Learning hub

BGP: study hub

BGP is the path-vector protocol that routes between autonomous systems, and the one where policy — not a metric — decides where traffic goes. This CCNP hub ties the concepts to step-by-step guides, a command cheat sheet, and graded hands-on labs, from a first eBGP session to steering traffic with weight, local preference and filters.

eBGP at the edges, iBGP across the middle — the reference wiring for this topic, not a specific lab.

BGP, in reading order

Border Gateway Protocol carries reachability between autonomous systems — what the public internet runs on. It is not on the CCNA 200-301 blueprint: eBGP peering and best-path selection sit in CCNP ENCOR, the heavier policy work in ENARSI, and Cisco revises blueprints, so confirm current scope on Cisco's exam page. BGP discovers nothing: you name every peer by address and AS number, the session runs over TCP port 179, and each router advertises one best path per prefix with the attributes describing it. Administrative distance is 20 for eBGP and 200 for iBGP, so an external BGP route outranks OSPF's 110 and an internal one does not.

Everything starts with a session reaching Established. neighbor 10.0.13.2 remote-as 65002 is the whole definition: a different AS number makes the session external, the same one makes it internal, and eBGP sends packets with a TTL of 1, so the peer must be directly connected unless you add ebgp-multihop. Idle and Active both mean down: Idle usually means no route to the neighbor address, Active a TCP connection that keeps failing while BGP retries. A wrong remote-as never settles into a state you can read — it fails during the OPEN exchange and is recorded as the last reset reason.

A session that is up advertises nothing on its own. network 172.16.1.0 mask 255.255.255.0 is a condition, not an injection: originate that prefix only if the routing table already holds that exact network and mask. A /24 in the table against a /16 in the statement produces silence, not an error. The alternatives differ: redistribute takes what the IGP or a static route already holds and marks the origin incomplete; aggregate-address advertises a summary built from more specific prefixes already in the BGP table.

Inside one AS, two rules catch people out. A route learned from one iBGP peer is never re-advertised to another, so every iBGP speaker has to hear a prefix directly — classically a full mesh, with route reflectors as the ENARSI answer. And a prefix learned over eBGP keeps its external next hop when it crosses to an iBGP peer, so the far router holds a path whose next hop it cannot reach, and BGP marks it inaccessible rather than selecting it. next-hop-self rewrites the next hop, and update-source Loopback0 peers over loopbacks the IGP already carries.

BGP picks exactly one best path per prefix, comparing candidates step by step and stopping at the first difference; a path whose next hop is unreachable never enters the comparison. Weight comes first: highest wins, 0 on learned paths and 32768 on those this router originates, and it is never advertised. Local preference is next: highest wins, default 100, and it travels to every iBGP peer, so it is how a whole AS agrees on an exit. Then locally originated paths, the shortest AS path, the origin code and the lowest MED. To steer traffic coming back, you lengthen the path with set as-path prepend, which the neighbor AS may ignore.

Policy is applied per neighbor and per direction, which decides whether a filter does anything. A prefix-list matches a network and mask, with ge and le opening the mask into a range, and ends in an implicit deny; an AS-path access-list matches the path itself with a regular expression, where ^$ matches an empty path: a route originated inside your own AS. Nothing takes effect until you refresh the peer in the direction you changed: clear ip bgp <ip> soft in for inbound policy, clear ip bgp <ip> soft out for outbound. Work the guides in order, keep the BGP Commands Cheat Sheet open for syntax, and let the graded labs say whether the policy you wrote is the one the router applied.

Practice on real Cisco IOS

Build and grade hands-on Cisco Modeling Labs — the only way it sticks.

Now build it

Labs that drill this on real Cisco IOS — configure it yourself, then grade your config against the answer key.

Browse every lab →

Related study hubs

Frequently asked questions

Is BGP on the CCNA exam?

No. For routing protocols the CCNA 200-301 blueprint stops at static routing and single-area OSPFv2. BGP is CCNP material: eBGP peering, path attributes and best-path selection appear in ENCOR, with the deeper policy, filtering and troubleshooting work in ENARSI. Cisco revises blueprints between exam versions, so treat any statement of scope as approximate and confirm the current details on Cisco's own exam page. It is still worth learning early, because BGP is what runs at every internet edge and at every multihomed enterprise.

If iBGP already runs inside my AS, why do I still need an IGP?

Because they carry different things. BGP peers are configured by address rather than discovered, so something has to make the peer's address reachable first — that is the IGP's job, and it is why iBGP sessions are usually built between loopbacks that OSPF or EIGRP advertises. The IGP also resolves BGP next hops: a path is only a candidate if the router has a route to its next hop. The split is deliberate. The IGP carries a small set of internal links and loopbacks and converges fast; BGP carries the external prefixes, which you never want inside an IGP.

In what order should I learn BGP?

Follow the reading order on this page, because each step is what breaks the next one. Bring up a single eBGP session and confirm it reaches Established. Learn to read Idle and Active properly, since both simply mean the session is down. Then originate prefixes and meet the exact-match rule the network statement enforces. Next add a second router in your own AS, which is where update-source and next-hop-self become necessary. Only then move to path selection and filtering — policy is meaningful only once you have two paths to choose between.

What grading looks like

This is what grading your config looks like

A sample result — 4 of 5 requirements met. This is exactly what you see the moment you submit.

bgp-lab-export.yaml — read 3 device configs

Score: 80% — Keep going (4 of 5 checks passed)

  • Passed: BGP process running as AS 65001 on R1
  • Passed: eBGP neighbor 10.0.13.2 in AS 65002
  • Passed: Session to 10.0.13.2 is Established
  • Passed: 172.16.1.0/24 originated by an exact match
  • Failed: next-hop-self toward the iBGP peer — missing on R2
Solution revealed

The full node-by-node answer key unlocks the moment you submit — so you see exactly what you missed.

Study every CCNA topic this way

The CCNA Complete Path sequences the lab bundles into one graded progression, fundamentals first.