09 iBGP Split-Horizon & Full-Mesh
Because AS-PATH cannot prevent loops inside an AS, iBGP uses a different rule to stay loop-free. That rule has a major consequence: it forces a full mesh of iBGP sessions, which in turn creates the scalability problem that route reflectors and confederations solve.
The iBGP split-horizon rule
The fundamental rule of iBGP is: a prefix learned from one iBGP peer is never re-advertised to another iBGP peer.
The reason is loop prevention. Since the AS-PATH is not modified between internal peers (they share the same ASN), there is no way to detect an internal loop using AS-PATH. The safe preventive rule is therefore to not forward internally learned routes to other internal peers.
The consequence: full-mesh requirement
If no iBGP router re-advertises what it learned internally, then every iBGP router must peer directly with every other iBGP router, so that all of them receive the information directly. This is the full-mesh requirement.
A full mesh is not about efficiency; it is about reachability. Without it, some routers simply never learn certain prefixes. It is not that routing becomes slower, it is that some routes never arrive.
The scalability problem
A full mesh of n routers requires n(n-1)/2 iBGP sessions. This grows quadratically:
| Routers (n) | iBGP sessions |
|---|---|
| 5 | 10 |
| 10 | 45 |
| 20 | 190 |
| 50 | 1225 |
This explosive growth is what makes a full mesh impractical at scale, and it is precisely the problem that route reflectors (note 22) and confederations (note 23) exist to solve.
Why iBGP peers often use loopbacks
Because iBGP peers are frequently not directly connected and reach each other through the internal IGP, iBGP sessions are commonly sourced from loopback interfaces. A loopback never goes down as long as any path to it exists, so the session survives the failure of any single physical link as long as the IGP still has a route to the loopback.
Self-check
Q1 — What is the iBGP split-horizon rule?
A) A route learned from an iBGP peer is re-advertised to all other iBGP peers
B) A route learned from an iBGP peer is never re-advertised to another iBGP peer
C) A route learned from an eBGP peer is never sent to iBGP peers
D) iBGP routes are never installed in the routing table
Respuesta
B is correct. A prefix learned from one iBGP peer is not passed to another iBGP peer, because AS-PATH cannot detect internal loops.
- A) False — that is the opposite of the rule and would risk loops.
- C) False — eBGP-learned routes are advertised to iBGP peers normally.
- D) False — iBGP routes can be installed; the rule is about re-advertisement.
Q2 — Why does the split-horizon rule exist?
A) To save memory on internal routers
B) Because AS-PATH is not modified internally, so internal loops cannot be detected
C) Because iBGP has a higher Administrative Distance
D) Because iBGP uses multicast
Respuesta
B is correct. Internal peers share the same ASN, so AS-PATH does not change and cannot reveal a loop; the preventive rule is to not forward internally learned routes.
- A) False — the rule is about loop prevention, not memory.
- C) False — AD affects route preference, not this rule.
- D) False — BGP is unicast; multicast is unrelated.
Q3 — Why is a full mesh of iBGP sessions required?
A) For faster convergence
B) For reachability — without it, some routers never learn certain prefixes
C) To reduce the number of sessions
D) To enable eBGP multihop
Respuesta
B is correct. Because no router re-advertises internally learned routes, each must peer with every other so all receive the information; it is a reachability requirement, not an efficiency one.
- A) False — it is not about speed; missing meshes cause missing routes, not slow ones.
- C) False — a full mesh maximizes sessions, not reduces them.
- D) False — multihop is an eBGP feature, unrelated to the mesh.
Q4 — How many iBGP sessions does a full mesh of 10 routers require?
A) 10
B) 20
C) 45
D) 90
Respuesta
C is correct. n(n-1)/2 = 10(9)/2 = 45 sessions. This quadratic growth is what makes full mesh impractical at scale.
- A) False — 10 would be one per router, not a full mesh.
- B) False — 20 does not match the formula.
- D) False — 90 is n(n-1) without dividing by 2 (that counts each session twice).