27 MP-BGP & Address Families
Multiprotocol BGP (MP-BGP) extends BGP to carry more than just IPv4 unicast routes. It is the foundation for BGP over IPv6 and for overlay technologies like MPLS L3VPN and EVPN. The organizing concept is the address family.
Why MP-BGP exists
Original BGP only understood IPv4 unicast. MP-BGP adds two new attributes, MP_REACH_NLRI and MP_UNREACH_NLRI, that carry reachability information for any address family inside the same Update messages. This is why a single BGP session can handle several types of routes.
MP-BGP can carry, among others: IPv4 unicast and multicast, IPv6 unicast and multicast, and VPNv4/VPNv6 for MPLS L3VPN. (Older references also list AppleTalk and IPX, which are obsolete and no longer used.)
Address families
The address family (AF) is the organizing structure of MP-BGP. Each route type (IPv4 unicast, IPv6 unicast, VPNv4, and so on) is configured in its own address-family section within the BGP process.
The session with a neighbor is one, but the neighbor must be activated per address family for each family you want to exchange with it. This is the same address-family model seen in OSPFv3.
Activation behavior
By default, IOS automatically activates each neighbor in the IPv4 unicast family as soon as it is declared with neighbor ... remote-as. The command no bgp default ipv4-unicast disables this automatic activation, forcing you to explicitly activate each neighbor in each family with neighbor <ip> activate inside the address-family. This is used in clean MP-BGP configurations so an IPv6-only neighbor is not accidentally activated for IPv4.
The Router ID across families
The Router ID is unique per BGP process, not per address family. It is configured once and applies to all families, so setting it again inside another family is optional if already set. Manually configuring it remains best practice.
Dual stack
Running both IPv4 and IPv6 has two approaches:
- Recommended: peer IPv4 over an IPv4-transport session and IPv6 over an IPv6-transport session, so two separate TCP sessions each carry their own family. The next-hop resolves correctly in each protocol.
- Alternative: a single session (for example IPv4 transport) carrying both families. It works, but the next-hop for IPv6 routes can be malformed (an IPv4 next-hop for IPv6 routes), requiring route-map adjustments. Less clean.
Relevance beyond the basics
MP-BGP is the base for MPLS L3VPN (VPNv4/VPNv6) and EVPN (for VXLAN in data centers), both heavily used in service provider and data center networks. The address-family model learned here is the foundation for those overlays.
Self-check
Q1 — What lets MP-BGP carry more than IPv4 unicast?
A) A separate TCP session per route type is mandatory
B) The MP_REACH_NLRI and MP_UNREACH_NLRI attributes carry any address family in the same Updates
C) It converts all routes to IPv4 first
D) It uses UDP instead of TCP
Respuesta
B is correct. MP-BGP adds MP_REACH_NLRI and MP_UNREACH_NLRI, which carry reachability for any address family inside the same Update messages, so one session handles multiple route types.
- A) False — a single session can carry multiple families; separate sessions are one option, not a requirement.
- C) False — it does not convert everything to IPv4.
- D) False — BGP still runs over TCP.
Q2 — In MP-BGP, how does a neighbor start exchanging a given address family?
A) Automatically for all families once declared
B) It must be activated per address family withneighbor <ip> activate
C) By raising the TTL
D) By configuring a separate Router ID per family
Respuesta
B is correct. The session is one, but the neighbor is activated per address family for each family you want to exchange.
- A) False — only IPv4 unicast is auto-activated by default; others need explicit activation.
- C) False — TTL is unrelated to family activation.
- D) False — the Router ID is per process, not per family.
Q3 — What does
no bgp default ipv4-unicastdo?A) Disables IPv6 entirely
B) Disables the automatic activation of neighbors in the IPv4 unicast family
C) Removes the Router ID
D) Turns off MP-BGP
Respuesta
B is correct. It disables IOS’s automatic IPv4-unicast activation, so you must explicitly activate each neighbor per family, preventing an IPv6-only neighbor from being activated for IPv4 by accident.
- A) False — it does not disable IPv6; it stops auto-activating IPv4.
- C) False — it does not affect the Router ID.
- D) False — it does not turn off MP-BGP; it makes activation explicit.
Q4 — In the recommended dual-stack approach, how are IPv4 and IPv6 peered?
A) One session carrying both families
B) Separate sessions: IPv4 over IPv4 transport and IPv6 over IPv6 transport
C) Over UDP for IPv6
D) By converting IPv6 next-hops to IPv4
Respuesta
B is correct. The recommended approach uses separate TCP sessions, each carrying its own family, so the next-hop resolves correctly in each protocol.
- A) False — a single session carrying both works but can malform the IPv6 next-hop; it is the less clean alternative.
- C) False — BGP uses TCP, not UDP.
- D) False — converting next-hops is a workaround for the single-session case, not the recommended design.