If a connected route supplies the prefix and its interface goes down, the route may disappear from the RIB. BGP can remain Established with the upstream neighbor while the customer prefix stops being advertised.<\/span><\/p>\n<h2><b>2. Confirm the Prefix Entered the BGP Table<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Finding the route in the IP routing table is only the first step.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Now verify that BGP actually originated or learned it.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Depending on the design, the route could enter BGP through:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">a <\/span><span style=\"font-weight: 400;\">network<\/span><span style=\"font-weight: 400;\"> statement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">redistribution<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">aggregation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">another BGP peer<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">If the route exists in the main routing table but not in the local BGP table, investigate the origination method before touching neighbor filters.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This separates two different problems:<\/span><\/p>\n<p><b>Route exists locally but never entered BGP<\/b><\/p>\n<p><span style=\"font-weight: 400;\">versus:<\/span><\/p>\n<p><b>Route entered BGP but was not sent to a peer<\/b><\/p>\n<p><span style=\"font-weight: 400;\">That distinction saves a great deal of troubleshooting time.<\/span><\/p>\n<h2><b>3. Verify the Prefix Is Actually Advertised to the Neighbor<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Next, inspect the routes being advertised toward the affected peer.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Conceptually, this is the <\/span><b>Adj-RIB-Out<\/b><span style=\"font-weight: 400;\"> stage.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If the prefix appears in your local BGP table but not among routes sent to the neighbor, focus on outbound policy.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Common causes include:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">outbound prefix-list<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">route-map<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">route-policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AS-path filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">community match<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">conditional advertisement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">wrong neighbor policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">wrong address family<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">aggregation behavior<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">route not selected for advertisement<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">A session can remain Established through all of these conditions.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The peer relationship and route policy are separate parts of BGP operation.<\/span><\/p>\n<h3><b>Check Policy Direction<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">One of the easiest mistakes to miss is applying the correct policy in the wrong direction.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Confirm whether the route filter is:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">inbound<\/span><\/p>\n<p><span style=\"font-weight: 400;\">or:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">outbound<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A prefix-list intended to control received routes will cause very different results if attached to advertisements.<\/span><\/p>\n<h2><b>4. Verify the Peer Received and Accepted the Route<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">A route can cross the BGP session and still disappear on the receiving router.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Separate three questions:<\/span><\/p>\n<h3><b>Did the peer receive the route?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">This confirms an UPDATE containing the route reached the remote BGP process.<\/span><\/p>\n<h3><b>Did the peer accept the route?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">An inbound policy may reject it after reception.<\/span><\/p>\n<h3><b>Did BGP consider the path usable?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A route that passes policy may still fail path eligibility because its next hop cannot be resolved or another protocol condition rejects it.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">These stages correspond conceptually to the received route information, routing policy, and BGP&#8217;s local route information.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Do not treat &#8220;received&#8221; and &#8220;installed&#8221; as synonyms.<\/span><\/p>\n<h2><b>5. Check Prefix-Lists, Route-Maps, and Routing Policy<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Route filtering is one of the first places to look when only certain prefixes are missing.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Consider an expected route:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">203.0.113.0\/24<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A filter might accidentally allow:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">203.0.113.0\/25<\/span><\/p>\n<p><span style=\"font-weight: 400;\">but not the <\/span><span style=\"font-weight: 400;\">\/24<\/span><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Prefix-length rules can create less obvious errors.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Check:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">exact prefix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">mask length<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">staart<\/span><span style=\"font-weight: 400;\"> values<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">le<\/span><span style=\"font-weight: 400;\"> values<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">route-map sequence numbers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">implicit deny behavior<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">community matches<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AS-path expressions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">policy order<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">correct neighbor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">correct AFI\/SAFI<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">An apparently small mask-length mistake can remove an entire customer network while every BGP peer remains Established.<\/span><\/p>\n<h2><b>6. Verify the Correct Address Family<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">BGP can have an active peer relationship while the required address family is not exchanging the routes you expect.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Examples include:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPv4 unicast<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPv6 unicast<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPNv4<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPNv6<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">A dual-stack peer may exchange IPv4 correctly while IPv6 routes are absent.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If IPv4 works and IPv6 does not, do not assume the entire BGP session is faulty. Check the IPv6 address family, activation, policies, and advertised prefixes separately.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The reverse applies as well.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Treat each address family as its own routing path during diagnosis.<\/span><\/p>\n<h2><b>7. Check BGP Next-Hop Reachability<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Next-hop resolution is one of the most common reasons a route exists in BGP but remains unusable.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The route may look like this:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Prefix: \u00a0 203.0.113.0\/24<\/span><\/p>\n<p><span style=\"font-weight: 400;\">NEXT_HOP: 198.51.100.1<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The receiving router then needs a route that can resolve <\/span><span style=\"font-weight: 400;\">198.51.100.1<\/span><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If it cannot reach that address, the BGP path may be marked inaccessible.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Cisco states that paths with an inaccessible <\/span><span style=\"font-weight: 400;\">NEXT_HOP<\/span><span style=\"font-weight: 400;\"> are ignored for best-path selection and recommends confirming IGP reachability to that next hop.<\/span> <span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The failure chain looks like this:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">BGP receives prefix<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u2193<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Reads NEXT_HOP<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u2193<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Performs recursive lookup<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u2193<\/span><\/p>\n<p><span style=\"font-weight: 400;\">NEXT_HOP cannot be resolved<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u2193<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Path cannot become usable<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u2193<\/span><\/p>\n<p><span style=\"font-weight: 400;\">No best path for forwarding<\/span><\/p>\n<h3><b>A Common iBGP Case<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Suppose:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">R1 &#8212;- eBGP &#8212;- ISP<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">iBGP<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">R2<\/span><\/p>\n<p><span style=\"font-weight: 400;\">R1 learns an external prefix and advertises it to R2 through iBGP.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The original external next hop may remain unchanged.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">R2 now knows the destination prefix through BGP, but if R2 has no route to that external next hop, the destination cannot become usable.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Cisco documents this exact type of case, where an iBGP route shows an inaccessible next hop until the receiving router gains a valid route to it.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Depending on the architecture, the fix may involve:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IGP reachability to the next hop<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">a suitable static route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">next-hop-self<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">a change to the underlay routing design<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Do not add <\/span><span style=\"font-weight: 400;\">next-hop-self<\/span><span style=\"font-weight: 400;\"> automatically. First confirm why the next hop is unreachable.<\/span><\/p>\n<h2><b>8. Confirm BGP Selected a Best Path<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">A prefix appearing in BGP output does not automatically mean BGP selected it as the active path.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Check whether the route is:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">valid<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">best<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">rejected<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">received only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">inaccessible<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">suppressed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">affected by loop prevention<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Potential causes include:<\/span><\/p>\n<h3><b>Inaccessible NEXT_HOP<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Already covered above, but this is often the first reason a path loses eligibility.<\/span><\/p>\n<h3><b>Local ASN in AS_PATH<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">BGP loop prevention may reject a path containing the local AS where that appearance is not permitted.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Cisco lists an inaccessible next hop and local AS appearing in an external path among conditions that can prevent a route from becoming a valid best-path candidate.\u00a0<\/span><\/p>\n<h3><b>Policy Rejection<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The route may have arrived but failed an access list, prefix filter, AS-path policy, community rule, or another routing policy.<\/span><\/p>\n<h3><b>RPKI State<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A route can also be rejected by networks that apply Route Origin Validation policy.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We cover that separately below.<\/span><\/p>\n<h2><b>9. Check Whether the Best BGP Route Entered the RIB<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Now move one layer down.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">There are three separate databases engineers often treat as if they were one:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">BGP table<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u2193<\/span><\/p>\n<p><span style=\"font-weight: 400;\">IP routing table, or RIB<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u2193<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Forwarding table, or FIB<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A route can exist at one layer but not the next.<\/span><\/p>\n<h3><b>BGP Route Exists, but RIB Does Not Contain It<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Look for:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">inaccessible next hop<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">no usable BGP best path<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">another routing source<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">route installation failure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">wrong VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">routing table policy<\/span><\/li>\n<\/ul>\n<h3><b>Another Protocol Owns the Route<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">A static or IGP route may already provide the destination.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Do not assume BGP must always become the installed route simply because BGP knows about the prefix.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Inspect the active routing table entry and identify which routing source currently owns it.<\/span><\/p>\n<h3><b>Check the VRF<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">This problem appears frequently in hosting, MPLS, cloud connectivity, and segmented enterprise networks.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The prefix can exist correctly inside:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">VRF-CUSTOMER-A<\/span><\/p>\n<p><span style=\"font-weight: 400;\">while testing is performed from the default routing table.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The route is present, but not in the forwarding context being used.<\/span><\/p>\n<h2><b>10. Check the FIB and Next-Hop Adjacency<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Once the route reaches the RIB, verify forwarding.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The FIB tells the router where packets should actually go.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Depending on the platform, inspect:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">forwarding entry<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">resolved next hop<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">outgoing interface<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">adjacency<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">hardware programming<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">label stack where applicable<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Then check Layer 2 resolution.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For IPv4:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">For IPv6:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Neighbor Discovery<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">A correct BGP route cannot deliver packets if the router cannot resolve the next-hop adjacency on the outgoing network.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This is where troubleshooting should move away from BGP configuration and toward the data plane.<\/span><\/p>\n<h2><b>11. Check RPKI, ROA, and the Origin ASN<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Public prefixes may look correct on your own routers but still be unreachable from parts of the Internet because other networks reject the announcement.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">RPKI Route Origin Validation checks whether an AS is authorized to originate a prefix.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A ROA records:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">the authorized origin ASN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">the covered prefix<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">optionally, the most-specific permitted prefix length<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">RIPE NCC describes three primary route states:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Valid<\/b><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Invalid<\/b><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Not Found<\/b><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">An announcement becomes Invalid when, for example, it originates from an unauthorized ASN or is more specific than the ROA permits.<\/span> <span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<h3><b>Example<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Suppose the ROA permits:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Prefix:\u00a0 \u00a0 203.0.113.0\/23<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Origin:\u00a0 \u00a0 AS65001<\/span><\/p>\n<p><span style=\"font-weight: 400;\">MaxLength: \/23<\/span><\/p>\n<p><span style=\"font-weight: 400;\">You then announce:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">203.0.113.0\/24<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The origin ASN is correct, but the <\/span><span style=\"font-weight: 400;\">\/24<\/span><span style=\"font-weight: 400;\"> is more specific than the ROA permits.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Networks rejecting RPKI-invalid routes may drop that advertisement.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The result can be confusing:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP session is Established<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">your provider receives the route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">some networks can reach you<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">other networks cannot<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">For BYOIP deployments, verify the ROA before the production BGP announcement.<\/span><\/p>\n<h2><b>12. Check AS_PATH Loop Prevention<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">BGP uses AS_PATH partly to prevent routing loops.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If your own ASN appears in a received AS_PATH in a context where it is not permitted, the route may be rejected.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Possible cases include:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">accidental re-advertisement<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">multi-provider designs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">private ASN handling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">migration between ASNs<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">route servers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">unusual <\/span><span style=\"font-weight: 400;\">allowas-in<\/span><span style=\"font-weight: 400;\"> requirements<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Do not disable loop prevention simply to make a route appear.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">First identify why the local ASN is present in the path.<\/span><\/p>\n<h2><b>13. Verify the Return Path<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">One of the most common mistakes in BGP incident response is testing only the forward route.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Traffic must work both ways.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Consider:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Client<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Transit A<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Your BGP Edge<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Server<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The client reaches the server correctly.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The server replies through:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Server<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Different gateway<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Transit B<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Stateful firewall<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">DROP<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The BGP route may be correct while the connection still fails.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Check:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">server default route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">reverse route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">source address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">policy-based routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">firewall state<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">asymmetric path<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">multiple upstreams<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<\/ul>\n<h3><b>Test From More Than One Direction<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Use:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">traceroute from external locations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">reverse traceroute where available<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">looking glasses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">route collectors<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">probes from several networks<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">If one provider reaches the prefix and another does not, the problem is probably larger than a local server firewall.<\/span><\/p>\n<h2><b>14. Check Firewall, ACL, VLAN, and Host Networking<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Once BGP, RIB, and FIB look correct, stop changing BGP until the data plane has been tested.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Verify:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">server IP address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">subnet mask or prefix length<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">default gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN assignment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">switch port<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">hypervisor bridge<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">virtual switch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">security group<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">router ACL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">host firewall<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">service bind address<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP or NDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT rules<\/span><\/li>\n<\/ul>\n<h3><b>A Simple Diagnostic Question<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Can the gateway reach the host directly?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If the answer is no, Internet BGP is probably not the immediate problem.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Fix the local network first.<\/span><\/p>\n<h2><b>15. Check MTU When Reachability Is Partial<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">MTU issues do not usually make a whole BGP prefix disappear, but they can make a working route look broken.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Typical symptoms include:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">small pings succeed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">large packets fail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TCP connects but stalls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">tunnels work inconsistently<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">some applications load while others time out<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Check:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">interface MTU<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">tunnel overhead<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TCP MSS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Path MTU Discovery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ICMP filtering<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Treat this as a later-stage check after routing has been proven.<\/span><\/p>\n<h2><b>BGP Established but Receiving Zero Prefixes<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">If the session is up but the received prefix count is zero, use a shorter workflow.<\/span><\/p>\n<h3><b>Check in this order:<\/b><\/h3>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confirm the correct address family is active.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confirm the remote router has routes to advertise.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Check the remote export policy.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Check your import policy.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Check maximum-prefix controls.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Verify the correct VRF.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Check route policy based on AS path or communities.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Check RPKI policy where public routes are involved.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">Do not restart the BGP session as the first troubleshooting step.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A reset may hide useful state without correcting the configuration fault.<\/span><\/p>\n<h2><b>BGP Prefix Received but NEXT_HOP Is Inaccessible<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">A typical incident may look like this:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">BGP neighbor: Established<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Prefix:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">203.0.113.0\/24<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Status:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Received<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">NEXT_HOP:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">198.51.100.1<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Route to NEXT_HOP:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Missing<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">Result:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">No usable BGP path<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The proper question is not:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Why is BGP down?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">BGP is not down.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The proper question is:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Which route should resolve 198.51.100.1, and why is that route missing?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Cisco notes that when a BGP next hop is inaccessible, the route has no usable best path and may not be advertised further.<\/span> <span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<h2><b>Prefix Works From Some Networks but Not Others<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Partial Internet reachability often points toward routing policy outside the local server.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Check:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPKI validity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ROA <\/span><span style=\"font-weight: 400;\">maxLength<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">upstream advertisements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">route propagation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">prefix length<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">communities sent to transit providers<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">regional advertisements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">route leaks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">stale routes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">anycast configuration<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">For IPv4, also review whether the prefix is being announced at a length that upstream and downstream networks are willing to propagate.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A prefix visible through one transit provider may still be filtered elsewhere.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This is why multi-provider testing matters.<\/span><\/p>\n<h2><b>Troubleshooting an Unreachable BYOIP Prefix<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">BYOIP adds another set of dependencies.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Use this order:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confirm ownership or authorization for the IP block.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Verify the prefix and prefix length.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confirm the intended origin ASN.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Check the ROA.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Check the ROA maximum length.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Review IRR route objects if the provider uses them.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confirm the hosting provider imported the prefix.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confirm BGP advertisement toward upstream networks.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Check external route visibility.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Check local forwarding to the server.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Verify the return path.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Test from several external ASNs.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">Do not assume the announcement is globally working because the prefix appears on one local router.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Atal Networks supports IPv4 and IPv6 services, ASN-related infrastructure, BYOIP, private networking, and multihomed hosting environments. About Atal Networks These deployments benefit from checking routing authorization, origin ASN, prefix length, and server-side forwarding before a production cutover.<\/span><\/p>\n<h2><b>Quick BGP Troubleshooting Decision Tree<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Use this sequence during an incident:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">BGP session Established<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0v<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Is the source prefix in the local RIB?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0No +&#8212;-&gt; Fix source route\/interface<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Ja<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0v<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Is the prefix in the local BGP table?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0No +&#8212;-&gt; Fix BGP origination<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Ja<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0v<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Is the prefix advertised to the peer?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0No +&#8212;-&gt; Check export policy<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Ja<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0v<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Did the peer receive the prefix?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0No +&#8212;-&gt; Check AFI\/SAFI and remote side<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Ja<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0v<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Did the peer accept it?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0No +&#8212;-&gt; Import policy \/ AS_PATH \/ RPKI<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Ja<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0v<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Is NEXT_HOP reachable?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0No +&#8212;-&gt; Fix next-hop resolution<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Ja<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0v<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Is there a best path?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0No +&#8212;-&gt; Check path eligibility<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Ja<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0v<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Is it installed in the RIB?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0No +&#8212;-&gt; Check RIB\/VRF\/competing route<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Ja<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0v<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Is it installed in the FIB?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0No +&#8212;-&gt; Check forwarding programming<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Ja<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0v<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Does the return path work?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0No +&#8212;-&gt; Fix routing\/firewall\/asymmetry<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0|<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Ja<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0v<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Check host, VLAN, ACL, ARP\/NDP, and MTU<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This flow works because each step proves one stage before moving to the next.<\/span><\/p>\n<h2><b>Useful Commands by Troubleshooting Stage<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Exact syntax varies by network operating system and release.<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td><b>Goal<\/b><\/td>\n<td><b>Cisco-style example<\/b><\/td>\n<td><b>FRR-style example<\/b><\/td>\n<td><b>Junos concept<\/b><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Peer status<\/span><\/td>\n<td><span style=\"font-weight: 400;\">show ip bgp summary<\/span><\/td>\n<td><span style=\"font-weight: 400;\">show bgp summary<\/span><\/td>\n<td><span style=\"font-weight: 400;\">show bgp summary<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Inspect prefix<\/span><\/td>\n<td><span style=\"font-weight: 400;\">show ip bgp PREFIX<\/span><\/td>\n<td><span style=\"font-weight: 400;\">show bgp ipv4 unicast PREFIX<\/span><\/td>\n<td><span style=\"font-weight: 400;\">show route PREFIX extensive<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Routing table<\/span><\/td>\n<td><span style=\"font-weight: 400;\">show ip route PREFIX<\/span><\/td>\n<td><span style=\"font-weight: 400;\">show ip route PREFIX<\/span><\/td>\n<td><span style=\"font-weight: 400;\">show route PREFIX<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Advertised routes<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Neighbor advertised-routes<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Neighbor advertised-routes<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Route advertising-protocol<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">Received routes<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Neighbor received-routes<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Neighbor received-routes<\/span><\/td>\n<td><span style=\"font-weight: 400;\">Route receive-protocol<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-weight: 400;\">IPv6 route<\/span><\/td>\n<td><span style=\"font-weight: 400;\">show bgp ipv6 unicast<\/span><\/td>\n<td><span style=\"font-weight: 400;\">show bgp ipv6 unicast<\/span><\/td>\n<td><span style=\"font-weight: 400;\">show route table inet6.0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\">Always verify syntax against the vendor documentation before applying configuration changes to a production router.<\/span><\/p>\n<h2><b>Monitor More Than the BGP Session State<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">An alert that only checks whether a neighbor is <\/span><span style=\"font-weight: 400;\">Established<\/span><span style=\"font-weight: 400;\"> can miss a routing outage.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Monitor:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP state<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">received prefix count<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">advertised prefix count<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">sudden prefix changes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">next-hop reachability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPKI state<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">route installation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FIB state where available<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">external reachability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IPv4 and IPv6 separately<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">A useful alert might detect:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Neighbor state: Established<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Expected prefixes: 25<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Received prefixes: 0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That is already a service problem even though the session never dropped.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">External probes also help because they test the result that customers care about: whether the prefix is actually reachable.<\/span><\/p>\n<h2><b>BGP Prefix Unreachable Troubleshooting Checklist<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Before escalating the incident, confirm all of the following:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP peer state is Established.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Correct AFI\/SAFI is active.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Source prefix exists in the correct RIB.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Prefix entered the BGP table.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Prefix is advertised to the intended neighbor.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remote peer receives the route.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Import policy permits it.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Export policy permits it.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Prefix-list length matches.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NEXT_HOP resolves.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Correct VRF is used.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP selected a usable best path.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route entered the routing table.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route entered the forwarding table.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPKI state is correct.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ROA authorizes the origin ASN.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ROA <\/span><span style=\"font-weight: 400;\">maxLength<\/span><span style=\"font-weight: 400;\"> permits the advertisement.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AS_PATH is acceptable.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Server gateway is correct.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewall and ACL rules permit traffic.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN and interface configuration are correct.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP or NDP works.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Return routing works.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">External tests succeed from several networks.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">The key is to stop asking only whether <\/span><b>BGP is up<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Ask instead:<\/span><\/p>\n<p><b>At which stage does this specific prefix stop working?<\/b><\/p>\n<p><span style=\"font-weight: 400;\">That question usually points directly toward the fault.<\/span><\/p>\n<h1><b>Veel gestelde vragen<\/b><\/h1>\n<h3><b>Why is my BGP session Established but the prefix is unreachable?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The BGP session may be healthy while the route fails elsewhere. Check whether the prefix was originated, advertised, received, accepted, selected as best, installed in the RIB, programmed into the FIB, and reachable in both directions.<\/span><\/p>\n<h3><b>Does BGP Established mean routes are being advertised?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">No. Established means the peers can exchange BGP messages. Export policy, missing origination, address-family configuration, or route eligibility can still prevent a specific route from being advertised. RFC 4271 defines Established as the state where BGP peers can exchange UPDATE and other BGP messages.<\/span> <span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<h3><b>Why is a BGP route in the BGP table but not the routing table?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Common causes include an inaccessible next hop, no usable best path, another routing source, routing policy, or the route existing in another VRF. Cisco notes that paths with an inaccessible next hop are not considered usable best-path candidates.<\/span> <span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<h3><b>What does BGP next hop inaccessible mean?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">It means the router cannot resolve the route&#8217;s <\/span><span style=\"font-weight: 400;\">NEXT_HOP<\/span><span style=\"font-weight: 400;\"> through its routing information. The router may know the destination prefix through BGP but still be unable to forward packets toward the next-hop router.<\/span><\/p>\n<h3><b>Can a prefix-list block a route without dropping BGP?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Yes. Prefix policies operate on route exchange. A policy can reject one prefix, many prefixes, or every route while the neighbor session remains Established.<\/span><\/p>\n<h3><b>Can RPKI make a prefix unreachable?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Yes. Networks using Route Origin Validation may reject an RPKI-invalid route. A route can become Invalid because the origin ASN is unauthorized or because the announced prefix is more specific than the ROA permits.<\/span> <span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<h3><b>Why does the route look correct but ping still fail?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The failure may sit outside BGP. Check the FIB, outgoing interface, ARP or NDP, VLAN, firewall, host configuration, default gateway, and return path.<\/span><\/p>\n<h3><b>What does <\/b><b>next-hop-self<\/b><b> solve?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">It can change the advertised BGP next hop to an address the receiving peer can reach. This is useful in some iBGP designs, but it should only be used after confirming that next-hop preservation is actually causing the failure.<\/span><\/p>\n<h3><b>Why does a BYOIP prefix work from some networks but not others?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Check RPKI, ROA prefix length, upstream advertisements, Internet route propagation, routing policy, and the origin ASN. Partial propagation can produce working routes through some networks and missing routes through others.<\/span><\/p>\n<h2><b>Troubleshooting BGP Prefix Reachability With Atal Networks<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">We operate global hosting infrastructure that includes dedicated servers, bare metal servers, VPS hosting, IPv4\/IPv6 services, private networking, BYOIP support, and multihomed network capabilities. About Atal Networks<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For customer-owned IPv4 or IPv6 prefixes, we recommend treating BGP deployment as an end-to-end routing process. The prefix, origin ASN, ROA, routing policy, upstream advertisement, local forwarding path, and return route should all be checked before production traffic moves to the new infrastructure.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A healthy BGP session is only one checkpoint. Reliable reachability depends on every stage between prefix origination and the destination server.<\/span><\/p>","protected":false},"excerpt":{"rendered":"<p>A BGP neighbor can show Established while the network behind that neighbor remains unreachable. This happens because the BGP session [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":24866,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[1],"tags":[],"class_list":["post-24865","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-grade-server"],"acf":[],"_links":{"self":[{"href":"https:\/\/atalnetworks.com\/nl\/wp-json\/wp\/v2\/posts\/24865","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/atalnetworks.com\/nl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/atalnetworks.com\/nl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/atalnetworks.com\/nl\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/atalnetworks.com\/nl\/wp-json\/wp\/v2\/comments?post=24865"}],"version-history":[{"count":1,"href":"https:\/\/atalnetworks.com\/nl\/wp-json\/wp\/v2\/posts\/24865\/revisions"}],"predecessor-version":[{"id":24867,"href":"https:\/\/atalnetworks.com\/nl\/wp-json\/wp\/v2\/posts\/24865\/revisions\/24867"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/atalnetworks.com\/nl\/wp-json\/wp\/v2\/media\/24866"}],"wp:attachment":[{"href":"https:\/\/atalnetworks.com\/nl\/wp-json\/wp\/v2\/media?parent=24865"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/atalnetworks.com\/nl\/wp-json\/wp\/v2\/categories?post=24865"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/atalnetworks.com\/nl\/wp-json\/wp\/v2\/tags?post=24865"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}