26 AS-PATH ACLs & Regular Expressions

An AS-PATH ACL filters routes based on the AS-PATH attribute (which AS appear in the path), using regular expressions to match. This is the tool that answers “which path,” complementing prefix-based filtering which answers “which network.”

Two ways to apply an AS-PATH ACL

  • Directly to BGP with a filter-list, which permits or denies routes based on their AS-PATH.
  • Associated with a route-map using match as-path, which selects routes so their attributes can then be modified (Local Preference, MED, and so on).

In both cases the AS-PATH ACL is a matching tool, like a prefix-list, but it inspects the AS-PATH instead of the prefix.

Regular expression characters

The regex operates on the AS-PATH string. The key characters:

CharacterMatches
_A space, comma, start of the string, or end of the string (used to bound an exact ASN)
^Start of the string (AS-PATH)
$End of the string (AS-PATH)
[]Any single symbol inside the brackets (a set)
.Any single character, including a space
|Logical OR (the value before or after)
?The preceding element appears zero or one time (optional)
*The preceding element repeats zero or more times
+The preceding element repeats one or more times
-A range between two values (inside brackets)

Two corrections worth noting, because course material often states them wrong:

  • + means one or more times (not exactly one).
  • ? means zero or one (optional), not “any value.”

Common expressions

These are the patterns most worth memorizing:

  • ^$ → an empty AS-PATH = routes originated in your own AS.
  • .* → matches everything (used for permit .* to allow all routes).
  • _65000$ → routes originated in AS 65000 (last in the path = the origin).
  • ^65000_ → routes received directly from AS 65000 (first in the path = the direct neighbor).
  • _65000_ → routes that pass through AS 65000 in any position.

filter-list vs distribute-list

They filter on different things and are complementary:

  • filter-list → filters by AS-PATH (which AS are in the path). Uses an AS-PATH ACL.
  • distribute-list / prefix-list → filters by prefix (which network).

Knowing which to use for a given requirement is a core skill: one inspects the path, the other the destination.

Testing expressions

show ip bgp regexp <expression> filters the BGP table output to show only routes whose AS-PATH matches the regex. This is useful for testing an expression before applying it in a filter.

Self-check

Q1 — What does an AS-PATH ACL filter on?

A) The prefix and its length
B) The AS-PATH (which AS appear in the path)
C) The next-hop
D) The community

Q2 — What does the expression ^$ match?

A) Every route
B) Routes with an empty AS-PATH, originated in your own AS
C) Routes ending in AS 0
D) Routes received directly from a neighbor

Q3 — What does _65000$ match?

A) Routes received directly from AS 65000
B) Routes originated in AS 65000 (last in the path)
C) Routes that never touch AS 65000
D) All routes containing any AS

Q4 — Which correction about regex characters is accurate?

A) + means exactly one time
B) + means one or more times, and ? means zero or one (optional)
C) ? means any value
D) * means one or more times