show ip bgp neighbors

Displays configuration information and statistics for BGP4 neighbors of the device.
Syntax
show ip bgp neighbors [ip-addr]
show ip bgp neighbors last-packet-with-error
show ip bgp neighbors routes-summary
Parameters
ip-addr
Specifies the IPv4 address of a neighbor in dotted-decimal notation.
last-packet-with-error
Displays the last packet with an error.
routes-summary
Displays routes received, routes accepted, number of routes advertised by peer, and so on.
Modes

User EXEC mode

Usage Guidelines

Output shows all configured parameters for the neighbors. Only the parameters whose values differ from defaults are shown.

The show ip bgp neighbors command displays the following information:

Output field

Description

Total Number of BGP4 Neighbors

The number of BGP4 neighbors configured.

IP Address

The IP address of the neighbor.

AS

The AS the neighbor is in.

EBGP or IBGP

Whether the neighbor session is an IBGP session, an EBGP session, or a confederation EBGP session:

  • EBGP - The neighbor is in another AS.
  • EBGP_Confed - The neighbor is a member of another sub-AS in the same confederation.
  • IBGP - The neighbor is in the same AS.

RouterID

The neighbor device ID.

Description

The description you gave the neighbor when you configured it on the device.

Local AS

The value (if any) of the Local AS configured.

State

The state of the session with the neighbor. The states are from the device perspective, not the neighbor perspective. The state values are based on the BGP4 state machine values described in RFC 1771 and can be one of the following for each device:

  • IDLE - The BGP4 process is waiting to be started. Usually, enabling BGP4 or establishing a neighbor session starts the BGP4 process. A minus sign (-) indicates that the session has gone down and the software is clearing or removing routes.
  • ADMND - The neighbor has been administratively shut down. A minus sign (-) indicates that the session has gone down and the software is clearing or removing routes.
  • CONNECT - BGP4 is waiting for the connection process for the TCP neighbor session to be completed.
  • ACTIVE - BGP4 is waiting for a TCP connection from the neighbor.
Note: If the state frequently changes between CONNECT and ACTIVE, there may be a problem with the TCP connection.
  • OPEN SENT - BGP4 is waiting for an Open message from the neighbor.
  • OPEN CONFIRM - BGP4 has received an OPEN message from the neighbor and is now waiting for either a KEEPALIVE or NOTIFICATION message. If the device receives a KEEPALIVE message from the neighbor, the state changes to Established. If the message is a NOTIFICATION, the state changes to Idle.
  • ESTABLISHED - BGP4 is ready to exchange UPDATE messages with the neighbor.

If there is more BGP4 data in the TCP receiver queue, a plus sign (+) is also displayed.

Note: If you display information for the neighbor using the show ip bgp neighborip-addr command, the TCP receiver queue value will be greater than 0.

Time

The amount of time this session has been in the current state.

KeepAliveTime

The keep alive time, which specifies how often this device sends keepalive messages to the neighbor.

HoldTime

The hold time, which specifies how many seconds the device will wait for a keepalive or update message from a BGP4 neighbor before deciding that the neighbor is not operational.

PeerGroup

The name of the peer group the neighbor is in, if applicable.

Multihop-EBGP

Whether this option is enabled for the neighbor.

RouteReflectorClient

Whether this option is enabled for the neighbor.

SendCommunity

Whether this option is enabled for the neighbor.

NextHopSelf

Whether this option is enabled for the neighbor.

DefaultOriginate

Whether this option is enabled for the neighbor.

MaximumPrefixLimit

Maximum number of prefixes the device will accept from this neighbor.

RemovePrivateAs

Whether this option is enabled for the neighbor.

RefreshCapability

Whether this device has received confirmation from the neighbor that the neighbor supports the dynamic refresh capability.

CooperativeFilteringCapability

Whether the neighbor is enabled for cooperative route filtering.

Distribute-list

Lists the distribute list parameters, if configured.

Filter-list

Lists the filter list parameters, if configured.

Prefix-list

Lists the prefix list parameters, if configured.

Route-map

Lists the route map parameters, if configured.

Messages Sent

The number of messages this device has sent to the neighbor. The display shows statistics for the following message types:

  • Open
  • Update
  • KeepAlive
  • Notification
  • Refresh-Req

Messages Received

The number of messages this device has received from the neighbor. The message types are the same as for the Message Sent field.

Last Update Time

Lists the last time updates were sent and received for the following:

  • NLRIs
  • Withdraws

Last Connection Reset Reason

The reason the previous session with this neighbor ended. The reason can be one of the following:

Reasons described in the BGP4 specifications:

  • Message Header Error
  • Connection Not Synchronized
  • Bad Message Length
  • Bad Message Type
  • OPEN Message Error
  • Unsupported Version Number
  • Bad Peer AS Number
  • Bad BGP4 Identifier
  • Unsupported Optional Parameter
  • Authentication Failure
  • Unacceptable Hold Time
  • Unsupported Capability
  • UPDATE Message Error
  • Malformed Attribute List
  • Unrecognized Well-known Attribute
  • Missing Well-known Attribute
  • Attribute Flags Error
  • Attribute Length Error
  • Invalid ORIGIN Attribute
  • Invalid NEXT_HOP Attribute
  • Optional Attribute Error
  • Invalid Network Field
  • Malformed AS_PATH
  • Hold Timer Expired
  • Finite State Machine Error
  • Rcv Notification

Last Connection Reset Reason (cont.)

Reasons specific to the RUCKUS implementation:

  • Reset All Peer Sessions
  • User Reset Peer Session
  • Port State Down
  • Peer Removed
  • Peer Shutdown
  • Peer AS Number Change
  • Peer AS Confederation Change
  • TCP Connection KeepAlive Timeout
  • TCP Connection Closed by Remote
  • TCP Data Stream Error Detected

Notification Sent

If the device receives a NOTIFICATION message from the neighbor, the message contains an error code corresponding to one of the following errors. Some errors have subcodes that clarify the reason for the error. Where applicable, the subcode messages are listed underneath the error code messages.

  • Message Header Error:
    • Connection Not Synchronized
    • Bad Message Length
    • Bad Message Type
    • Unspecified
  • Open Message Error:
    • Unsupported Version
    • Bad Peer As
    • Bad BGP4 Identifier
    • Unsupported Optional Parameter
    • Authentication Failure
    • Unacceptable Hold Time
    • Unspecified
  • Update Message Error:
    • Malformed Attribute List
    • Unrecognized Attribute
    • Missing Attribute
    • Attribute Flag Error
    • Attribute Length Error
    • Invalid Origin Attribute
    • Invalid NextHop Attribute
    • Optional Attribute Error
    • Invalid Network Field
    • Malformed AS Path
    • Unspecified
  • Hold Timer Expired
  • Finite State Machine Error
  • Cease
  • Unspecified

Notification Received

Refer to details for the field Notification Sent.

AO Keychain name Name of the TCP keychain (AO) used for authentication

TCP Connection state

The state of the connection with the neighbor. The connection can have one of the following states:

  • LISTEN - Waiting for a connection request.
  • SYN-SENT - Waiting for a matching connection request after having sent a connection request.
  • SYN-RECEIVED - Waiting for a confirming connection request acknowledgment after having both received and sent a connection request.
  • ESTABLISHED - Data can be sent and received over the connection. This is the normal operational state of the connection.
  • FIN-WAIT-1 - Waiting for a connection termination request from the remote TCP, or an acknowledgment of the connection termination request previously sent.
  • FIN-WAIT-2 - Waiting for a connection termination request from the remote TCP.
  • CLOSE-WAIT - Waiting for a connection termination request from the local user.
  • CLOSING - Waiting for a connection termination request acknowledgment from the remote TCP.
  • LAST-ACK - Waiting for an acknowledgment of the connection termination request previously sent to the remote TCP (which includes an acknowledgment of its connection termination request).
  • TIME-WAIT - Waiting for enough time to pass to be sure the remote TCP received the acknowledgment of its connection termination request.
  • CLOSED - There is no connection state.
TCP Keychain name Name of active TCP keychain used for TCP segment authentication
TCP-AO Enabled YES/NO Indicates whether TCP keychain authentication is enabled.
TCP-AO in use YES/NO Indicates whether TCP keychain authentication is being used.
Keychain valid YES/NO Indicates whether there is a valid keychain in use.
No of segments dropped Displays the number of segments dropped because they failed TCP authentication.
Send-Active-Key Provides details on the TCP authentication send key associated with the active keychain:

Key-Id

Crypto Algorithm (for example, AES-128-CMAC or HMAC-SHA-1)

Send-id - Configured identifier sent in outgoing TCP segments

Recv-id - Configured identifier used to compare to send-id in received segments

Include-tcp-options (YES/NO) - Specifies whether or not to include TCP options in calculating the Message Authentication Code (MAC) for a TCP segment

Accept-ao-mistmatch (YES/NO) - Specifies whether TCP segments are accepted or dropped when TCP peers do not have matching TCP authentication support

Recv-Active-Key Provides details on the TCP authentication receive key associated with the active keychain:

Key-Id

Crypto Algorithm (for example, AES-128-CMAC or HMAC-SHA-1)

Send-id - Configured identifier sent in outgoing TCP segments

Recv-id - Configured identifier used to compare to send-id in received segments

Include-tcp-options (YES/NO) - Specifies whether or not to include TCP options in calculating the Message Authentication Code (MAC) for a TCP segment

Accept-ao-mistmatch (YES/NO) - Specifies whether TCP segments are accepted or dropped when TCP peers do not have matching TCP authentication support

Maximum segment size Displays maximum size for TCP segments.
TTL check: value Diplays TTL value.

Byte Sent

The number of bytes sent.

Byte Received

The number of bytes received.

Local host

The IP address of the device.

Local port

The TCP port the device is using for the BGP4 TCP session with the neighbor.

Remote host

The IP address of the neighbor.

Remote port

The TCP port the neighbor is using for the BGP4 TCP session with the device.

ISentSeq

The initial send sequence number for the session.

SendNext

The next sequence number to be sent.

TotUnAck

The number of sequence numbers sent by the device that have not been acknowledged by the neighbor.

TotSent

The number of sequence numbers sent to the neighbor.

ReTrans

The number of sequence numbers that the device retransmitted because they were not acknowledged.

UnAckSeq

The current acknowledged sequence number.

IRcvSeq

The initial receive sequence number for the session.

RcvNext

The next sequence number expected from the neighbor.

SendWnd

The size of the send window.

TotalRcv

The number of sequence numbers received from the neighbor.

DupliRcv

The number of duplicate sequence numbers received from the neighbor.

RcvWnd

The size of the receive window.

SendQue

The number of sequence numbers in the send queue.

RcvQue

The number of sequence numbers in the receive queue.

CngstWnd

The number of times the window has changed.

Examples

The following example shows sample output from the show ip bgp neighbors command.

Idevice# show ip bgp neighbors   
    Total number of BGP Neighbors:3
1   IP Address: 17.1.1.1, AS: 1 (IBGP), RouterID: 3.1.1.1, VRF: default-vrf
    State: ESTABLISHED, Time: 1d22h42m4s, KeepAliveTime: 10, HoldTime: 30
       KeepAliveTimer Expire in 4 seconds, HoldTimer Expire in 23 seconds
    Minimal Route Advertisement Interval: 0 seconds
       PeerGroup: p1
       RefreshCapability: Received
       GracefulRestartCapability: Received
           Restart Time 120 sec, Restart bit 0
           afi/safi 1/1, Forwarding bit 0
           afi/safi 2/1, Forwarding bit 0
       GracefulRestartCapability: Sent
           Restart Time 120 sec, Restart bit 0
           afi/safi 1/1, Forwarding bit 0
           afi/safi 2/1, Forwarding bit 0
    Messages:    Open    Update  KeepAlive Notification Refresh-Req
       Sent    : 1       2       16729     0            0          
       Received: 1       2       18097     0            0          
    Last Update Time: NLRI       Withdraw          NLRI       Withdraw
                  Tx: ---        ---           Rx: ---        ---        
    Last Connection Reset Reason:Unknown
    Notification Sent:     Unspecified
    Notification Received: Unspecified
    Neighbor NLRI Negotiation:
      Peer Negotiated IPV4  unicast  capability
      Peer Negotiated IPV6 unicast  capability                    
      Peer configured for IPV4 unicast  Routes
      Peer configured for IPV6 unicast  Routes
    Neighbor AS4 Capability Negotiation:
    Outbound Policy Group:
       ID: 3, Use Count: 6
    AO Keychain name : 1
    TCP Connection state: ESTABLISHED
     TCP Keychain name      : 1
     TCP-AO Enabled         : YES
     TCP-AO in use          : YES
     Keychain valid         : YES
     No of segments dropped : 0
     Send-Active-Key
     ---------------
       Key-id               : 1
       Crypto Algorithm     : AES-128-CMAC
       Send-id              : 100
       Recv-id              : 100
       Include-tcp-options  : YES
       Accept-ao-mismatch   : YES
     Recv-Active-Key
     ---------------
       Key-id               : 1
       Crypto Algorithm     : AES-128-CMAC
       Send-id              : 100                                 
       Recv-id              : 100
       Include-tcp-options  : YES
       Accept-ao-mismatch   : YES

     Maximum segment size: 1420
    TTL check: value: 0
       Byte Sent:   317970, Received: 343962
       Local host:  17.1.1.2, Local  Port: 8003
       Remote host: 17.1.1.1, Remote Port: 179
       ISentSeq:   17564913  SendNext:   17882884  TotUnAck:          0
       TotSent:      317971  ReTrans:          40  UnAckSeq:   17882884
       IRcvSeq:   153787685  RcvNext:   154131648  SendWnd:       16365
       TotalRcv:     343963  DupliRcv:       1083  RcvWnd:        16384
       SendQue:           0  RcvQue:            0  CngstWnd:       1439
 

The following example shows sample output from the show ip bgp neighbors command when an IP address is specified.

device# show ip bgp neighbors 17.1.1.1
1   IP Address: 17.1.1.1, AS: 1 (IBGP), RouterID: 3.1.1.1, VRF: default-vrf
    State: ESTABLISHED, Time: 1d22h42m42s, KeepAliveTime: 10, HoldTime: 30
       KeepAliveTimer Expire in 9 seconds, HoldTimer Expire in 21 seconds
    Minimal Route Advertisement Interval: 0 seconds
       PeerGroup: p1
       RefreshCapability: Received
       GracefulRestartCapability: Received
           Restart Time 120 sec, Restart bit 0
           afi/safi 1/1, Forwarding bit 0
           afi/safi 2/1, Forwarding bit 0
       GracefulRestartCapability: Sent
           Restart Time 120 sec, Restart bit 0
           afi/safi 1/1, Forwarding bit 0
           afi/safi 2/1, Forwarding bit 0
    Messages:    Open    Update  KeepAlive Notification Refresh-Req
       Sent    : 1       2       16733     0            0          
       Received: 1       2       18101     0            0          
    Last Update Time: NLRI       Withdraw          NLRI       Withdraw
                  Tx: ---        ---           Rx: ---        ---        
    Last Connection Reset Reason:Unknown
    Notification Sent:     Unspecified
    Notification Received: Unspecified
    Neighbor NLRI Negotiation:
      Peer Negotiated IPV4  unicast  capability
      Peer Negotiated IPV6 unicast  capability
      Peer configured for IPV4 unicast  Routes                    
      Peer configured for IPV6 unicast  Routes
    Neighbor AS4 Capability Negotiation:
    Outbound Policy Group:
       ID: 3, Use Count: 6
    AO Keychain name : 1
    TCP Connection state: ESTABLISHED
     TCP Keychain name      : 1
     TCP-AO Enabled         : YES
     TCP-AO in use          : YES
     Keychain valid         : YES
     No of segments dropped : 0
     Send-Active-Key
     ---------------
       Key-id               : 1
       Crypto Algorithm     : AES-128-CMAC
       Send-id              : 100
       Recv-id              : 100
       Include-tcp-options  : YES
       Accept-ao-mismatch   : YES
     Recv-Active-Key
     ---------------
       Key-id               : 1
       Crypto Algorithm     : AES-128-CMAC
       Send-id              : 100
       Recv-id              : 100                                 
       Include-tcp-options  : YES
       Accept-ao-mismatch   : YES

     Maximum segment size: 1420
    TTL check: value: 0
       Byte Sent:   318046, Received: 344038
       Local host:  17.1.1.2, Local  Port: 8003
       Remote host: 17.1.1.1, Remote Port: 179
       ISentSeq:   17564913  SendNext:   17882960  TotUnAck:          0
       TotSent:      318047  ReTrans:          40  UnAckSeq:   17882960
       IRcvSeq:   153787685  RcvNext:   154131724  SendWnd:       16365
       TotalRcv:     344039  DupliRcv:       1083  RcvWnd:        16384
       SendQue:           0  RcvQue:            0  CngstWnd:       1439
History
Release version Command history
08.0.90 This command was modified to display BGP BFD session information for neighbors.
08.0.92a The output for this command was modified so that the MD5 password is not displayed in clear text when enable password-display is configured.
09.0.10 The output for this command was modified to include TCP keychain authentication option (AO) information.