Design multihomed eBGP topologies that survive the loss of a single provider or physical link without manual intervention.
Border Gateway Protocol Routing Design for Enterprise Networks
Plan, design and secure multihomed BGP routing for enterprise networks, from autonomous system architecture and path selection through route reflectors, filtering policy and RPKI-based origin validation.
Course Overview
Enterprise networks that connect to more than one internet service provider, operate their own autonomous system, or interconnect multiple data centres depend on the Border Gateway Protocol to decide which paths traffic takes and how failures are absorbed without an outage. Misconfigured attributes, flat iBGP meshes and unfiltered route advertisements are a common source of asymmetric routing, slow convergence and accidental route leaks that affect other networks. This course works through BGP as it is actually run in production: autonomous system numbering and peering models, the path selection algorithm and the attributes that influence it, multihoming to two or more providers, iBGP scaling with route reflectors and confederations, inbound and outbound filtering with prefix lists and route maps, and route origin validation with RPKI. Each session builds a piece of a working design using router configuration extracts, routing policy documents and topology diagrams, so participants leave able to design, filter and troubleshoot a BGP network rather than only recite its attributes. The final module covers change control, convergence testing and the routing changes needed when migrating address space or providers.
Expected Learning Outcomes
Apply the BGP path selection algorithm to predict and control which routes a router will prefer.
Scale internal BGP using route reflectors and confederations instead of a full iBGP mesh.
Build inbound and outbound routing policy with prefix lists, route maps and communities.
Validate route origins with RPKI and filter bogus or hijacked prefixes before they affect production traffic.
Diagnose slow convergence, route flapping and asymmetric routing using looking-glass output and router state.
Plan a phased BGP migration for provider changes or address renumbering with a documented rollback path.
Who Should Attend
Network engineers responsible for enterprise routing and internet edge design.
Infrastructure architects designing multihomed or multi-site wide area networks.
Network operations staff who troubleshoot routing incidents and peering issues.
Data centre network engineers introducing BGP into the underlay or overlay.
Service provider engineers who manage customer or peering BGP sessions.
IT managers overseeing a migration between internet service providers.
Course Modules
Select any module to see its sessions and points.
01BGP Architecture and the Path Selection Process
2 sessions · 8 points
Session 1Autonomous Systems and Enterprise Peering Models
- Distinguish public and private autonomous system numbers and decide when an enterprise needs its own ASN.
- Compare transit, peering and route-server relationships and their effect on routing policy.
- Map an enterprise edge design showing eBGP sessions to providers and iBGP sessions between routers.
- Document a peering and addressing plan that records AS numbers, prefixes and session parameters.
Session 2The Path Selection Algorithm and Route Attributes
- Trace the BGP best-path algorithm step by step from weight through router ID to select a route.
- Use local preference to set an outbound preference for a route across the autonomous system.
- Apply MED and AS-path prepending to influence how neighbouring networks route traffic inbound.
- Read a router's BGP table to explain why one path was selected over an available alternative.
02Resilient Multihoming and Internal BGP Scaling
2 sessions · 8 points
Session 1Multihoming Design for Providers and Data Centres
- Design active-active and active-backup multihoming for two or more internet service providers.
- Configure BFD alongside BGP so link failures are detected in milliseconds rather than seconds.
- Apply maximum-prefix limits and graceful shutdown communities to protect sessions during maintenance.
- Plan default-route and full-table strategies and their effect on router memory and convergence.
Session 2Route Reflectors and Confederations for iBGP
- Replace a full iBGP mesh with a route reflector hierarchy without creating routing loops.
- Design cluster IDs and redundant route reflectors so a single device failure does not isolate routes.
- Decide when a confederation of sub-autonomous systems is preferable to route reflection.
- Test that route reflector clients receive the routes a full mesh would have provided.
03Routing Policy, Filtering and Route Security
2 sessions · 8 points
Session 1Prefix Filtering, Route Maps and BGP Communities
- Build inbound and outbound prefix lists that block default routes and bogon address space.
- Write route maps that match on prefix, AS path and community to apply consistent policy.
- Tag routes with BGP communities to control redistribution and regional route advertisement.
- Aggregate and summarise announced prefixes to reduce table size without hiding needed detail.
Session 2RPKI Validation and Hijack and DDoS Mitigation
- Create route origin authorisations and configure origin validation to reject invalid announcements.
- Explain how a route hijack or leak propagates and the evidence that identifies one in progress.
- Apply remotely triggered black-hole routing to drop attack traffic close to the network edge.
- Set well-known communities such as no-export and no-advertise to contain internal routes.
04Operating, Monitoring and Evolving the BGP Network
2 sessions · 8 points
Session 1Convergence, Troubleshooting and Change Control
- Measure convergence time after a link or session failure and identify the slowest contributing step.
- Use looking-glass servers and route collectors to view how external networks see your prefixes.
- Diagnose route flapping and dampening behaviour that suppresses a legitimately recovering path.
- Run a peer review and staged rollout process for routing policy changes before they reach production.
Session 2Migration Planning and Segment Routing Foundations
- Plan a provider migration or address renumbering with a dual-announcement transition period.
- Write a rollback procedure that restores the previous routing policy within an agreed time.
- Introduce segment routing and EVPN control planes as BGP's role extends into the data centre.
- Hand over the finished design as a routing policy document that operations staff can maintain.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
