Inter-AS routing (BGP)
To route packets between Autonomous Systems (ASs), the Internet uses a routing protocol called the Border Gateway Protocol (BGP) (RFC 4271).
BGP is a key Internet protocol that connects all ISPs.
It is decentralized and operates asynchronously, in the style of distance-vector routing.
The institutions that operate ASs make business agreements to interconnect their networks and exchange BGP routing information.
The role of BGP
BGP does not forward packets directly.
It selects and installs routes into the forwarding tables.
BGP operates on CIDR prefixes:
- each prefix represents a contiguous block of IP addresses (a subnet or aggregation of subnets)
- e.g., a destination could be
138.16.68/22(1,024 IPv4 addresses) or2001:db8::/32(IPv6 prefix)
BGP allows routers to:
- learn prefix reachability from other ASs:
- ASs advertise reachability to their IP prefixes
- BGP propagates this information across the Internet according to policy
- select the best route to each prefix:
- routers may learn multiple routes to the same prefix
- BGP runs a best-path selection process
- policy, rather than shortest path, is the primary driver of selection
Advertising BGP route information
This network has three autonomous systems: AS1, AS2 and AS3.
Each router in an AS is either:
- a gateway router (e.g.,
1.c): a router on the edge of an AS that connects to one or more routers in other ASs - an internal router (e.g.,
1.a,1.b,1.d): only connects inside its own AS
We want all routers to learn how to reach prefix x in AS3:
| Step | Details |
|---|---|
|
1. |
|
|
2. |
|
|
3. |
|
|
4. |
|
After these steps:
- every router in
AS1andAS2knows thatxexists - they also know an AS path to reach
x(AS2→AS3→x)
Routers exchange BGP messages over TCP connections (port 179).
Determining the best routes
In a real network, a router can learn multiple possible paths to the same destination.
For example, if a new link is added, there may now be two ways for AS1 to reach subnet x:
- via
AS2→AS3→x - directly via
AS3→x
How does a router choose between several possible routes to the same destination?
When a router advertises a prefix via BGP, it includes additional information called BGP attributes. A destination prefix together with its attributes is called a route.
Each route includes a prefix and several attributes, such as:
AS-PATH:- the sequence of ASs the route has traversed
- in this example, there are two routes from
AS1to subnetx:AS-PATH = AS2 AS3AS-PATH = AS3
- helps routers:
- compare paths (shorter or preferred ones may be chosen)
- avoid routing loops (if a router sees its own AS in the list, it rejects the route)
NEXT-HOP:- the IP address of the first router on the path to the next AS
- this links inter-AS routing with intra-AS routing
- example:
NEXT-HOPfor routeAS2 AS3 x= IP address of router2aNEXT-HOPfor routeAS3 x= IP address of router3d
Each router in AS1 learns two BGP routes to prefix x:
NEXT-HOP | AS-PATH | destination prefix
----------------------------------------------------------
IP address of router 2a; | AS2 AS3; | x
IP address of router 3d; | AS3; | x
Each BGP route consists of three components:
NEXT-HOPAS-PATHdestination prefix
In practice, a BGP route contains additional attributes.
Hot potato routing
In hot potato routing, a router forwards traffic through the closest exit point from its AS.
For router 1b:
- it checks the cost of reaching each
NEXT-HOPusing its intra-AS routing information - it compares:
- cost to router
2a - cost to router
3d
- cost to router
- it selects the route with the lower cost
Since 2a is closer, router 1b chooses the route through 2a.
The idea behind hot-potato routing is to get packets out of the AS as quickly as possible.
A packet is like a hot potato in your hands: you want to pass it to another AS as soon as you can, without worrying about what happens after it leaves your network.
Hot potato routing is a selfish algorithm:
- it minimizes costs inside the local AS
- it ignores costs outside the AS
As a result, two routers in the same AS may choose two different AS paths to the same prefix.
For example:
- router
1bsends traffic throughAS2to reachx - router
1dsends traffic directly toAS3to reachx
Route-selection algorithm
BGP uses a route-selection algorithm that includes hot potato routing, but also considers other factors.
When multiple routes exist for the same prefix, BGP applies the following rules in order until only one route remains:
| Step | Description |
|---|---|
|
1. Highest local preference |
|
|
2. Shortest |
|
|
3. Lowest intra-AS cost to the |
|
|
4. Lowest BGP Identifier |
|
Consider router 1b:
- there are two BGP routes to prefix
x:- one through
AS2 - one through
AS3
- one through
- if only hot potato routing were used,
1bwould choose the route throughAS2because itsNEXT-HOPis closer - however, BGP applies the shortest
AS-PATHrule before hot potato routing - since the route through
AS3has a shorterAS-PATH, BGP selects that route instead
As a result, BGP is not purely selfish:
- it considers the overall path through the Internet before considering the cost within its own AS
- this often leads to shorter end-to-end routes
A more realistic decision process includes additional steps such as:
- Highest weight (Cisco-specific)
- Highest local preference
- Locally originated route
- Shortest AS-PATH
- Lowest origin type
- Lowest MED
- eBGP over iBGP
- Lowest IGP cost to NEXT-HOP (hot potato routing)
- Various tie-breakers (router ID, neighbor address, etc.)
IP-Anycast
BGP is also used to implement IP anycast (RFC 7094), a routing technique used by systems such as DNS and CDNs.
During the IP-anycast configuration stage:
- the same IP address (or IP prefix) is assigned to multiple servers in different locations
- BGP advertises this same IP address from multiple physical sites
- each router on the Internet:
- receives multiple BGP routes to the same IP address
- uses the BGP route-selection algorithm to choose the preferred route
After the BGP address-advertisement phase, when a client sends a request:
- the client sends packets to the same anycast IP address
- Internet routing automatically forwards the packets along the best BGP path
- the request is delivered to the server instance selected by BGP routing (often the geographically closest one)
IP anycast is heavily used in the DNS system:
- the DNS root system has 13 logical root server identities (A–M)
- each root server identity is not a single machine, but a service that is replicated globally
- that service is run by many independent physical server instances distributed around the world
- these instances advertise the same IP addresses using BGP anycast
- as a result, when you query a root DNS server:
- your request is routed to one of the replicated root server instances
- the instance you reach depends on Internet routing, not on DNS itself
Routing policy
When a router selects a route, routing policy can override all other route-selection criteria.
This happens because routes are first ranked using the "local-preference" attribute, which is set by each AS according to its own policies.
Example with two types of networks:
- backbone providers
A,B,C(connected to each other) - customer networks (access ISPs)
W,X,Y:- routing rules:
- traffic entering must be destined for the ISP
- traffic leaving must originate from the ISP
Xis multi-homed (connected to two providers)
- routing rules:
| Network | Behavior | Image |
|---|---|---|
Customer network ( |
|
|
Backbone provider ( |
|
There are no strict global standards for inter-provider routing, but commercial ISPs generally follow this principle:
An ISP should only carry traffic if either the source or destination is a customer of that ISP.
Otherwise, the ISP is providing free transit, which is avoided unless explicitly agreed upon.
These arrangements are governed by peering agreements, which are often confidential.
BGP vulnerabilities
BGP relies on trust rather than built-in verification.
While this design allows the Internet to scale efficiently, it also enables accidental misconfigurations or false route announcements that can redirect or intercept traffic.
Real-world incidents demonstrate how BGP weaknesses can cause service outages, traffic diversion, and security breaches:
- Google (2017): accidental routing error and service disruption
- Amazon Route 53 (2018): malicious route hijacking and traffic interception
- Verizon (2019): large-scale route leak and misrouting
Because BGP was not originally designed with strong security controls, these failures have driven efforts to improve routing security through measures such as RPKI-based route validation, stronger route filtering, improved monitoring, and greater coordination among network operators.
Why are there different inter-AS and intra-AS routing protocols?
Because of the differences between the goals:
- routing within an AS: the goal is to optimize performance and speed (OSPF/IS-IS)
- routing among ASs: the goal is to enforce policy, business rules (control traffic exchange), and scalability (BGP)