network-bgp-diagnostics
affaan-m/ecc
Read-only BGP troubleshooting: diagnose neighbor state, route exchange, and policy issues safely.
What is network-bgp-diagnostics?
Diagnostics-only patterns for troubleshooting BGP sessions that are down, flapping, or missing routes. Covers neighbor state interpretation, transport validation, route policy inspection, and safe evidence collection—all without making changes. Use this when you need to understand why a BGP session failed or is not exchanging expected prefixes.
- Identify exact neighbor, ASN, VRF, and address-family context before diving into diagnostics
- Capture BGP summary state, last reset reason, and neighbor details to establish baseline
- Validate reachability to peer source address and confirm TCP connectivity on port 179
- Inspect route-maps, prefix-lists, and max-prefix limits to detect policy-based filtering
- Parse BGP summary output and route tables to compare advertised, received, and installed prefixes
- Distinguish between transport failures, authentication issues, and route policy problems using state-specific checks
How to install network-bgp-diagnostics
npx skills add null --skill network-bgp-diagnosticsHow to use network-bgp-diagnostics
- 1.Run `show bgp summary` to identify the neighbor IP, remote ASN, and current state (Established, Active, Idle, etc.).
- 2.Run `show bgp neighbors <peer>` and `show logging | include BGP` to capture the last reset reason and any recent errors.
- 3.Validate transport: run `ping <peer> source <local-source>` and `show ip route <peer>` to confirm reachability.
- 4.Check route policy: run `show bgp neighbors <peer> advertised-routes` and `show route-map <name>` to inspect filtering rules.
- 5.Compare prefix counts: use `show bgp neighbors <peer> routes` (or platform equivalent) to see received vs. advertised vs. installed prefixes.
- 6.Document findings in a structured format (use the provided parser pattern for BGP summary) and escalate to a change window if a reset or config change is needed.
Use cases
- A BGP neighbor is stuck in Active or OpenConfirm state; diagnose whether it is a reachability, authentication, or timer mismatch issue.
- An Established session shows zero prefixes received; check inbound policy, max-prefix limits, and AFI/SAFI configuration.
- Routes are missing from the routing table despite being advertised by the peer; inspect route-maps and prefix-lists.
- Collecting before/after evidence for a planned BGP configuration change in a change window.
- Parsing BGP summary output in automation to detect state changes and trigger alerts without making unsupervised resets.
- Network engineers troubleshooting BGP connectivity and route exchange issues
- Automation engineers building BGP monitoring and alerting systems
- Network operators reviewing BGP incidents and collecting evidence for root-cause analysis
- DevOps teams validating BGP state during infrastructure deployments
network-bgp-diagnostics FAQ
Never during incident triage. Always read the last reset reason and logs first. If a reset is approved in a change window, prefer soft-reset or route-refresh to minimize disruption.
The TCP session and BGP handshake succeeded, but no routes are being received. Check inbound route-maps, max-prefix limits, AFI/SAFI configuration, and whether the peer is actually advertising routes.
Run `show route-map <name>` to see the rules, then run `show bgp neighbors <peer> advertised-routes` to see what the peer is sending, and compare against what appears in `show bgp neighbors <peer> routes` (received).
Active means TCP is not completing. Check: (1) routing to the peer source address, (2) firewall/ACL rules blocking port 179, (3) the peer's listener is actually running, (4) source address configuration on both sides.
No. Enabling received-route storage is a configuration change that should happen in a change window with approval, not during triage. Use other commands to infer what routes arrived.
Full instructions (SKILL.md)
Source of truth, from affaan-m/ecc.
name: network-bgp-diagnostics description: Diagnostics-only BGP troubleshooting patterns for neighbor state, route exchange, prefix policy, AS path inspection, and safe evidence collection. metadata: origin: community
Network BGP Diagnostics
Use this skill when a BGP session is down, flapping, established with missing routes, or advertising unexpected prefixes. The default workflow is read-only evidence collection; policy and reset actions belong in a reviewed change window.
When to Use
- BGP neighbors are stuck in Idle, Connect, Active, OpenSent, or OpenConfirm.
- A session is Established but expected prefixes are missing.
- A route-map, prefix-list, max-prefix limit, or AS path policy may be filtering routes.
- You need before/after evidence for a BGP change.
- You are reviewing automation that parses BGP summary output.
Read-Only Triage Flow
- Identify the exact neighbor, address family, VRF, and local/remote ASNs.
- Capture summary state and last reset reason.
- Prove reachability to the peer source address.
- Check route policy references before assuming transport failure.
- Compare advertised, received, and installed routes where the platform supports those commands.
show bgp summary
show bgp neighbors <peer>
show ip route <peer>
show tcp brief | include <peer>|:179
show logging | include BGP|<peer>
show running-config | section router bgp
show ip prefix-list
show route-map
Use platform-specific address-family commands when the device uses VRFs, IPv6, VPNv4, or EVPN. Do not assume global IPv4 unicast.
State Interpretation
| State | First checks |
|---|---|
| Established with prefix count | Route exchange is up; inspect policy and table selection |
| Established with zero prefixes | Check inbound policy, max-prefix, advertised routes, and AFI/SAFI |
| Active | TCP session is not completing; check routing, source, ACLs, and peer reachability |
| Connect | TCP connection is in progress; check path and remote listener |
| OpenSent/OpenConfirm | TCP works; check ASN, authentication, timers, capabilities, and logs |
| Idle | Neighbor may be disabled, missing config, blocked by policy, or backoff timer |
Transport Checks
ping <peer> source <local-source>
traceroute <peer> source <local-source>
show ip route <peer>
show bgp neighbors <peer> | include BGP state|Last reset|Local host|Foreign host
If the peer is sourced from a loopback, confirm both directions route to the loopback addresses and that the neighbor config uses the expected update source.
Avoid disabling ACLs or firewall policy as a diagnostic shortcut. Read hit counters, logs, and path state first.
Route Policy Checks
show bgp neighbors <peer> advertised-routes
show bgp neighbors <peer> routes
show ip prefix-list <name>
show route-map <name>
show bgp <prefix>
Some platforms require additional configuration before received-routes is
available. Do not add that configuration during incident triage unless the
operator approves the change.
AS Path And Prefix Review
show bgp regexp _65001_
show bgp regexp ^65001$
show bgp <prefix>
show bgp neighbors <peer> advertised-routes | include Network|Path|<prefix>
Use AS-path regex carefully. _65001_ matches AS 65001 as a token. Plain
65001 can match longer ASNs or unrelated text.
Parser Pattern
import re
from typing import Any
BGP_SUMMARY_RE = re.compile(
r"^(?P<neighbor>\d{1,3}(?:\.\d{1,3}){3})\s+"
r"(?P<version>\d+)\s+"
r"(?P<remote_as>\d+)\s+"
r"(?P<msg_rcvd>\d+)\s+"
r"(?P<msg_sent>\d+)\s+"
r"(?P<table_version>\d+)\s+"
r"(?P<input_queue>\d+)\s+"
r"(?P<output_queue>\d+)\s+"
r"(?P<uptime>\S+)\s+"
r"(?P<state_or_prefixes>\S+)$",
re.M,
)
def parse_bgp_summary(raw: str) -> list[dict[str, Any]]:
rows = []
for match in BGP_SUMMARY_RE.finditer(raw):
state_or_prefixes = match.group("state_or_prefixes")
if state_or_prefixes.isdigit():
state = "Established"
prefixes_received = int(state_or_prefixes)
else:
state = state_or_prefixes
prefixes_received = None
rows.append({
"neighbor": match.group("neighbor"),
"remote_as": int(match.group("remote_as")),
"state": state,
"prefixes_received": prefixes_received,
"uptime": match.group("uptime"),
})
return rows
Prefer structured parser output when available, but store raw output with the incident record because BGP summary formats vary by platform and address family.
Change-Window Only
These actions can affect routing and should not be suggested as automatic diagnostics:
- Clearing a BGP session.
- Changing neighbor authentication, timers, update source, route-maps, or prefix-lists.
- Enabling additional received-route storage.
- Relaxing firewall, ACL, or control-plane policy.
If a reset is approved, prefer the least disruptive soft or route-refresh option supported by the platform and document exactly why it is safe.
Anti-Patterns
- Assuming
Activealways means the remote side is down. - Ignoring VRF, address family, or update-source differences.
- Using broad AS-path regex without token boundaries.
- Hard-resetting a peer before reading last reset reason and logs.
- Treating missing
received-routesoutput as proof that no routes arrived.
See Also
- Skill:
cisco-ios-patterns - Skill:
network-config-validation - Skill:
network-interface-health
Related skills
More from affaan-m/ecc and the wider catalog.
network-config-validation
Pre-deployment validation for Cisco IOS/IOS-XE configs: dangerous commands, IP conflicts, stale references, and security hygiene.
network-interface-health
Diagnose physical link, duplex, and congestion issues by analyzing interface error and drop counters on routers, switches, and Linux hosts.
nextjs-turbopack
Next.js 16+ incremental bundler with Rust-powered Turbopack for 5–14x faster dev startup and HMR.
nodejs-keccak256
Use Ethereum's Keccak-256, not Node's NIST SHA3, to prevent silent hashing bugs in selectors, signatures, and addresses.
nutrient-document-processing
Convert, extract, OCR, redact, sign, and fill documents via Nutrient DWS API.
nuxt4-patterns
Nuxt 4 patterns for SSR hydration, route rules, lazy loading, and safe data fetching.