cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7989
Views
5
Helpful
19
Replies

EBGP to iBGP works with physical interfaces but not with loopback interfaces

Amjad Abdullah
VIP Alumni
VIP Alumni

Hi everyone

 

I am tampering with BGP learning it..and I came across this issue.

I am posting the network diagram below. EBGP need to run between ASs. OSPF and iBGP are running inside AS2.

Now, between AS1 and AS2 (same for AS2 and AS3), if I use loopback interfaces (static routes are configured for reachability) as the update source, the advertised networks (loopback1 in my case) appears only in first router in AS2 and "show ip bgp 11.11.11.11" says that the IP 1.1.1.1 is inaccessible (It is already configured with a static route and appears clearly in the routing table and pingable from physical and loopback interfaces).

I am not able to understand why it says "inaccessible"!

I would expect the AS edge router of AS2 to know the route and pass it to other routers in AS2. I expect those other routers to complain about reachability. But I can see that the edge AS2 router itself is complaining and says the source is "inaccessible" although it can reach it by all means.

! This is AS1 router config
router bgp 1
 neighbor 2.2.2.2 remote-as 2
 neighbor 2.2.2.2 update-source Loopback0
 network 11.11.11.0 mask 255.255.255.0

 ! This is the relevant AS2 edge router config
router bgp 2
 neighbor 2.2.2.2 remote-as 2
 neighbor 2.2.2.2 update-source Loopback0

 

 Thanks for your help in advance.

 

Am

 Capture.PNG

 

 

Rating useful replies is more useful than saying "Thank you"
19 Replies 19

You had an empty post my friend. If you wanted to say something and it was erased by mistake, please write it again.

Rating useful replies is more useful than saying "Thank you"

Harold Ritter
Spotlight
Spotlight

By default, the ebgp next hop needs to be directly connected. You need to configure either , "neighbor ebgp-multihop" or "neighbor disable-connected-check" for it to work.

 

Regards,

Regards,
Harold Ritter, CCIE #4168 (EI, SP)

Thanks for your reply.
I am using ssl-security (as a replacement of the multihop command) which will increase the TTL to 2. Shouldn't this do the trick of the multi-hop issue? or you are meaning something else?

Rating useful replies is more useful than saying "Thank you"

Amjad Abdullah
VIP Alumni
VIP Alumni
Can anybody reproduce the issue?! I think it is interesting! I hope it is not buggy issue so we don't waste our investigations! BTW, I am using c3640-jk9s-mz.124-16 IOS image.
Rating useful replies is more useful than saying "Thank you"

Amjad Abdullah
VIP Alumni
VIP Alumni

Has anyone had any 'possible' solution for this issue??! 

Rating useful replies is more useful than saying "Thank you"