Cheat sheet

BGP Commands Cheat Sheet

BGP commands for Cisco IOS XE at CCNP depth, in build order: neighbors, iBGP over loopbacks, originating prefixes, path selection, filtering and verification. Values in <angle brackets> are yours to supply. Every command on this page was entered on an IOL-XE router running IOS XE 17.16.1a in Cisco Modeling Labs and accepted there, and the effect of each one was read back with a show command, so the syntax is what the image accepts.

1. Start BGP and define neighbors

All under 'router bgp'. BGP never discovers peers on its own: each one is a 'neighbor' line, and the AS you give it sets the session type.

CommandWhat it does
router bgp <asn>Start BGP. One process per router; <asn> is the number your peers put in their remote-as lines.
bgp router-id <a.b.c.d>Pin the router ID. Without it, BGP takes the highest loopback address, then the highest active interface address.
neighbor <ip> remote-as <asn>Define a peer. Your own AS makes it iBGP; any other AS makes it eBGP.
neighbor <ip> description <text>A free-text label for the peer, printed as 'Description:' at the top of show ip bgp neighbors.
neighbor <ip> password <string>TCP MD5 authentication. Set the same string on both ends; a changed key only applies to a new session, so reset the peer. With a key on one side only the session sits in Active and the log fills with %TCP-6-BADAUTH.
neighbor <ip> timers <keepalive> <holdtime>Per-peer timers. The session uses the lower hold time of the two peers, and a change applies after a hard reset.
timers bgp <keepalive> <holdtime>The same, for every peer that has no per-peer timers.
neighbor <ip> shutdownDisable the peer but keep its config. The summary shows Idle (Admin).

2. iBGP over loopbacks and multihop eBGP

iBGP peers usually use loopbacks reached through the IGP, so one failed link does not drop the session. eBGP sends with a TTL of 1 and expects a directly connected peer.

CommandWhat it does
neighbor <ip> update-source Loopback0Source the session from your loopback. The peer's neighbor line must name this address.
neighbor <ip> next-hop-selfSend iBGP peers your own address as the next hop. Without it, eBGP routes keep the external next hop, which the peer can use only if its IGP reaches that address.
neighbor <ip> ebgp-multihop <ttl>Raise the TTL so an eBGP peer can sit more than one hop away, as in loopback-to-loopback eBGP.
ip route <peer-loopback> 255.255.255.255 <next-hop>Global config: a route to the eBGP peer's loopback. The two ASes share no IGP, so a static route is the usual answer.
neighbor <ip> route-reflector-clientOn the reflector: pass iBGP-learned routes to this client. Without reflection, a route learned from one iBGP peer never reaches another, so iBGP needs a full mesh. Adding or removing the line resets that session.

3. Address families (IOS XE)

IOS XE accepts the per-family lines — network, aggregate-address, redistribute, next-hop-self and the per-peer policy lines — typed directly under 'router bgp', and while the default 'bgp default ipv4-unicast' is in force it prints them back flat there. Configure once inside 'address-family ipv4 unicast', or turn that default off, and the router re-files the same lines into an 'address-family ipv4' block with an explicit 'neighbor <ip> activate' per peer, keeping remote-as, update-source and ebgp-multihop above the block. Same configuration either way, and once the block appears it stays.

CommandWhat it does
no bgp default ipv4-unicastNew neighbors exchange no IPv4 routes until you activate them. Common on routers that carry several address families.
address-family ipv4 unicastEnter the IPv4 unicast family, where network, aggregate and per-peer policy lines live. The running config prints the block as 'address-family ipv4'.
neighbor <ip> activateTurn on IPv4 route exchange with the peer. Required once the default above is off, and in every other family.
exit-address-familyBack to router bgp.

4. Originate prefixes

'network' advertises a prefix only when that exact prefix and mask are already in the routing table. Leave off 'mask' and IOS assumes the classful mask (/16 for 172.16.0.0), which matches no subnetted route: with no /16 present, 'show ip bgp 172.16.0.0/16' answers '% Network not in table'. A classful pair is stored without the keyword, so 'network 172.16.0.0 mask 255.255.0.0' reads back as 'network 172.16.0.0'.

CommandWhat it does
network <prefix> mask <mask>Advertise a prefix that is in the routing table with exactly this mask. Origin code i.
ip route <prefix> <mask> Null0Global config: an anchor route, so a network line for a summary always finds its exact match.
redistribute static route-map <name>Inject static routes, limited by a route-map so nothing extra leaks. Origin code ?, shown as 'Origin incomplete'.
aggregate-address <prefix> <mask>Advertise a summary once any more-specific route is in the BGP table. The specifics are still sent.
aggregate-address <prefix> <mask> summary-onlyThe same, with the specifics suppressed (s in show ip bgp). The summary itself is installed as a local route to Null0 at distance 200.

5. Influence path selection

Weight never leaves the router. Local preference travels to iBGP peers, so it steers the whole AS's outbound traffic. AS-path prepending and MED go to the neighbor AS to influence how traffic comes back in. After any change, refresh the peer (group 11).

CommandWhat it does
neighbor <ip> weight <0-65535>Weight on every path from this peer. Highest wins; Cisco-only and local to this router.
bgp default local-preference <value>Replace the default local preference of 100. Highest wins, and the value is sent to iBGP peers.
route-map <name> permit <seq>Start a route-map entry. The match and set lines that follow belong to it.
set local-preference <value>Route-map: local preference for the matched routes. Usually applied inbound from an eBGP peer.
set as-path prepend <asn> [<asn> ...]Route-map: repeat your AS so the neighbor sees a longer, less preferred path. Usually applied outbound. A second prepend line replaces the first.
set metric <value>Route-map: the MED sent to a neighbor AS. Lowest wins. Usually applied outbound.
neighbor <ip> route-map <name> in|outRun the route-map on routes from this peer (in) or to it (out).
bgp always-compare-medCompare MED across paths from different neighbor ASes, not only within one.
maximum-paths <n>Install up to n tied eBGP paths instead of one. maximum-paths ibgp <n> does the same for iBGP, and show ip bgp <prefix> then prints a 'Multipath:' line.

6. Best-path order

IOS compares two paths step by step and stops at the first difference. A path whose next hop is unreachable is never a candidate.

StepPreferNotes
1. WeightHighestLocal to this router. Default 0; 32768 for paths it originates.
2. Local preferenceHighestShared across the AS. Default 100.
3. Locally originatedPaths this router originatednetwork or redistribute beats aggregate-address; the AIGP metric, where configured, is compared here.
4. AS pathShortestPrepending lengthens it.
5. Origini, then e, then ?IGP (network), EGP, incomplete (redistribute).
6. MEDLowestCompared only between paths from the same neighbor AS by default. A missing MED counts as 0.
7. Path typeeBGP over iBGPConfederation paths count as internal.
8. IGP metric to next hopLowestThe nearest exit.
9. MultipathTied pathsWith maximum-paths set, tied paths are installed together.
10. Oldest eBGP pathReceived firstOnly when both paths are external. Avoids churn when two eBGP paths tie.
11. Router IDLowestFor a reflected route, the originator ID.
12. Cluster listShortestRoute reflection only.
13. Neighbor addressLowestThe final tiebreaker.

7. Filter routes

Every prefix-list, AS-path list and route-map ends in an implicit deny, so a list that only denies drops everything: applied inbound it leaves State/PfxRcd at 0. Finish it with a permit — 'permit 0.0.0.0/0 le 32' in a prefix-list, 'permit .*' in an AS-path list, an empty permit entry in a route-map.

CommandWhat it does
ip prefix-list <name> seq <n> permit|deny <prefix>/<len> [ge <n>] [le <n>]Global config: match by prefix and length. The lengths must satisfy len < ge <= le <= 32.
neighbor <ip> prefix-list <name> in|outFilter the routes a peer sends you (in) or that you send it (out).
ip as-path access-list <n> permit|deny <regex>Global config: match the AS path with a regular expression (group 9).
neighbor <ip> filter-list <n> in|outFilter a peer's routes by AS path.
route-map <name> deny <seq>A route-map entry that drops whatever it matches.
match ip address prefix-list <name>Route-map: match routes by prefix-list.
match as-path <n>Route-map: match routes by AS-path list.
neighbor <ip> maximum-prefix <max> [<threshold>] [warning-only]Drop the session if the peer sends more than <max> prefixes; it stays in Idle (PfxCt) until cleared. <threshold> is the warning percentage (75 by default), and warning-only logs without dropping. Each maximum-prefix line replaces the previous one.

8. Prefix-list matching

With no ge or le, an entry matches one exact prefix and length. ge and le widen it to a range of lengths inside that prefix. To check one prefix against a list, run 'show ip prefix-list <name> <prefix>/<len> first-match' and read the entry it prints.

EntryMatches
172.16.0.0/16Only 172.16.0.0/16 itself
172.16.0.0/16 le 24172.16.0.0/16 and any subnet of it down to /24
172.16.0.0/16 ge 24 le 24Only the /24s inside 172.16.0.0/16
0.0.0.0/0Only the default route
0.0.0.0/0 le 32Every prefix, the usual final permit
0.0.0.0/0 le 24Any prefix of /24 or shorter
0.0.0.0/0 ge 32Host routes (/32) only

9. AS-path regular expressions

Test an expression with 'show ip bgp regexp <regex>' before you put it in a list. The underscore matches a space, a comma, a brace, or the start or end of the path.

RegexMatches
^$Routes originated inside your own AS (empty AS path)
^65002$Paths that are exactly 65002: routes the neighbor AS originated, unless it prepended its own AS
^65002_Every path that starts with 65002: routes from neighbor AS 65002, whether it originated them or passed them on
_65003$Routes originated by AS 65003, by any path
_65003_Routes that crossed AS 65003 anywhere in the path
.*Every route

10. Communities

A community is a tag carried with the route so policy on other routers can match it. Enable send-community toward every peer that should receive the tags.

CommandWhat it does
ip bgp-community new-formatGlobal config: show communities as AS:value instead of one 32-bit number.
set community <asn:nn> [additive]Route-map: tag the matched routes. Without additive, the new value replaces any existing communities.
neighbor <ip> send-communityInclude communities in updates to this peer. IOS stores it as 'send-community standard'.
show ip bgp community <asn:nn>List the routes that carry a community. show ip bgp <prefix> prints it as a 'Community:' line.

11. Apply policy changes

IOS does not re-run an edited policy over routes it already holds. Refresh the peer instead; a soft refresh keeps the session up.

CommandWhat it does
clear ip bgp <ip> soft inRe-run inbound policy on the peer's routes. The peer resends them, or IOS replays its stored copy if soft-reconfiguration is on.
clear ip bgp <ip> soft outResend your routes to the peer through outbound policy.
clear ip bgp * softBoth directions, every peer.
clear ip bgp <ip>Hard reset: drop the TCP session and rebuild it. Needed for timer and password changes; routes from the peer are withdrawn meanwhile.
neighbor <ip> soft-reconfiguration inboundKeep an unmodified copy of everything the peer sends. Costs memory; needed for received-routes.

12. Verify and troubleshoot

Start with the summary. A number under State/PfxRcd means Established with that many prefixes received; a word means the session is not up.

CommandWhat it does
show ip bgp summaryEvery peer with its AS, uptime and State/PfxRcd. The first command to run.
show bgp ipv4 unicast summaryThe same in address-family syntax, which also covers IPv6 and other families.
show ip bgpThe BGP table: every path, > on the best, with next hop, MED, local preference, weight and AS path.
show ip bgp <prefix>/<length>Every path to one prefix with all its attributes, and which one is best.
show ip route bgpBGP routes in the routing table: [20/x] from eBGP, [200/x] from iBGP.
show ip bgp neighbors <ip>Session detail: state, negotiated hold time, capabilities, message counts and the last reset reason.
show ip bgp neighbors <ip> routesWhat you accepted from this peer, after inbound policy.
show ip bgp neighbors <ip> advertised-routesWhat you are sending this peer, after outbound policy.
show ip bgp neighbors <ip> received-routesWhat the peer sent, before inbound policy. Answers '% Inbound soft reconfiguration not enabled' until soft-reconfiguration inbound is on.
show ip bgp regexp <regex>Routes whose AS path matches an expression.
show ip bgp filter-list <n>Routes an AS-path list permits.
show ip bgp prefix-list <name>Routes a prefix-list permits. Test a list here before you apply it.
show ip prefix-list <name>The list's entries with their sequence numbers.
show ip prefix-list detail <name>The same with a hit count per entry, so you can see which entry is doing the work.
show ip as-path-access-list [<n>]AS-path access lists and their entries.
show route-map <name>The route-map's entries in order, with their match and set clauses.
show ip bgp rib-failureBest paths BGP could not install, usually because a source with a lower administrative distance already has the prefix.

13. Session states

Idle and Active both mean the session is down. The cause is almost always reachability or a mismatch in the neighbor lines, not routing policy.

StateMeaningCheck first
IdleNot trying yet, or backing off after an errorA route to the neighbor address: show ip bgp neighbors reports 'the RIB does not have a route to <ip>' when there is none. Then, on a loopback-peered iBGP neighbor, update-source on both routers — the peer resets a connection from any other source while ping still succeeds. On a single-hop eBGP neighbor, the 'External BGP neighbor not directly connected.' line. Then read the last reset reason
Idle (Admin)The neighbor is shut down in the configRemove the neighbor shutdown line
Idle (PfxCt)The peer exceeded maximum-prefixWhy the peer sent more, then clear ip bgp <ip>
ConnectOpening the TCP connection to port 179Normally brief; if it sticks, treat it like Active
ActiveThe TCP connection failed and BGP is retryingAn ACL on TCP 179 — ping still works, so read show ip access-lists counters — or a password on one side only, which logs %TCP-6-BADAUTH
OpenSent / OpenConfirmTCP is up; OPEN and KEEPALIVE messages are being exchangedA wrong remote-as fails here: the router sends a notification, the summary flicks through Closing, and show ip bgp neighbors records 'peer in wrong AS' as the last reset reason
EstablishedRoutes are being exchangedState/PfxRcd shows a prefix count

14. Defaults and numbers

Values IOS uses when you configure nothing.

ItemValue
TransportTCP port 179
Keepalive / hold time60 s / 180 s; the session uses the lower hold time of the two peers
Administrative distanceeBGP 20, iBGP 200, local aggregate 200
Weight0 for learned paths, 32768 for paths this router originates
Local preference100
eBGP TTL1, so peers must be directly connected unless ebgp-multihop is set
iBGP next hopThe eBGP next hop, unchanged, unless next-hop-self is set
iBGP split horizonRoutes learned from one iBGP peer are not sent to another
Router IDbgp router-id, then highest loopback, then highest active interface
Private AS numbers64512-65534 and 4200000000-4294967294 (RFC 6996)

Frequently asked questions

What is the difference between weight and local preference?

Both choose an exit, and the higher value wins for both. Weight is Cisco-only, is checked first, and never leaves the router it is set on, so it changes only that router's choice. Local preference is a standard attribute sent to every iBGP peer, so setting it on one border router moves the whole AS to that exit.

Why does iBGP need next-hop-self?

A border router passes eBGP routes to its iBGP peers with the external next hop unchanged: the neighbor's address on the eBGP link. If the IGP does not carry that link, the iBGP peers have no route to the next hop and cannot use the path. 'neighbor <ip> next-hop-self' on the border router replaces the next hop with its own peering address, usually a loopback the IGP already carries.

Do I have to reset BGP after changing a route-map or prefix-list?

Not with a hard reset. IOS does not re-run an edited policy over routes it already holds, so refresh the peer: 'clear ip bgp <ip> soft in' for inbound policy, 'clear ip bgp <ip> soft out' for outbound. The session stays up. A plain 'clear ip bgp <ip>' drops the TCP session and every route learned over it; keep it for changes that only a new session picks up, such as timers and MD5 passwords.

How do I stop my AS from becoming a transit network?

Advertise only routes that originated inside your AS. The shortest filter permits the empty AS path: 'ip as-path access-list 1 permit ^$', applied to each eBGP peer with 'neighbor <ip> filter-list 1 out'. A prefix-list that permits only your own address blocks does the same job and is easier to read. Refresh with a soft out clear, then check 'show ip bgp neighbors <ip> advertised-routes'.

What do s, r, i and ? mean in show ip bgp?

The codes before the prefix are status codes: * valid, > best, i internal, meaning the path came from an iBGP peer, s suppressed by a summary-only aggregate, and r RIB-failure, meaning BGP chose the path but the routing table kept another source for that prefix. The code at the end of the line is the origin: i for a network statement or aggregate, ? for redistributed routes, and e for the obsolete EGP protocol.

Now build it

Labs that drill this on real Cisco IOS — configure it yourself, then grade your config against the answer key.

All BGP labs →

Stop memorizing — configure it on real Cisco IOS

A cheat sheet gets you unstuck; a graded lab makes it stick. Build one on real Cisco IOS and have your config graded.