BGP Commands Cheat Sheet
BGP commands for Cisco IOS XE at CCNP depth, in build order: neighbors, iBGP over loopbacks, originating prefixes, path selection, filtering and verification. Values in <angle brackets> are yours to supply. Every command on this page was entered on an IOL-XE router running IOS XE 17.16.1a in Cisco Modeling Labs and accepted there, and the effect of each one was read back with a show command, so the syntax is what the image accepts.
Part of the BGP learning hub
1. Start BGP and define neighbors
All under 'router bgp'. BGP never discovers peers on its own: each one is a 'neighbor' line, and the AS you give it sets the session type.
| Command | What it does |
|---|---|
router bgp <asn> | Start BGP. One process per router; <asn> is the number your peers put in their remote-as lines. |
bgp router-id <a.b.c.d> | Pin the router ID. Without it, BGP takes the highest loopback address, then the highest active interface address. |
neighbor <ip> remote-as <asn> | Define a peer. Your own AS makes it iBGP; any other AS makes it eBGP. |
neighbor <ip> description <text> | A free-text label for the peer, printed as 'Description:' at the top of show ip bgp neighbors. |
neighbor <ip> password <string> | TCP MD5 authentication. Set the same string on both ends; a changed key only applies to a new session, so reset the peer. With a key on one side only the session sits in Active and the log fills with %TCP-6-BADAUTH. |
neighbor <ip> timers <keepalive> <holdtime> | Per-peer timers. The session uses the lower hold time of the two peers, and a change applies after a hard reset. |
timers bgp <keepalive> <holdtime> | The same, for every peer that has no per-peer timers. |
neighbor <ip> shutdown | Disable the peer but keep its config. The summary shows Idle (Admin). |
2. iBGP over loopbacks and multihop eBGP
iBGP peers usually use loopbacks reached through the IGP, so one failed link does not drop the session. eBGP sends with a TTL of 1 and expects a directly connected peer.
| Command | What it does |
|---|---|
neighbor <ip> update-source Loopback0 | Source the session from your loopback. The peer's neighbor line must name this address. |
neighbor <ip> next-hop-self | Send iBGP peers your own address as the next hop. Without it, eBGP routes keep the external next hop, which the peer can use only if its IGP reaches that address. |
neighbor <ip> ebgp-multihop <ttl> | Raise the TTL so an eBGP peer can sit more than one hop away, as in loopback-to-loopback eBGP. |
ip route <peer-loopback> 255.255.255.255 <next-hop> | Global config: a route to the eBGP peer's loopback. The two ASes share no IGP, so a static route is the usual answer. |
neighbor <ip> route-reflector-client | On the reflector: pass iBGP-learned routes to this client. Without reflection, a route learned from one iBGP peer never reaches another, so iBGP needs a full mesh. Adding or removing the line resets that session. |
3. Address families (IOS XE)
IOS XE accepts the per-family lines — network, aggregate-address, redistribute, next-hop-self and the per-peer policy lines — typed directly under 'router bgp', and while the default 'bgp default ipv4-unicast' is in force it prints them back flat there. Configure once inside 'address-family ipv4 unicast', or turn that default off, and the router re-files the same lines into an 'address-family ipv4' block with an explicit 'neighbor <ip> activate' per peer, keeping remote-as, update-source and ebgp-multihop above the block. Same configuration either way, and once the block appears it stays.
| Command | What it does |
|---|---|
no bgp default ipv4-unicast | New neighbors exchange no IPv4 routes until you activate them. Common on routers that carry several address families. |
address-family ipv4 unicast | Enter the IPv4 unicast family, where network, aggregate and per-peer policy lines live. The running config prints the block as 'address-family ipv4'. |
neighbor <ip> activate | Turn on IPv4 route exchange with the peer. Required once the default above is off, and in every other family. |
exit-address-family | Back to router bgp. |
4. Originate prefixes
'network' advertises a prefix only when that exact prefix and mask are already in the routing table. Leave off 'mask' and IOS assumes the classful mask (/16 for 172.16.0.0), which matches no subnetted route: with no /16 present, 'show ip bgp 172.16.0.0/16' answers '% Network not in table'. A classful pair is stored without the keyword, so 'network 172.16.0.0 mask 255.255.0.0' reads back as 'network 172.16.0.0'.
| Command | What it does |
|---|---|
network <prefix> mask <mask> | Advertise a prefix that is in the routing table with exactly this mask. Origin code i. |
ip route <prefix> <mask> Null0 | Global config: an anchor route, so a network line for a summary always finds its exact match. |
redistribute static route-map <name> | Inject static routes, limited by a route-map so nothing extra leaks. Origin code ?, shown as 'Origin incomplete'. |
aggregate-address <prefix> <mask> | Advertise a summary once any more-specific route is in the BGP table. The specifics are still sent. |
aggregate-address <prefix> <mask> summary-only | The same, with the specifics suppressed (s in show ip bgp). The summary itself is installed as a local route to Null0 at distance 200. |
5. Influence path selection
Weight never leaves the router. Local preference travels to iBGP peers, so it steers the whole AS's outbound traffic. AS-path prepending and MED go to the neighbor AS to influence how traffic comes back in. After any change, refresh the peer (group 11).
| Command | What it does |
|---|---|
neighbor <ip> weight <0-65535> | Weight on every path from this peer. Highest wins; Cisco-only and local to this router. |
bgp default local-preference <value> | Replace the default local preference of 100. Highest wins, and the value is sent to iBGP peers. |
route-map <name> permit <seq> | Start a route-map entry. The match and set lines that follow belong to it. |
set local-preference <value> | Route-map: local preference for the matched routes. Usually applied inbound from an eBGP peer. |
set as-path prepend <asn> [<asn> ...] | Route-map: repeat your AS so the neighbor sees a longer, less preferred path. Usually applied outbound. A second prepend line replaces the first. |
set metric <value> | Route-map: the MED sent to a neighbor AS. Lowest wins. Usually applied outbound. |
neighbor <ip> route-map <name> in|out | Run the route-map on routes from this peer (in) or to it (out). |
bgp always-compare-med | Compare MED across paths from different neighbor ASes, not only within one. |
maximum-paths <n> | Install up to n tied eBGP paths instead of one. maximum-paths ibgp <n> does the same for iBGP, and show ip bgp <prefix> then prints a 'Multipath:' line. |
6. Best-path order
IOS compares two paths step by step and stops at the first difference. A path whose next hop is unreachable is never a candidate.
| Step | Prefer | Notes |
|---|---|---|
1. Weight | Highest | Local to this router. Default 0; 32768 for paths it originates. |
2. Local preference | Highest | Shared across the AS. Default 100. |
3. Locally originated | Paths this router originated | network or redistribute beats aggregate-address; the AIGP metric, where configured, is compared here. |
4. AS path | Shortest | Prepending lengthens it. |
5. Origin | i, then e, then ? | IGP (network), EGP, incomplete (redistribute). |
6. MED | Lowest | Compared only between paths from the same neighbor AS by default. A missing MED counts as 0. |
7. Path type | eBGP over iBGP | Confederation paths count as internal. |
8. IGP metric to next hop | Lowest | The nearest exit. |
9. Multipath | Tied paths | With maximum-paths set, tied paths are installed together. |
10. Oldest eBGP path | Received first | Only when both paths are external. Avoids churn when two eBGP paths tie. |
11. Router ID | Lowest | For a reflected route, the originator ID. |
12. Cluster list | Shortest | Route reflection only. |
13. Neighbor address | Lowest | The final tiebreaker. |
7. Filter routes
Every prefix-list, AS-path list and route-map ends in an implicit deny, so a list that only denies drops everything: applied inbound it leaves State/PfxRcd at 0. Finish it with a permit — 'permit 0.0.0.0/0 le 32' in a prefix-list, 'permit .*' in an AS-path list, an empty permit entry in a route-map.
| Command | What it does |
|---|---|
ip prefix-list <name> seq <n> permit|deny <prefix>/<len> [ge <n>] [le <n>] | Global config: match by prefix and length. The lengths must satisfy len < ge <= le <= 32. |
neighbor <ip> prefix-list <name> in|out | Filter the routes a peer sends you (in) or that you send it (out). |
ip as-path access-list <n> permit|deny <regex> | Global config: match the AS path with a regular expression (group 9). |
neighbor <ip> filter-list <n> in|out | Filter a peer's routes by AS path. |
route-map <name> deny <seq> | A route-map entry that drops whatever it matches. |
match ip address prefix-list <name> | Route-map: match routes by prefix-list. |
match as-path <n> | Route-map: match routes by AS-path list. |
neighbor <ip> maximum-prefix <max> [<threshold>] [warning-only] | Drop the session if the peer sends more than <max> prefixes; it stays in Idle (PfxCt) until cleared. <threshold> is the warning percentage (75 by default), and warning-only logs without dropping. Each maximum-prefix line replaces the previous one. |
8. Prefix-list matching
With no ge or le, an entry matches one exact prefix and length. ge and le widen it to a range of lengths inside that prefix. To check one prefix against a list, run 'show ip prefix-list <name> <prefix>/<len> first-match' and read the entry it prints.
| Entry | Matches |
|---|---|
172.16.0.0/16 | Only 172.16.0.0/16 itself |
172.16.0.0/16 le 24 | 172.16.0.0/16 and any subnet of it down to /24 |
172.16.0.0/16 ge 24 le 24 | Only the /24s inside 172.16.0.0/16 |
0.0.0.0/0 | Only the default route |
0.0.0.0/0 le 32 | Every prefix, the usual final permit |
0.0.0.0/0 le 24 | Any prefix of /24 or shorter |
0.0.0.0/0 ge 32 | Host routes (/32) only |
9. AS-path regular expressions
Test an expression with 'show ip bgp regexp <regex>' before you put it in a list. The underscore matches a space, a comma, a brace, or the start or end of the path.
| Regex | Matches |
|---|---|
^$ | Routes originated inside your own AS (empty AS path) |
^65002$ | Paths that are exactly 65002: routes the neighbor AS originated, unless it prepended its own AS |
^65002_ | Every path that starts with 65002: routes from neighbor AS 65002, whether it originated them or passed them on |
_65003$ | Routes originated by AS 65003, by any path |
_65003_ | Routes that crossed AS 65003 anywhere in the path |
.* | Every route |
10. Communities
A community is a tag carried with the route so policy on other routers can match it. Enable send-community toward every peer that should receive the tags.
| Command | What it does |
|---|---|
ip bgp-community new-format | Global config: show communities as AS:value instead of one 32-bit number. |
set community <asn:nn> [additive] | Route-map: tag the matched routes. Without additive, the new value replaces any existing communities. |
neighbor <ip> send-community | Include communities in updates to this peer. IOS stores it as 'send-community standard'. |
show ip bgp community <asn:nn> | List the routes that carry a community. show ip bgp <prefix> prints it as a 'Community:' line. |
11. Apply policy changes
IOS does not re-run an edited policy over routes it already holds. Refresh the peer instead; a soft refresh keeps the session up.
| Command | What it does |
|---|---|
clear ip bgp <ip> soft in | Re-run inbound policy on the peer's routes. The peer resends them, or IOS replays its stored copy if soft-reconfiguration is on. |
clear ip bgp <ip> soft out | Resend your routes to the peer through outbound policy. |
clear ip bgp * soft | Both directions, every peer. |
clear ip bgp <ip> | Hard reset: drop the TCP session and rebuild it. Needed for timer and password changes; routes from the peer are withdrawn meanwhile. |
neighbor <ip> soft-reconfiguration inbound | Keep an unmodified copy of everything the peer sends. Costs memory; needed for received-routes. |
12. Verify and troubleshoot
Start with the summary. A number under State/PfxRcd means Established with that many prefixes received; a word means the session is not up.
| Command | What it does |
|---|---|
show ip bgp summary | Every peer with its AS, uptime and State/PfxRcd. The first command to run. |
show bgp ipv4 unicast summary | The same in address-family syntax, which also covers IPv6 and other families. |
show ip bgp | The BGP table: every path, > on the best, with next hop, MED, local preference, weight and AS path. |
show ip bgp <prefix>/<length> | Every path to one prefix with all its attributes, and which one is best. |
show ip route bgp | BGP routes in the routing table: [20/x] from eBGP, [200/x] from iBGP. |
show ip bgp neighbors <ip> | Session detail: state, negotiated hold time, capabilities, message counts and the last reset reason. |
show ip bgp neighbors <ip> routes | What you accepted from this peer, after inbound policy. |
show ip bgp neighbors <ip> advertised-routes | What you are sending this peer, after outbound policy. |
show ip bgp neighbors <ip> received-routes | What the peer sent, before inbound policy. Answers '% Inbound soft reconfiguration not enabled' until soft-reconfiguration inbound is on. |
show ip bgp regexp <regex> | Routes whose AS path matches an expression. |
show ip bgp filter-list <n> | Routes an AS-path list permits. |
show ip bgp prefix-list <name> | Routes a prefix-list permits. Test a list here before you apply it. |
show ip prefix-list <name> | The list's entries with their sequence numbers. |
show ip prefix-list detail <name> | The same with a hit count per entry, so you can see which entry is doing the work. |
show ip as-path-access-list [<n>] | AS-path access lists and their entries. |
show route-map <name> | The route-map's entries in order, with their match and set clauses. |
show ip bgp rib-failure | Best paths BGP could not install, usually because a source with a lower administrative distance already has the prefix. |
13. Session states
Idle and Active both mean the session is down. The cause is almost always reachability or a mismatch in the neighbor lines, not routing policy.
| State | Meaning | Check first |
|---|---|---|
Idle | Not trying yet, or backing off after an error | A route to the neighbor address: show ip bgp neighbors reports 'the RIB does not have a route to <ip>' when there is none. Then, on a loopback-peered iBGP neighbor, update-source on both routers — the peer resets a connection from any other source while ping still succeeds. On a single-hop eBGP neighbor, the 'External BGP neighbor not directly connected.' line. Then read the last reset reason |
Idle (Admin) | The neighbor is shut down in the config | Remove the neighbor shutdown line |
Idle (PfxCt) | The peer exceeded maximum-prefix | Why the peer sent more, then clear ip bgp <ip> |
Connect | Opening the TCP connection to port 179 | Normally brief; if it sticks, treat it like Active |
Active | The TCP connection failed and BGP is retrying | An ACL on TCP 179 — ping still works, so read show ip access-lists counters — or a password on one side only, which logs %TCP-6-BADAUTH |
OpenSent / OpenConfirm | TCP is up; OPEN and KEEPALIVE messages are being exchanged | A wrong remote-as fails here: the router sends a notification, the summary flicks through Closing, and show ip bgp neighbors records 'peer in wrong AS' as the last reset reason |
Established | Routes are being exchanged | State/PfxRcd shows a prefix count |
14. Defaults and numbers
Values IOS uses when you configure nothing.
| Item | Value |
|---|---|
Transport | TCP port 179 |
Keepalive / hold time | 60 s / 180 s; the session uses the lower hold time of the two peers |
Administrative distance | eBGP 20, iBGP 200, local aggregate 200 |
Weight | 0 for learned paths, 32768 for paths this router originates |
Local preference | 100 |
eBGP TTL | 1, so peers must be directly connected unless ebgp-multihop is set |
iBGP next hop | The eBGP next hop, unchanged, unless next-hop-self is set |
iBGP split horizon | Routes learned from one iBGP peer are not sent to another |
Router ID | bgp router-id, then highest loopback, then highest active interface |
Private AS numbers | 64512-65534 and 4200000000-4294967294 (RFC 6996) |
Frequently asked questions
What is the difference between weight and local preference?
Both choose an exit, and the higher value wins for both. Weight is Cisco-only, is checked first, and never leaves the router it is set on, so it changes only that router's choice. Local preference is a standard attribute sent to every iBGP peer, so setting it on one border router moves the whole AS to that exit.
Why does iBGP need next-hop-self?
A border router passes eBGP routes to its iBGP peers with the external next hop unchanged: the neighbor's address on the eBGP link. If the IGP does not carry that link, the iBGP peers have no route to the next hop and cannot use the path. 'neighbor <ip> next-hop-self' on the border router replaces the next hop with its own peering address, usually a loopback the IGP already carries.
Do I have to reset BGP after changing a route-map or prefix-list?
Not with a hard reset. IOS does not re-run an edited policy over routes it already holds, so refresh the peer: 'clear ip bgp <ip> soft in' for inbound policy, 'clear ip bgp <ip> soft out' for outbound. The session stays up. A plain 'clear ip bgp <ip>' drops the TCP session and every route learned over it; keep it for changes that only a new session picks up, such as timers and MD5 passwords.
How do I stop my AS from becoming a transit network?
Advertise only routes that originated inside your AS. The shortest filter permits the empty AS path: 'ip as-path access-list 1 permit ^$', applied to each eBGP peer with 'neighbor <ip> filter-list 1 out'. A prefix-list that permits only your own address blocks does the same job and is easier to read. Refresh with a soft out clear, then check 'show ip bgp neighbors <ip> advertised-routes'.
What do s, r, i and ? mean in show ip bgp?
The codes before the prefix are status codes: * valid, > best, i internal, meaning the path came from an iBGP peer, s suppressed by a summary-only aggregate, and r RIB-failure, meaning BGP chose the path but the routing table kept another source for that prefix. The code at the end of the line is the origin: i for a network statement or aggregate, ? for redistributed routes, and e for the obsolete EGP protocol.
Now build it
Labs that drill this on real Cisco IOS — configure it yourself, then grade your config against the answer key.
Stop memorizing — configure it on real Cisco IOS
A cheat sheet gets you unstuck; a graded lab makes it stick. Build one on real Cisco IOS and have your config graded.