08 AS-PATH Loop Prevention (eBGP)
AS-PATH serves two purposes in BGP: it is used to select the best path (shortest AS-PATH wins), and it is used to prevent routing loops between Autonomous Systems. This note focuses on the loop-prevention role, which applies specifically to eBGP.
The eBGP loop-prevention mechanism
When a prefix is advertised across an eBGP boundary, the advertising router prepends its own ASN to the AS-PATH. This building AS-PATH becomes the basis for loop detection.
The rule is: if a router receives an update whose AS-PATH already contains its own ASN, it discards the update. The logic is that if its own AS already appears in the path, the route has already passed through this AS, so accepting it would create a loop.
Why this is eBGP-specific
This mechanism only works for eBGP, because the ASN is prepended only when crossing an AS boundary.
Inside a single AS (iBGP), the AS-PATH is not modified between internal peers, since they all share the same ASN. Because no ASN is added internally, AS-PATH cannot reveal an internal loop. Loop prevention inside the AS therefore relies on a different mechanism: the iBGP split-horizon rule (covered in note 09), which in turn drives the need for route reflectors and confederations.
AS-PATH also drives best-path
Although this note is about loops, remember the second role: in best-path selection, the route with the shorter AS-PATH is preferred. “Shorter” means fewer AS to cross, not the numeric value of the ASN, and it counts AS traversed, not router hops. A single AS may contain many internal routers and still counts as one entry in the AS-PATH.
When the loop check gets in the way
In certain designs the rejection of routes carrying your own ASN becomes a problem rather than a protection. Two examples:
- MPLS VPN or hub-and-spoke topologies where a site legitimately needs to receive a prefix whose AS-PATH contains its own ASN.
- Situations solved with
allowas-in(accept routes containing your own ASN) oras-override(replace the customer’s ASN in the AS-PATH).
These are exceptions used deliberately; the default behavior remains to discard such updates.
Self-check
Q1 — What are the two roles of AS-PATH in BGP?
A) Setting the next-hop and negotiating timers
B) Best-path selection (shortest wins) and loop prevention
C) Authentication and summarization
D) Assigning Administrative Distance and Weight
Respuesta
B is correct. AS-PATH is used both to choose the best path (shorter AS-PATH preferred) and to prevent inter-AS loops.
- A) False — next-hop and timers are separate mechanisms.
- C) False — AS-PATH is not about authentication or summarization.
- D) False — AD and Weight are unrelated to AS-PATH.
Q2 — How does eBGP detect and prevent a loop?
A) It compares Router IDs
B) It discards an update whose AS-PATH already contains its own ASN
C) It checks the next-hop reachability
D) It rejects routes with a Hold Time mismatch
Respuesta
B is correct. If an incoming update’s AS-PATH already includes the router’s own ASN, the route has already passed through this AS, so it is discarded to avoid a loop.
- A) False — Router ID comparison is not the eBGP loop check.
- C) False — next-hop reachability affects validity, not loop detection.
- D) False — Hold Time mismatches concern session setup, not loops.
Q3 — Why does AS-PATH loop prevention not work inside an AS (iBGP)?
A) Because iBGP strips the AS-PATH
B) Because the ASN is only prepended when crossing an AS boundary, so no ASN is added internally
C) Because iBGP uses Local Preference instead
D) Because internal routers ignore the AS-PATH
Respuesta
B is correct. The ASN is prepended only across eBGP boundaries. Between iBGP peers (same ASN) the AS-PATH is unchanged, so it cannot expose an internal loop; the split-horizon rule handles that instead.
- A) False — the AS-PATH is not stripped, only left unmodified.
- C) False — Local Preference is a best-path attribute, not a loop mechanism.
- D) False — internal routers still carry the AS-PATH; it just does not change internally.
Q4 — In best-path terms, a "shorter AS-PATH" means:
A) The path with the lowest numeric ASN values
B) The path crossing the fewest AS, counting AS traversed rather than router hops
C) The path with the fewest internal routers
D) The path with the smallest Router ID
Respuesta
B is correct. Shorter AS-PATH means fewer AS to cross; it counts AS traversed, not router hops, and not the numeric size of the ASN. One AS counts as one entry regardless of how many routers it contains.
- A) False — the numeric value of the ASN is irrelevant.
- C) False — internal routers inside an AS do not add to the AS-PATH.
- D) False — Router ID is a final tiebreaker, not the AS-PATH length.