03 BGP Messages
BGP uses four message types to establish sessions, exchange routes, and keep sessions alive. All BGP messages are unicast and are sent over TCP port 179.
The four message types
Open
Sent first, immediately after the TCP three-way handshake completes. Its purpose is to identify the router to its neighbor and negotiate operational parameters. If the parameters are not compatible, the session fails.
The Open message carries:
- Version (both peers must use the same BGP version or the session will not establish)
- Autonomous System number (this is what determines eBGP vs iBGP)
- BGP Identifier (the Router ID)
- Hold Time
- Optional Parameters (for example authentication and multiprotocol support)
Keepalive
Sent to confirm acceptance of the parameters in the Open message, and periodically afterward to keep the session alive and prevent the Hold Time from expiring. Keepalives are sent by default every 60 seconds.
Update
Carries route information. A single Update message can:
- Advertise new reachable prefixes as NLRI (Network Layer Reachability Information), together with their Path Attributes.
- Withdraw routes that are no longer available (Withdrawn Routes).
So one Update can both add and remove routing information at the same time.
Notification
Sent when an error is detected in a session. A Notification always indicates a problem (misconfiguration, incompatible parameters, an administrative reset, etc.). Sending a Notification tears the session down and returns it toward Idle.
Timers
- Keepalive: default 60 seconds.
- Hold Time: default 180 seconds. This is the maximum time allowed without receiving a Keepalive or Update from the peer. If nothing is received within the Hold Time, the peer is declared down and the session drops.
- The standard relationship is 1:3 — the Hold Time is three times the Keepalive interval.
Hold Time is negotiated to the lower value
If the two peers are configured with different Hold Times, the session uses the lower of the two values. This is negotiated during the Open exchange.
The BGP Identifier (Router ID)
The BGP Identifier carried in the Open message is the Router ID. When not set manually, it is chosen automatically in this order:
- Manually configured Router ID (always wins).
- Highest IP address on an active loopback interface.
- Highest IP address on an active physical interface.
Once selected, the Router ID does not update automatically if a better interface later appears; a reset is required. Manually configuring it is best practice. A duplicated Router ID between peers causes a collision and breaks the session.
Self-check
Q1 — When is the Open message sent?
A) Before the TCP three-way handshake
B) Immediately after the TCP three-way handshake completes
C) Only after the first Keepalive is received
D) At the same time as the first Update
Respuesta
B is correct. The Open is the first BGP message, sent right after the TCP three-way handshake, to identify the router and negotiate parameters.
- A) False — BGP rides on TCP, so nothing is sent before the handshake.
- C) False — the Keepalive comes later, in the OpenConfirm stage.
- D) False — Updates are only exchanged once the session reaches Established.
Q2 — What can a single Update message do?
A) Only advertise new prefixes
B) Only withdraw unreachable routes
C) Both advertise new prefixes and withdraw routes at the same time
D) Keep the session alive when no routes change
Respuesta
C is correct. One Update can carry new NLRI (with Path Attributes) and Withdrawn Routes simultaneously.
- A) False — advertising NLRI is only half; it can also withdraw.
- B) False — withdrawing is only half; it can also carry new NLRI.
- D) False — keeping the session alive with no change is the Keepalive’s job.
Q3 — What does a Notification message indicate?
A) A normal, healthy step in keeping the session up
B) An error, which tears the session down
C) That new routes are available
D) That the Hold Time was successfully negotiated
Respuesta
B is correct. A Notification always signals an error (misconfiguration, incompatible parameters, administrative reset) and drops the session toward Idle.
- A) False — Notification is never routine.
- C) False — advertising routes is the Update’s job.
- D) False — Hold Time is negotiated inside the Open exchange.
Q4 — Default BGP timers on Cisco are:
A) Keepalive 30s, Hold Time 90s
B) Keepalive 60s, Hold Time 180s
C) Keepalive 180s, Hold Time 60s
D) Keepalive 60s, Hold Time 60s
Respuesta
B is correct. Cisco defaults are Keepalive 60s and Hold Time 180s, a 1:3 ratio. Hold Time is the max time allowed without hearing from the peer.
- A) False — 30/90 keeps the ratio but is not the Cisco default.
- C) False — the values are reversed; Keepalive is the short timer.
- D) False — equal values break the 1:3 ratio and would drop the session almost immediately.
Q5 — When two peers have different Hold Times configured, which is used?
A) The higher of the two
B) The lower of the two
C) The local router’s value always
D) They must match exactly or the session fails
Respuesta
B is correct. The lower of the two configured Hold Times is used, negotiated during the Open exchange.
- A) False — the higher value is not chosen.
- C) False — it is negotiated, not simply the local value.
- D) False — they need not match; the lower one is agreed automatically.
Q6 — When the Router ID is not set manually, what is chosen first?
A) The lowest physical interface IP
B) The highest active loopback IP
C) The highest active physical interface IP
D) A random value
Respuesta
B is correct. With no manual Router ID, the highest active loopback IP is used; only if no loopback exists does it fall to the highest active physical interface IP.
- A) False — selection is by highest, not lowest, and loopback is preferred.
- C) False — physical is used only when no loopback is available.
- D) False — the choice is deterministic, not random.