BGP, the Border Gateway Protocol, is the routing protocol that independently operated networks use to tell each other which IP address blocks they can reach and which path traffic should take to get there. Tens of thousands of those networks, called autonomous systems, exchange routes through it continuously, and between them they make up everything you'd call "the internet."
This guide walks through what BGP is doing when it routes traffic: how BGP neighbors connect, what their messages contain, how a router picks one path out of many, and why the whole system runs on business relationships as much as on engineering. It builds on What Is an ASN? Autonomous System Numbers Explained for Developers (2026), so if AS numbers are new to you, start there.
TL;DR
- BGP is how independently run networks tell each other which IP address blocks they can reach. It runs between autonomous systems over TCP port 179, while interior protocols like OSPF handle routing inside each network.
- Neighbors exchange four core message types (
OPEN,UPDATE,NOTIFICATION,KEEPALIVE).UPDATEmessages carry new routes and withdrawals, along with path attributes such asAS_PATH. - When a router hears about the same prefix from several neighbors, it works down a fixed list of tie-breakers, starting with the operator's own preference (
LOCAL_PREF) and then the shortestAS_PATH. - Networks prefer routes that earn them money (customer routes) over routes that cost them money (provider routes), so the chosen path is often not the fastest one.
- As of October 5, 2026, roughly 68% of routed IPv4 prefixes and 75% of IPv6 prefixes are covered by RPKI origin records, but path validation through ASPA is still an Internet-Draft, and only about 3% of routed ASNs have published an ASPA record.
Key Terms You'll See in This Guide
- Prefix: a block of IP addresses written like
203.0.113.0/24. - Autonomous system (AS): a network, or group of networks, run under a single routing policy and identified by an AS number.
- Peer (neighbor): a router that BGP has been configured to exchange routes with.
- Route: a prefix plus the path and attributes needed to reach it.
- Path attribute: a labeled piece of information attached to a route, such as AS_PATH, that routers use to compare their options.
What Is BGP in Plain Terms?
Routing on the internet happens at two levels, and they're handled by different protocols.
Inside a single network, one operator controls every router. Interior gateway protocols (IGPs) such as OSPF and IS-IS take advantage of that: every router shares detailed link information, and the protocol calculates the mathematically shortest path. That works because everyone involved trusts everyone else and shares one set of goals.
Between networks, none of that holds. Your ISP, a cloud provider and a backbone carrier each run their own infrastructure, have their own commercial contracts and have no interest in exposing their internal topology to each other. BGP is the de facto exterior gateway protocol built for that situation. It doesn't share link maps or compute shortest paths. Each network simply announces, "these prefixes are reachable through me, and here's the list of networks this announcement has already passed through." Every neighbor then applies its own rules to decide whether to accept the route, prefer it and pass it on.
That list of networks is the AS_PATH, and it's why BGP is called a path vector protocol. Because a router can see every network a route has crossed, it can reject any route that already contains its own AS number and write policy about which networks it will send traffic through.
BGP messages travel inside a TCP connection, and the protocol listens on port 179 under RFC 4271, A Border Gateway Protocol 4 (BGP-4), the current BGP-4 specification. Wikipedia's Border Gateway Protocol entry classifies BGP as an application layer protocol. Reliable delivery, ordering and retransmission all come from TCP, so BGP itself doesn't need to handle any of that.
A Short History: From Two Napkins to BGP-4
Before BGP, networks exchanged reachability using the Exterior Gateway Protocol, specified in RFC 904, Exterior Gateway Protocol formal specification. EGP was designed for a tree-shaped topology, and the RFC itself looks ahead to topologies not restricted to trees. As the internet grew into a mesh of interconnected providers, a protocol built around a single core no longer fit.
At an IETF meeting in 1989, Kirk Lougheed of Cisco and Yakov Rekhter of IBM sketched a replacement over lunch. The Computer History Museum's The Two-Napkin Protocol notes that their notes were written on napkins, which is why BGP is still nicknamed the "two-napkin protocol." The design was published in June 1989 as RFC 1105, Border Gateway Protocol (BGP).
The version running today is BGP-4. It was first published in July 1994 as RFC 1654, A Border Gateway Protocol 4 (BGP-4), which already included mechanisms for classless addressing (CIDR). RFC 1771 revised it in March 1995, and RFC 4271 brought it to its current form in January 2006. Many extensions have been layered on since, including Multiprotocol Extensions for BGP-4, which let the same protocol carry IPv6, VPN and other route types.
How Does BGP Work? The Life of a Route
The easiest way to understand BGP routing is to follow one route from the network that owns it to a router on the other side of the world. The examples below use documentation-reserved AS numbers (64496 to 64511) and the reserved prefix 203.0.113.0/24, so none of them point at a real network.

Each hop prepends its own AS number. A withdrawal follows the same path as the announcement.
Step 1: Neighbors Build a Session
Two BGP routers, called peers or neighbors, are configured with each other's IP address and AS number. The standard protocol has no neighbor discovery of its own. One router opens a TCP connection to port 179 on the other, they swap OPEN messages to agree on settings, and once both sides accept, the session is Established and routes can flow. RFC 4271 defines six states a session moves through on the way there, which the "Going Deeper" section below walks through.
Step 2: The Four Core Message Types
Everything a BGP session does happens through a small set of messages, each capped at 4,096 bytes under RFC 4271:
| Type | Message | Purpose |
|---|---|---|
| 1 | OPEN | Starts the session and exchanges AS numbers, the proposed hold time, a router identifier and optional capabilities. |
| 2 | UPDATE | Announces new routes, withdraws old ones, or both, in a single message. |
| 3 | NOTIFICATION | Reports an error and immediately closes the session. |
| 4 | KEEPALIVE | Confirms the peer is still alive when there's nothing else to send. |
An extension, ROUTE-REFRESH (RFC 2918, Route Refresh Capability for BGP-4, message type 5), lets a router ask a peer to resend its routes so policy changes can take effect without resetting the session.
BGP is incremental. Once two peers are Established, they send their full set of routes once, and from then on they only send changes. That's very different from a protocol like RIP, which periodically re-sends its whole table, and it's a big reason BGP can carry over a million routes without drowning in its own chatter.
Step 3: A Route Is Announced
Say AS64496 holds 203.0.113.0/24 and wants the internet to be able to reach it. Its border router sends an UPDATE to its upstream provider, AS64497. That UPDATE carries the prefix itself (called NLRI, Network Layer Reachability Information) plus a set of path attributes. The ones you'll run into most:
- AS_PATH: the networks the route has passed through. At this point it's just
64496. - NEXT_HOP: the IP address routers should forward traffic to in order to use this route.
- ORIGIN: how the route entered BGP in the first place (IGP, EGP or INCOMPLETE).
- LOCAL_PREF: a preference value used only inside an AS to steer outbound traffic.
- MULTI_EXIT_DISC (MED): a hint to a neighboring network about which of several entry points to prefer.
- COMMUNITIES: tags that carry policy signals between networks, such as "don't export this route beyond your customers."
AS64497 accepts the route, prepends its own number, and sends it on to AS64498, which receives it with an AS_PATH of 64497 64496. When AS64498 passes the route to its own neighbors, it prepends itself as well, so they see 64498 64497 64496. Each AS adds its own number to the front, so the rightmost number is the origin AS.
When the route stops being valid, perhaps because a link went down, AS64496 sends another UPDATE listing the prefix in its withdrawn routes field. The withdrawal ripples outward the same way the announcement did, and routers either switch to another path they already know about or drop the destination entirely.
Step 4: Keepalives Hold the Session Open
During the OPEN exchange, each peer proposes a hold time and the smaller of the two values is used. If a router hears nothing from its peer for that long, it sends a NOTIFICATION, closes the session and discards every route it learned through that peer. RFC 4271 suggests a hold time of 90 seconds, with KEEPALIVE messages sent at one third of that interval, so roughly every 30 seconds. Vendors ship their own defaults, so check the values your platform actually uses.
How BGP Chooses the Best Path
A large network can learn the same prefix from several neighbors. BGP keeps all of those candidates but installs only one as the best path for forwarding. Think of it as a ranked checklist: the router walks down the list and stops as soon as one rule picks a winner. RFC 4271 defines the order, and every router in an AS needs to apply it the same way to avoid inconsistent decisions:
- Highest LOCAL_PREF. The operator's own preference wins first. This is how a network says "use the customer link before the paid transit link."
- Shortest AS_PATH. Fewer networks to cross wins, regardless of how fast or slow those networks are.
- Lowest ORIGIN. IGP beats EGP, which beats INCOMPLETE.
- Lowest MED. Only compared between routes learned from the same neighboring AS.
- eBGP over iBGP. A route learned directly from another network beats one learned from a router inside your own network.
- Cheapest internal path to the NEXT_HOP. The exit point that's closest by your own IGP metric wins, often called "hot potato" routing.
- Lowest BGP identifier. A deterministic tie-breaker based on the advertising router's ID.
- Lowest peer address. The final tie-breaker if everything else is equal.
Vendors add their own steps on top of this list, so check your platform's documentation for the exact order it uses. The list above is the order defined in the standard.
There's one rule that sits above all of this, and it's easy to miss. BGP picks the best path per prefix, but the router's forwarding table always uses the most specific matching prefix. If one network announces 203.0.113.0/24 and another announces 203.0.113.0/25, traffic to 203.0.113.10 follows the /25, no matter how good the /24's AS_PATH looks. That longest-prefix-match behavior is central to both routing tricks and routing incidents, as you'll see below.
Why BGP Routes Follow Money, Not Latency
The ASN guide, What Is an ASN? Autonomous System Numbers Explained for Developers (2026), covers the two basic relationships between networks: transit, where a customer pays a provider for access to the rest of the internet, and peering, where two networks exchange their own customers' traffic directly. Those relationships shape BGP policy at least as much as any measurement of speed does.
Lixin Gao and Jennifer Rexford formalized the policy pattern most ISPs follow in their 2001 paper "Stable Internet Routing Without Global Coordination" (IEEE/ACM Transactions on Networking), which describes its guidelines as matching conventional ISP traffic engineering. It comes down to two habits:
What networks prefer. A route learned from a customer earns money, a route learned from a peer is roughly free, and a route learned from a provider costs money. So networks typically set LOCAL_PREF so that customer routes beat peer routes, which beat provider routes. Because LOCAL_PREF is the first step in path selection, this outranks AS path length entirely.
What networks pass on. Routes learned from customers are announced to everyone, because carrying that traffic is what customers pay for. Routes learned from peers or providers are announced only to customers. A network has no reason to carry traffic between two of its providers for free.
Following both habits produces what researchers call "valley-free" paths: traffic climbs up through providers, crosses at most one peering link, and descends through customers. When a network breaks the second habit, say by accidentally re-announcing a provider's routes to another provider, it creates a route leak (see Problem Definition and Classification of BGP Route Leaks), and a small network can suddenly attract far more traffic than its links were built for. RFC 8212, Default External BGP (EBGP) Route Propagation Behavior without Policies, makes this kind of mistake harder by specifying that an eBGP session should, by default, accept and announce nothing until an explicit policy is configured.

Customer routes travel up and across. A leak sends one provider's routes to another provider.
BGP vs OSPF
They're often compared because both are routing protocols, but they solve different problems and usually run side by side.
| BGP | OSPF | |
|---|---|---|
| Category | Exterior gateway protocol (path vector) | Interior gateway protocol (link state) |
| Scope | Between autonomous systems | Inside a single autonomous system |
| How it picks paths | Policy and path attributes, in a fixed order | Lowest total link cost, calculated with Dijkstra's algorithm |
| What neighbors share | Reachable prefixes and the path to them | Full link-state information about the topology |
| Transport | TCP port 179 | Runs directly over IP (protocol 89) |
| Neighbor discovery | Manually configured | Automatic on shared links |
| Scale | Over a million prefixes in the global table | Designed for a single operator's network |
A typical ISP uses OSPF or IS-IS so its own routers know how to reach each other, then runs BGP on top to learn and announce routes to the rest of the internet.
When BGP Goes Wrong: Two Incidents Worth Knowing
BGP's route sharing relies on trust: by default, a router believes what its neighbors tell it. Two well-documented incidents show how that plays out in two very different ways.
The 2008 YouTube Hijack: A More Specific Route Wins
According to the RIPE NCC's YouTube Hijacking: A RIPE NCC RIS case study, on February 24, 2008, YouTube (AS36561) was announcing 208.65.152.0/22. At 18:47 UTC, Pakistan Telecom (AS17557) began announcing 208.65.153.0/24, a smaller block inside YouTube's range, and its upstream provider propagated that announcement to the rest of the internet.
Because a /24 is more specific than a /22, routers worldwide followed the new announcement for any address in that block, and YouTube traffic was pulled toward a network that wasn't serving it. YouTube's response used the same rule in reverse: it announced the identical /24, then split it into two /25s, which were more specific still. The hijack ended when the upstream provider withdrew the bogus prefixes about two hours after it began.
The 2021 Facebook Outage: Withdrawing Yourself From the Internet
The October 4, 2021 Facebook outage involved no outside party at all. In More details about the October 4 outage, Meta explained that a maintenance command unintentionally disconnected its global backbone, and a bug in its audit tooling failed to stop it. Its DNS servers were built to withdraw their BGP announcements whenever they lost contact with Meta's data centers, treating that as a sign of an unhealthy network. They did exactly that.
With those routes withdrawn, the rest of the internet no longer had any path to Facebook's DNS servers, so Facebook's domains couldn't resolve, even though the servers themselves were still running.
How BGP Is Being Secured in 2026
RPKI targets origin hijacks like the YouTube one, and ASPA targets route leaks. Neither can help in a case like Facebook's, where a network withdraws its own routes.
Origin validation with RPKI. Resource Public Key Infrastructure lets an address holder publish a signed Route Origin Authorization (ROA) that names an AS permitted to originate a prefix and the longest prefix length it may announce. Routers performing route origin validation, defined in BGP Prefix Origin Validation, can drop announcements that contradict it. Had YouTube's /22 been covered by a ROA with a /22 maximum length, networks validating routes would have marked Pakistan Telecom's /24 as invalid.
Hurricane Electric's RPKI & ASPA Adoption Report showed the following when checked on October 5, 2026. The figures move daily, so treat them as a snapshot:
| Metric | Coverage |
|---|---|
| Routed IPv4 prefixes covered by a ROA | about 68% |
| Routed IPv6 prefixes covered by a ROA | about 75% |
| All routed prefixes covered by a ROA | about 69% |
| Routed ASNs with an ASPA record | about 3% |
A ROA only helps where networks enforce it, and it says nothing about the rest of the path.
Path validation with ASPA. Autonomous System Provider Authorization lets a network publish a signed list of its legitimate upstream providers. A router can then check whether an AS_PATH is consistent with those declared relationships, which can catch route leaks that origin validation can't. The Internet-Draft BGP AS_PATH Verification Based on Autonomous System Provider Authorization (ASPA) Objects is still an IETF working group Internet-Draft, last revised in August 2026 with Proposed Standard as its intended status, and adoption is early, as the roughly 3% figure above shows. An older approach, BGPsec, specified in BGPsec Protocol Specification, signs every hop of the path cryptographically, but it requires every network on the path to participate.
How Big Is the Global BGP Table?
The CIDR Report counted 1,081,393 IPv4 prefixes on October 5, 2026, and its IPv6 CIDR Report counted 256,750 IPv6 prefixes the same day. Its count of autonomous systems updates through the day, but it sits at roughly 79,500. Other sources report different totals. Hurricane Electric's report above, for instance, lists about 1.3 million IPv4 prefixes and about 88,500 autonomous systems. Each source measures from its own collection points, so treat any single figure as a snapshot from one source rather than a definitive count. If the two address families are new to you, IPv4 vs IPv6: Developer Guide to Key Differences explains how they differ.
That table size has practical consequences. Every router holding a full table has to store all of those routes in memory and recompute best paths whenever they change, which is why hardware capacity and route aggregation remain recurring topics in network operations.
Where Else Is BGP Used?
BGP now shows up in places well beyond ISP border routers:
- Data center fabrics. RFC 7938, Use of BGP for Routing in Large-Scale Data Centers, describes using eBGP as the only routing protocol inside large-scale data centers, using private AS numbers assigned within the data center.
- Anycast services. Announcing the same prefix from many locations lets BGP deliver each user to the nearest instance, a pattern documented in Operation of Anycast Services and widely used for DNS.
- VPNs. BGP/MPLS IP Virtual Private Networks (VPNs) and BGP MPLS-Based Ethernet VPN (EVPN) use BGP to distribute customer routes across provider networks.
- Multihoming. Organizations connected to two or more providers typically use BGP to fail over between them and control which link carries which traffic.
Going Deeper: Session States and Internal BGP
This section is for readers who configure or debug BGP. If you only need the concept, skip to the next section.
BGP Session States
Every BGP session moves through a finite state machine defined in RFC 4271:
| State | What's happening |
|---|---|
| Idle | The router is not yet trying to connect, or has reset after an error. |
| Connect | The router is waiting for its TCP handshake with the neighbor to finish. |
| Active | The TCP attempt failed or timed out, and the router is retrying. |
| OpenSent | TCP is up, and the router has sent its OPEN message. |
| OpenConfirm | The peer's OPEN was received and accepted; the router is waiting for a KEEPALIVE. |
| Established | The session is up, and routes can be exchanged. |
A session that never gets past Connect or Active is stuck at the TCP stage, so the first things to check are the neighbor address and whether port 179 is reachable.
eBGP vs iBGP
The same protocol runs in two modes depending on who's on the other end of the session.
| eBGP (external) | iBGP (internal) | |
|---|---|---|
| Peers | Routers belonging to different ASes | Routers belonging to one AS |
| AS_PATH | The sender prepends its own AS number | Unchanged, since the route hasn't left the AS |
| NEXT_HOP | Usually rewritten to the sender's address | Preserved by default from the eBGP router that learned it |
| Re-advertising | Routes can be passed to other eBGP peers per policy | A router won't pass iBGP-learned routes to other iBGP peers |
| Typical use | Connecting to providers, peers and customers | Spreading external routes across your own border and core routers |
The re-advertising rule matters for anyone designing a network. Because iBGP doesn't modify AS_PATH, it can't use it for loop detection, so iBGP routers refuse to relay routes between each other. The result is that every iBGP router needs a session with every other one: 10 routers need 45 sessions, and 100 need 4,950. Large networks avoid that full mesh with route reflectors, described in BGP Route Reflection: An Alternative to Full Mesh Internal BGP (IBGP), which are designated routers allowed to relay iBGP routes, or with confederations, described in Autonomous System Confederations for BGP, which split one AS into smaller sub-ASes internally.
How to See BGP Data for Any Network
You don't need a router to look at BGP. Public route collectors such as the RIPE NCC's Routing Information Service (RIS) record routing data from collection points around the world, and the RIPE NCC's YouTube case study above was built from that data.
For a quick look at a specific network, the free ASN Lookup tool lists the IPv4 and IPv6 prefixes and the upstream, downstream and peer relationships recorded for an AS, with no signup required. It's a fast way to see the transit and peering relationships described above for a real network. If you're starting from an address in a log file instead, the IP to ASN Lookup tool resolves it to the announcing AS and network block.
To pull the same data into code, the ASN Lookup API returns it as JSON from one GET request:
curl -X GET \
'https://api.apifreaks.com/v1.0/asn/whois/live?asn=AS32934' \
-H 'X-apiKey: YOUR_API_KEY'
The example looks up AS32934, Meta's network from the outage above, so swap in the AS you're investigating. A live response, trimmed for length, looks like this:
{
// Omitted: whoisResponse, parsedWhoisResponse, contacts, upstreams, peers
"asNumber": "32934",
"asName": "FACEBOOK",
"orgName": "Meta Platforms, Inc.",
"description": "",
"orgHandle": "thefa-3",
"country": "US",
"domain": "facebook.com",
"website": "http://facebook.com",
"allocationStatus": "",
"numOfIPv4Routes": "261",
"numOfIPv6Routes": "365",
"whoisHost": "ARIN",
"dateAllocated": "2004-08-24",
"type": "BUSINESS",
"routeObjects": [
{
"route": "31.13.69.0/24",
"origin": "AS32934",
"originName": "Meta Platforms, Inc.",
"isp": "Meta Platforms Ireland Limited",
"numberOfIps": 256
},
{
"route": "2a03:2880:f178::/48",
"origin": "AS32934",
"originName": "Meta Platforms, Inc.",
"isp": "Meta Platforms Ireland Limited",
"numberOfIps": 1208925819614629174706176
}
// ... more entries
],
"downstreams": [
{
"asNumber": "AS54115",
"description": "Facebook Inc",
"country": "US"
},
{
"asNumber": "AS63293",
"description": "Facebook, Inc.",
"country": "US"
}
// ... more entries
],
"legacyRoutes": []
}
Trimmed from a live call on October 5, 2026: the raw WHOIS text, the parsed WHOIS block and the contact fields were removed because they are long and can include personal contact details, the upstream and peer lists were left out to keep the example focused on route and downstream data, and the remaining lists were cut to their first two entries. The comments are added to mark the cuts and are not part of the API response. numOfIPv4Routes and numOfIPv6Routes show the full route counts (261 and 365 here).
The response fields map directly to concepts from this guide: routeObjects lists route prefixes with their origin AS, numOfIPv4Routes and numOfIPv6Routes give the size of that list, and upstreams, downstreams and peers describe its upstream, downstream and peer relationships. Each successful lookup costs 15 credits, and a request without the X-apiKey header returns a 400 error.
FAQs
What is BGP in simple terms?
BGP, the Border Gateway Protocol, is what networks use to tell each other which IP addresses they can reach. Each network announces its own address blocks to its neighbors, those neighbors pass the announcements on, and every router uses the collected announcements to decide which path to send traffic along.
What port does BGP use?
BGP uses TCP port 179. In the BGP protocol, one router opens a TCP connection to port 179 on its neighbor, and the session runs inside that connection, relying on TCP for reliable, ordered delivery.
Is BGP a layer 3, layer 4 or layer 7 protocol?
In the OSI model, BGP is classified as an application layer (layer 7) protocol. RFC 4271 specifies TCP, a layer 4 transport protocol, to carry its messages. What BGP exchanges is routing information for the network layer (layer 3), but BGP itself is neither a layer 3 nor a layer 4 protocol.
What is the difference between BGP and OSPF?
OSPF routes traffic inside a single network by calculating the lowest-cost path across links the operator controls. BGP routes traffic between separate networks using policy and path attributes. Most ISPs run OSPF or IS-IS internally and BGP at their borders.
Why is BGP needed?
The internet is made of tens of thousands of independently run networks with their own policies and business relationships. BGP gives them a common way to announce what they can reach and to choose paths according to their own rules, which no interior routing protocol is designed to do.
Is BGP difficult to learn?
The core ideas are small: sessions, UPDATE messages, path attributes and a fixed tie-breaker order. The harder part is policy at scale, deciding what to accept, prefer and announce across many neighbors and getting those rules right on production routers.
Is BGP still relevant today?
Yes. BGP-4 is still how networks exchange routes with each other, and RFC 4271 is still its core specification. The CIDR Report counted more than a million IPv4 prefixes in the global routing table on October 5, 2026, and the standards work continues, with ASPA path validation still moving through the IETF.
Does my home network use BGP?
A typical home connection doesn't run BGP. Your router sends everything to your ISP, and the ISP runs BGP with other networks on your behalf. Organizations generally run BGP themselves only when they connect to two or more providers or need their own routing policy.
Wrapping Up
Understanding what BGP is comes down to three pieces: sessions, UPDATE messages and a fixed list of tie-breakers, applied by tens of thousands of networks at once. The two best-known incidents here were a more specific announcement (YouTube, 2008) and a mass withdrawal (Facebook, 2021), and a strange-looking path is usually a business relationship expressed as LOCAL_PREF.
Start mapping BGP prefixes, upstreams and peers for any network with 10,000 free credits. The APIFreaks ASN Lookup API requires no credit card to get started. Create a free account and make your first call in minutes.
