Catalog
affaan-m/network-bgp-diagnostics

affaan-m

network-bgp-diagnostics

Diagnostics-only BGP troubleshooting patterns for neighbor state, route exchange, prefix policy, AS path inspection, and safe evidence collection. Use when a BGP neighbor is down, routes are missing, or prefix policy and AS path need inspection.

NewUpdated Sep 9, 2026

Network BGP Diagnostics

Use this skill when a BGP session is down, flapping, established with missing routes, or advertising unexpected prefixes. The default workflow is read-only evidence collection; policy and reset actions belong in a reviewed change window.

When to Use

  • BGP neighbors are stuck in Idle, Connect, Active, OpenSent, or OpenConfirm.
  • A session is Established but expected prefixes are missing.
  • A route-map, prefix-list, max-prefix limit, or AS path policy may be filtering routes.
  • You need before/after evidence for a BGP change.
  • You are reviewing automation that parses BGP summary output.

Read-Only Triage Flow

  1. Identify the exact neighbor, address family, VRF, and local/remote ASNs.
  2. Capture summary state and last reset reason.
  3. Prove reachability to the peer source address.
  4. Check route policy references before assuming transport failure.
  5. Compare advertised, received, and installed routes where the platform supports those commands.
show bgp summary
show bgp neighbors <peer>
show ip route <peer>
show tcp brief | include <peer>|:179
show logging | include BGP|<peer>
show running-config | section router bgp
show ip prefix-list
show route-map

Use platform-specific address-family commands when the device uses VRFs, IPv6, VPNv4, or EVPN. Do not assume global IPv4 unicast.

State Interpretation

State First checks
Established with prefix count Route exchange is up; inspect policy and table selection
Established with zero prefixes Check inbound policy, max-prefix, advertised routes, and AFI/SAFI
Active TCP session is not completing; check routing, source, ACLs, and peer reachability
Connect TCP connection is in progress; check path and remote listener
OpenSent/OpenConfirm TCP works; check ASN, authentication, timers, capabilities, and logs
Idle Neighbor may be disabled, missing config, blocked by policy, or backoff timer

Transport Checks

ping <peer> source <local-source>
traceroute <peer> source <local-source>
show ip route <peer>
show bgp neighbors <peer> | include BGP state|Last reset|Local host|Foreign host

If the peer is sourced from a loopback, confirm both directions route to the loopback addresses and that the neighbor config uses the expected update source.

Avoid disabling ACLs or firewall policy as a diagnostic shortcut. Read hit counters, logs, and path state first.

Route Policy Checks

show bgp neighbors <peer> advertised-routes
show bgp neighbors <peer> routes
show ip prefix-list <name>
show route-map <name>
show bgp <prefix>

Some platforms require additional configuration before received-routes is available. Do not add that configuration during incident triage unless the operator approves the change.

AS Path And Prefix Review

show bgp regexp _65001_
show bgp regexp ^65001$
show bgp <prefix>
show bgp neighbors <peer> advertised-routes | include Network|Path|<prefix>

Use AS-path regex carefully. _65001_ matches AS 65001 as a token. Plain 65001 can match longer ASNs or unrelated text.

Parser Pattern

import re
from typing import Any

BGP_SUMMARY_RE = re.compile(
    r"^(?P<neighbor>\d{1,3}(?:\.\d{1,3}){3})\s+"
    r"(?P<version>\d+)\s+"
    r"(?P<remote_as>\d+)\s+"
    r"(?P<msg_rcvd>\d+)\s+"
    r"(?P<msg_sent>\d+)\s+"
    r"(?P<table_version>\d+)\s+"
    r"(?P<input_queue>\d+)\s+"
    r"(?P<output_queue>\d+)\s+"
    r"(?P<uptime>\S+)\s+"
    r"(?P<state_or_prefixes>\S+)$",
    re.M,
)

def parse_bgp_summary(raw: str) -> list[dict[str, Any]]:
    rows = []
    for match in BGP_SUMMARY_RE.finditer(raw):
        state_or_prefixes = match.group("state_or_prefixes")
        if state_or_prefixes.isdigit():
            state = "Established"
            prefixes_received = int(state_or_prefixes)
        else:
            state = state_or_prefixes
            prefixes_received = None
        rows.append({
            "neighbor": match.group("neighbor"),
            "remote_as": int(match.group("remote_as")),
            "state": state,
            "prefixes_received": prefixes_received,
            "uptime": match.group("uptime"),
        })
    return rows

Prefer structured parser output when available, but store raw output with the incident record because BGP summary formats vary by platform and address family.

Change-Window Only

These actions can affect routing and should not be suggested as automatic diagnostics:

  • Clearing a BGP session.
  • Changing neighbor authentication, timers, update source, route-maps, or prefix-lists.
  • Enabling additional received-route storage.
  • Relaxing firewall, ACL, or control-plane policy.

If a reset is approved, prefer the least disruptive soft or route-refresh option supported by the platform and document exactly why it is safe.

Anti-Patterns

  • Assuming Active always means the remote side is down.
  • Ignoring VRF, address family, or update-source differences.
  • Using broad AS-path regex without token boundaries.
  • Hard-resetting a peer before reading last reset reason and logs.
  • Treating missing received-routes output as proof that no routes arrived.

See Also

  • Skill: cisco-ios-patterns
  • Skill: network-config-validation
  • Skill: network-interface-health
Files1
1 files · 1.0 KB

Select a file to preview

Overall Score

88/100

Grade

A

Excellent

Grades are signals, not a certification. Always review a skill yourself before use.

Safety

92

Quality

86

Clarity

87

Completeness

82

Summary

This skill provides read-only BGP troubleshooting diagnostics for network operators, covering neighbor state interpretation, route policy inspection, transport verification, and safe evidence collection. It emphasizes non-destructive investigation patterns and explicitly defers state-changing operations (resets, config changes) to reviewed change windows, making it a structured triage guide for BGP incidents.

Detected Capabilities

command-execution (read-only network commands)log inspectionconfiguration review (read-only)regex pattern parsingroute table inspectionAS path analysis

Trigger Keywords

Phrases that agents use to match this skill to user intent.

bgp neighbor downbgp state troubleshootmissing bgp routesbgp policy inspectroute-map diagnosticsbgp as path checkbgp session flappingprefix policy review

Risk Signals

INFO

No destructive commands or privilege escalation patterns detected

full document
INFO

Explicit prohibition of state-changing operations (session resets, config edits)

Change-Window Only section
INFO

Guidance to read ACL/firewall counters rather than modify them

Transport Checks section
INFO

Network device access required but scope limited to read-only diagnostic commands

Read-Only Triage Flow, all command blocks

Use Cases

  • Diagnosing why a BGP neighbor is stuck in Idle, Active, or OpenConfirm state
  • Investigating missing or unexpected routes on an established BGP session
  • Inspecting route-map, prefix-list, and AS path policies to identify filtering or policy mismatches
  • Collecting evidence (state snapshots, logs, route output) before/after a BGP configuration change
  • Learning BGP state machine behavior and state transition indicators
  • Validating BGP automation output parsing with regex patterns for show bgp summary

Quality Notes

  • Excellent scope boundaries: skill is explicitly limited to read-only diagnostics and evidence collection
  • Clear anti-patterns section helps operators avoid common pitfalls (hard resets before log review, ignoring VRF context)
  • Well-structured state interpretation table with decision logic for each BGP state
  • Practical Python parser example demonstrates regex pattern for real-world show output
  • Transport, policy, and AS path checks are logically grouped with platform-agnostic guidance
  • Defers change actions to reviewed change windows, setting appropriate expectations for incident response
  • Warnings about platform differences (VRF, AFI/SAFI, address family) prevent over-generalization
  • Good reference to related skills for escalation paths
  • Includes common gotchas (token boundaries in AS-path regex, loopback sourcing confusion)
Model: claude-haiku-4-5-20251001Analyzed: Sep 9, 2026

Reviews

Add this skill to your library to leave a review.

No reviews yet

Be the first to share your experience.

Version History

  1. v2.0

    Contract changed: description

    ✦ AIClarifies skill activation triggers in description: BGP neighbor down, missing routes, or prefix/AS path inspection needed.

    triggering2026-09-09

    LATEST
  2. v1.1

    Content updated

    ✦ AINo material changes detected between versions.

    2026-07-14

    View This Version
  3. v1.0

    2026-05-15

    View This VersionInitial version

Use affaan-m/network-bgp-diagnostics in your dev environment

Command Palette

Search for a command to run...