Guided buildadvanced8 steps~25 min5 devices
Two providers, one eBGP session
Connect two autonomous systems, bring up an eBGP session between their border routers, and announce each provider's customer blocks to the other.
What you'll be able to do: Two autonomous systems exchange their customer prefixes over one eBGP session: each provider learns the other's blocks as B routes with the far AS in the path, and a brand-new customer block becomes reachable from the other network with one `network` line and no change on the far side.
Topics: BGP · eBGP · Dynamic routing · Routing tables
What you'll build
- ISP-A — a router, the border router of the first provider, AS 65001
- WEB-A — a server, a server hosted by the first provider
- ISP-B — a router, the border router of the second provider, AS 65002
- PC-B — a pc, a customer of the second provider
- PC-B2 — a pc, the second provider's new customer, added last
Step by step
1. Stand up the first provider
Drag a router and a server onto the canvas, cable the server into Gi0/0 and name the router ISP-A. This provider is autonomous system 65001 and hosts 198.51.100.0/24 — a block the rest of the internet only finds if ISP-A tells it the block exists.
- Cable WEB-A Eth0 ↔ ISP-A Gi0/0
On ISP-A — Name the first provider's router and address its customer LAN
enable configure terminal hostname ISP-A interface Gi0/0 ip address 198.51.100.1 255.255.255.0 no shutdown exit endOn WEB-A — Name the server and set address, mask and gateway
hostname WEB-A ipconfig Eth0 198.51.100.10 255.255.255.0 198.51.100.1Check: run
show ip routeon ISP-A and look forC 198.51.100.0/24 is directly connected, Gi0/0.Why: An autonomous system is a network run by one organisation under one routing policy — a provider, a university, a large company. Between autonomous systems the internet runs a single protocol, BGP, and the thing it carries is a prefix like this /24.
2. Stand up the second provider
A second router and a second autonomous system: ISP-B is AS 65002 and hosts 203.0.113.0/24, with a customer's PC on it. Two networks, each complete on its own, neither aware the other exists.
- Cable PC-B Eth0 ↔ ISP-B Gi0/0
On ISP-B — Name the second provider's router and address its customer LAN
enable configure terminal hostname ISP-B interface Gi0/0 ip address 203.0.113.1 255.255.255.0 no shutdown exit endOn PC-B — Name the customer PC and point it at its gateway
hostname PC-B ipconfig Eth0 203.0.113.10 255.255.255.0 203.0.113.1Check: run
show ip routeon ISP-B and look forC 203.0.113.0/24 is directly connected, Gi0/0.Why: AS numbers are handed out by the same registries that hand out IP blocks. 64512 to 65534 are private — the AS equivalent of RFC 1918 space — which is why labs, and customers that connect to a single provider, use numbers from that range.
3. Cable the interconnect
Run a serial cable between the two routers' Se0/0/0 ports and number it 10.0.0.0/30: .1 for ISP-A, .2 for ISP-B. The two border routers can ping each other now — but WEB-A still can't reach PC-B, because a cable between two networks is not a route between them.
- Cable ISP-A Se0/0/0 ↔ ISP-B Se0/0/0 (serial)
On ISP-A — Address ISP-A's end of the interconnect
enable configure terminal interface Se0/0/0 ip address 10.0.0.1 255.255.255.252 no shutdown exit endOn ISP-B — Address ISP-B's end of the interconnect
enable configure terminal interface Se0/0/0 ip address 10.0.0.2 255.255.255.252 no shutdown exit endCheck: run
show ip routeon ISP-A and look forC 10.0.0.0/30 is directly connected, Se0/0/0.Why: Providers meet at private interconnects or exchange points and number the link between them by agreement. The link is plumbing: it exists so the two border routers can talk, and neither provider needs to tell the world about it.
4. Open BGP at ISP-A — and wait
Start BGP for AS 65001, name ISP-B's address as a neighbour in AS 65002, and announce ISP-A's customer block. Then read `show ip bgp summary`: the neighbour sits in Active. BGP never goes looking for peers — it opens a session only to an address you name, and nothing at 10.0.0.2 is answering yet.
On ISP-A — Configure ISP-A's half of the peering and announce its block
enable configure terminal router bgp 65001 bgp router-id 1.1.1.1 neighbor 10.0.0.2 remote-as 65002 network 198.51.100.0 mask 255.255.255.0 endOn WEB-A — Try the other provider's customer — this one is supposed to fail
ping 203.0.113.10Check: run
show ip bgp summaryon ISP-A and look for10.0.0.2 4 65002 0 0 1 0 0 00:00:00 Active.Why: Unlike OSPF, BGP sends no hellos to find neighbours: every peering is configured by hand at both ends and runs over a TCP session to port 179. One end configured is half a handshake, so the neighbour stays Active — still trying to connect — until the other side agrees.
5. Open BGP at ISP-B — the session comes up
Mirror it on ISP-B: AS 65002, neighbour 10.0.0.1 in AS 65001, and a `network` line for its own block. The session goes Established, each router receives the other's prefix, and WEB-A reaches PC-B across two autonomous systems.
On ISP-B — Configure ISP-B's half of the peering and announce its block
enable configure terminal router bgp 65002 bgp router-id 2.2.2.2 neighbor 10.0.0.1 remote-as 65001 network 203.0.113.0 mask 255.255.255.0 endOn WEB-A — Cross from one autonomous system into the other
ping 203.0.113.10Check: run
show ip bgp summaryon ISP-A and look for10.0.0.2 4 65002 0 0 1 0 0 00:00:00 1.Why: Each side now announces what it is responsible for and installs what it hears. `show ip bgp` on ISP-A lists 203.0.113.0/24 with the path 65002: BGP records every AS a route has crossed, which is one of the ways it chooses between routes and how it rejects a route that would loop back into an AS it already passed through.
6. Take on a new customer at ISP-B
ISP-B signs a second customer on a different block, 192.0.2.0/24. Cable a PC into ISP-B's Gi0/1 and address the port and the PC. Inside ISP-B everything works at once: the new customer reaches its gateway, and ISP-B has the block in its table.
- Cable PC-B2 Eth0 ↔ ISP-B Gi0/1
On ISP-B — Address the new customer's LAN on ISP-B
enable configure terminal interface Gi0/1 ip address 192.0.2.1 255.255.255.0 no shutdown exit endOn PC-B2 — Name the new customer's PC and point it at ISP-B
hostname PC-B2 ipconfig Eth0 192.0.2.10 255.255.255.0 192.0.2.1Check: run
show ip routeon ISP-B and look forC 192.0.2.0/24 is directly connected, Gi0/1.Why: A connected network is in the provider's own table the moment the interface comes up — but that is ISP-B's table, not the internet's. What another autonomous system can reach is decided by what this one announces.
7. The other provider can't see it yet
Change nothing — look. Ping PC-B2 from WEB-A and it fails at ISP-A, which has no route to 192.0.2.0/24. ISP-B announces exactly the prefixes it was told to announce, and nobody has told it about this one.
On WEB-A — Try the new customer from the other provider
ping 192.0.2.10On ISP-B — See what ISP-B is announcing
enable show ip bgpCheck: run
show ip route 192.0.2.10on ISP-A and look for% Network not in table.Why: BGP never announces a network just because it is connected. A provider announces exactly the prefixes it is prepared to carry traffic for — announcing the wrong one by accident is how the route leaks that make the news begin.
8. Announce the new block
One more `network` line under ISP-B's BGP process. The prefix is already in ISP-B's table, so it is announced at once: ISP-A installs a second B route and WEB-A reaches PC-B2 — with not a single change typed on ISP-A.
On ISP-B — Announce the new customer's block to ISP-B's peer
enable configure terminal router bgp 65002 network 192.0.2.0 mask 255.255.255.0 endOn WEB-A — Reach the new customer across the AS boundary
ping 192.0.2.10Check: run
show ip bgpon ISP-A and look for192.0.2.0/24 10.0.0.2.Why: That is the whole contract between providers: each announces what it is responsible for, each installs what it hears, and neither configures the other's customers. It scales to the entire internet because nobody ever types a route to somebody else's network.
The theory behind it
More in Routing
- Static routes across a WAN — Join three sites with point-to-point WAN links and route between them by hand, one line at a time.
- RIP: routing by counting hops — Chain three routers over two serial links and let RIP version 2 teach every router the way to every network, counting the hops as it goes.
- Two routers that learn the network — Join two sites over a WAN link, then let OSPF fill in the routing tables that you would otherwise type by hand.
- A backup link that waits its turn — Run two sites over a fast primary link, park a floating static route on a slow standby line, then pull the primary and watch the backup carry the traffic.
- Steer OSPF with link cost — Give OSPF two paths between two sites, watch it choose the cheaper one over the shorter one, then re-rate a link and watch the route move.
- Share one default route with OSPF — Give the edge router a default route to the provider, then let OSPF hand it to the rest of the campus instead of typing it on every router.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab