05 BGP Tables

BGP does not store routes in a single table. It maintains three conceptual structures per neighbor and per address family, which together explain how routes are received, filtered, selected, and advertised. Understanding them clarifies why a route can be present but not used, or received but not accepted.

The three RIBs

Adj-RIB-In

Holds the routes received from a specific peer, as they arrived, before any inbound policy is applied. This is the raw input from each neighbor. There is one Adj-RIB-In per peer.

Loc-RIB

The local BGP table: the routes that remain after inbound policy is applied, and where the best-path algorithm runs. This is what show ip bgp displays. The best path selected here is the one offered to the IP routing table and advertised onward.

Adj-RIB-Out

Holds the routes that will be advertised to a specific peer, after outbound policy is applied. There is one Adj-RIB-Out per peer.

The flow is: routes arrive into Adj-RIB-In → inbound policy → Loc-RIB (best-path runs) → outbound policy → Adj-RIB-Out → advertised to the peer.

Multiple routes per destination

The BGP table stores all valid routes to a destination, not just the winner. Only one route per destination is marked as best, installed into the routing table, and propagated to peers, but the table retains every candidate. This is why show ip bgp often shows several entries for the same prefix with only one marked best.

Reading the table

The show ip bgp output uses status markers and a path field. The two most important markers combine as *>:

MarkerMeaning
*Valid route (the next-hop is reachable)
>Best route (selected, installed, and propagated)

A route can be valid (*) without being best. For one destination you may see several * lines, but only one carries the >.

The Path field lists the ASN to cross to reach the destination, in order from nearest to farthest: the first ASN is the neighbor that advertised the route, and the last AS before the final letter is where the prefix originated. The final letter is the Origin code: i (IGP), e (EGP), or ? (incomplete).

Presence in the table does not reveal how a route was originated

To know how a route entered, read two fields: the Origin code (i / e / ?) and the next-hop. A next-hop of 0.0.0.0 means this router originated the prefix locally. A locally originated route also shows an empty path.

Table version

The table version is a counter that increments each time the BGP table changes. A version number that keeps climbing indicates instability (route flapping).

Self-check

Q1 — Which structure holds routes received from a peer before any inbound policy is applied?

A) Loc-RIB
B) Adj-RIB-In
C) Adj-RIB-Out
D) The IP routing table

Q2 — Does BGP keep more than one route to the same destination?

A) No, it only ever stores the single best route
B) Yes, it stores all valid routes but marks only one as best
C) Only when BGP Multipath is disabled
D) Only for iBGP-learned routes

Q3 — In show ip bgp, what does *> mean?

A) Suppressed and damped
B) Valid and best
C) Internal and external
D) Stale and backup

Q4 — Which table does show ip bgp display?

A) Adj-RIB-In
B) Adj-RIB-Out
C) Loc-RIB
D) The ARP table

Q5 — A next-hop of 0.0.0.0 with an empty path in the BGP table means:

A) The route is invalid
B) This router originated the prefix locally
C) The route came from an eBGP peer
D) The route is being withdrawn