Define the contract before the session
In a fictional project connecting a fund platform to two partners, delivery requires reaching a service prefix and advertising only the approved source. Record peering addresses, local and remote AS, address family, allowed prefixes in each direction and ownership on both sides. The configured neighbor must match the actual TCP connection source rather than merely a familiar management address. Check the interface and reachability between peering addresses before changing route attributes. A successful ping tests ICMP; it does not establish TCP/179 access or agreement on BGP parameters. If a session never reaches Established, collect state and the last error on both sides before repeatedly restarting the process.
Established is one stage
An established session can accept zero prefixes. The partner may not originate the network, the family may be inactive, or a policy may reject advertisements. With FRR bgp ebgp-requires-policy, a missing input filter prevents route acceptance and a missing output filter prevents advertisement. The lab keeps this protection and deliberately starts without the edge router’s input policy. Its summary shows Policy despite an established session. Correct this by installing the approved specific policy rather than disabling protection merely to increase the count. Do not generalize FRR defaults across images: traditional and datacenter profiles have documented differences, and another product requires its own documentation.
Prefix and length are part of authorization
A permit 192.0.2.80/32 entry authorizes that host route. It does not automatically authorize 192.0.2.0/24 or every host within that /24. In the applied policy, advertisements without a permitting match are rejected. If a range of prefix lengths is required, express it explicitly and test ge and le boundaries. In the lab, both partners advertise.80/32 and.81/32, but edge should accept only.80/32. Evidence that.81 is absent matters alongside evidence that.80 is present. A BGP route-map acts on routes and attributes; it is not itself an application packet filter. Opening a data ACL does not fix a prefix-list rejecting the required advertisement.
Origination and reception need separate evidence
Writing network does not establish that a neighbor received a usable route. In the exercise’s FRR configuration, bgp network import-check requires the network in the RIB. Removing A’s service loopback address removes the local route supporting origination while leaving the BGP session available. Edge should then use B. Record the source’s local route, its outgoing advertisement and the destination’s accepted route; these are separate observations. Do not invent a discard route merely to satisfy origination without understanding where packets will go. A present route can also lose best-path selection or fail to enter effective forwarding. Follow the chain through the RIB and the device’s kernel table or FIB.
Change policy without losing the diagnosis
Before correcting a filter, record configuration, prefixes and the suspected cause. Apply the change in the correct direction and family and use a supported update mechanism to reevaluate advertisements. Negotiated route refresh can permit reevaluation without taking down the session; soft reconfiguration and retained data have their own requirements. A full reset affects routes and sessions and needs an operational justification. In the lab, changing SERVICE to.99/32 removes service from both paths while neighbors remain established. Restoring.80/32 recovers forwarding. At work, add a probe from the application’s actual source, validate return routing and retain evidence that unapproved prefixes remain rejected.
# FRR lab reading exercise, not production configuration:
ip prefix-list SERVICE seq 10 permit 192.0.2.80/32
route-map FROM-B permit 10
match ip address prefix-list SERVICE
set local-preference 200
# Under router bgp 65000 / address-family ipv4 unicast:
# neighbor 172.30.246.11 route-map FROM-B in
# Check the session, accepted prefixes, kernel route and return path.
The dashboard shows two Established neighbors but zero service routes. The operator identifies the missing import policy, applies only the approved prefix and verifies acceptance, forwarding and return routing.
Common pitfalls
Treating Established as an SLA; confusing /24 and /32; disabling filters to diagnose; fixing routing only with ACLs; creating routes without validating packet disposition.
Related topics: OSPF and RIB · ACL and control plane
Verify each stage: transport, session, origination, policy, selection, installation and service.
Reference: Configuring a Basic BGP Network · 350-401 ENCOR v1.2, effective 2026-03-19; core component of CCNP Enterprise