03 BGP Messages

BGP uses four message types to establish sessions, exchange routes, and keep sessions alive. All BGP messages are unicast and are sent over TCP port 179.

The four message types

Open

Sent first, immediately after the TCP three-way handshake completes. Its purpose is to identify the router to its neighbor and negotiate operational parameters. If the parameters are not compatible, the session fails.

The Open message carries:

  • Version (both peers must use the same BGP version or the session will not establish)
  • Autonomous System number (this is what determines eBGP vs iBGP)
  • BGP Identifier (the Router ID)
  • Hold Time
  • Optional Parameters (for example authentication and multiprotocol support)

Keepalive

Sent to confirm acceptance of the parameters in the Open message, and periodically afterward to keep the session alive and prevent the Hold Time from expiring. Keepalives are sent by default every 60 seconds.

Update

Carries route information. A single Update message can:

  • Advertise new reachable prefixes as NLRI (Network Layer Reachability Information), together with their Path Attributes.
  • Withdraw routes that are no longer available (Withdrawn Routes).

So one Update can both add and remove routing information at the same time.

Notification

Sent when an error is detected in a session. A Notification always indicates a problem (misconfiguration, incompatible parameters, an administrative reset, etc.). Sending a Notification tears the session down and returns it toward Idle.

Timers

  • Keepalive: default 60 seconds.
  • Hold Time: default 180 seconds. This is the maximum time allowed without receiving a Keepalive or Update from the peer. If nothing is received within the Hold Time, the peer is declared down and the session drops.
  • The standard relationship is 1:3 — the Hold Time is three times the Keepalive interval.

Hold Time is negotiated to the lower value

If the two peers are configured with different Hold Times, the session uses the lower of the two values. This is negotiated during the Open exchange.

The BGP Identifier (Router ID)

The BGP Identifier carried in the Open message is the Router ID. When not set manually, it is chosen automatically in this order:

  1. Manually configured Router ID (always wins).
  2. Highest IP address on an active loopback interface.
  3. Highest IP address on an active physical interface.

Once selected, the Router ID does not update automatically if a better interface later appears; a reset is required. Manually configuring it is best practice. A duplicated Router ID between peers causes a collision and breaks the session.

Self-check

Q1 — When is the Open message sent?

A) Before the TCP three-way handshake
B) Immediately after the TCP three-way handshake completes
C) Only after the first Keepalive is received
D) At the same time as the first Update

Q2 — What can a single Update message do?

A) Only advertise new prefixes
B) Only withdraw unreachable routes
C) Both advertise new prefixes and withdraw routes at the same time
D) Keep the session alive when no routes change

Q3 — What does a Notification message indicate?

A) A normal, healthy step in keeping the session up
B) An error, which tears the session down
C) That new routes are available
D) That the Hold Time was successfully negotiated

Q4 — Default BGP timers on Cisco are:

A) Keepalive 30s, Hold Time 90s
B) Keepalive 60s, Hold Time 180s
C) Keepalive 180s, Hold Time 60s
D) Keepalive 60s, Hold Time 60s

Q5 — When two peers have different Hold Times configured, which is used?

A) The higher of the two
B) The lower of the two
C) The local router’s value always
D) They must match exactly or the session fails

Q6 — When the Router ID is not set manually, what is chosen first?

A) The lowest physical interface IP
B) The highest active loopback IP
C) The highest active physical interface IP
D) A random value