Day 31 --- Conditional Advertisement with advertise-map, exist-map and non-exist-map
1. Opening
Conditional advertisement is useful when a route should be announced only while another BGP condition exists---or only while it does not. It is particularly valuable for backup advertisements in multihomed networks, but it is also easy to misuse because the condition is evaluated from BGP table state, not from an arbitrary business notion of 'the primary circuit is healthy.'
The operational objective is not simply to make BGP choose a route. It is to make the intended behavior predictable during the normal state, degraded state, and rollback state.
| Conditional Advertisement with advertise-map, exist-map and non-exist-map |
2. Concept and standards behavior
Cisco conditional advertisement uses an advertise-map to identify what may be announced and an exist-map or non-exist-map to define the BGP-table condition. With non-exist-map, the advertised route becomes eligible when the condition route is absent. With exist-map, it becomes eligible when the condition route is present. This is Cisco implementation behavior; it is not a generic RFC 4271 primitive.
BGP remains a policy protocol. RFC 4271 provides the protocol framework, while several practical traffic-engineering controls are Cisco or operator-policy mechanisms. Evaluate each design at three layers: protocol behavior, IOS XE implementation, and neighboring-AS policy.
Separate route eligibility, route selection, and route export. Eligibility asks whether a path is usable. Selection determines the local best path. Export policy determines what a neighbor is permitted to learn.
3. Scenario
AS 65010 is dual-homed to ISP-A AS 65020 and ISP-B AS 65030. The enterprise service prefix is 203.0.113.0/24. Transit links use 192.0.2.0/30 and 198.51.100.0/30.
Success criteria 1. Primary and backup behavior is explicit. 2. No route is exported merely because it exists locally. 3. Failure behavior is observable in BGP and advertised-route evidence. 4. Rollback is independent of session redesign. 5. A negative test proves unintended advertisement is absent.
4. Topology
ISP-A AS65020 --- 192.0.2.0/30 --- EDGE1/AS65010
|
203.0.113.0/24
|
ISP-B AS65030 --- 198.51.100.0/30 --- EDGE2/AS65010
5. Prerequisites
- IOS XE 17.18.x documentation baseline.
- IPv4 unicast activated for both eBGP peers.
- Service prefix valid for origination.
- Independent management access.
- Pre-change capture of BGP state and advertised routes.
6. Baseline configuration
Topic-specific configuration excerpt --- not a complete device configuration.
router bgp 65010
address-family ipv4
network 203.0.113.0 mask 255.255.255.0
neighbor 192.0.2.1 remote-as 65020
neighbor 198.51.100.1 remote-as 65030
neighbor 198.51.100.1 advertise-map ADV-BACKUP non-exist-map PRIMARY-HEALTH
exit-address-family
ip prefix-list PL-SERVICE permit 203.0.113.0/24
route-map ADV-BACKUP permit 10
match ip address prefix-list PL-SERVICE
ip prefix-list PL-PRIMARY-HEALTH permit 192.0.2.0/30
route-map PRIMARY-HEALTH permit 10
match ip address prefix-list PL-PRIMARY-HEALTH
7. Verification before modification
show bgp ipv4 unicast
show bgp ipv4 unicast 203.0.113.0/24
show bgp ipv4 unicast neighbors
show bgp ipv4 unicast neighbors 192.0.2.1 advertised-routes
show bgp ipv4 unicast neighbors 198.51.100.1 advertised-routes
show route-map
show ip prefix-list
The question is not whether the policy object exists; it is whether the intended route is selected, matched and actually exported to the intended neighbor.
8. Controlled modification
Withdraw the route used by PRIMARY-HEALTH and predict that the backup service advertisement becomes eligible toward ISP-B. Then restore it and verify withdrawal of the conditional advertisement.
Predict Adj-RIB-Out behavior before applying the change. Re-evaluate policy using the least disruptive supported mechanism.
9. Fault injection
Illustrative lab — not a real incident.
Remove the condition route while leaving both BGP sessions up. The symptom should be a change in advertisement state rather than a session reset.
Change one variable only, capture the changed state, and compare it with the baseline.
10. Troubleshooting
- Confirm affected prefix and traffic direction.
- Confirm eBGP sessions are Established.
- Confirm local route eligibility/origination.
- Inspect selected BGP route.
- Inspect match objects.
- Inspect route-map sequence and implicit deny.
- Inspect advertised routes per provider.
- Confirm policy direction.
- Determine whether route refresh is required.
- Run positive traffic test.
- Run negative/containment test.
- Correct the smallest proven cause and repeat the same evidence set.
11. Root cause and correction
The usual failure is matching the wrong route in the condition map or assuming interface state is directly tracked. Correct the condition so it represents the BGP reachability signal the design actually intends to use.
12. Post-fix verification
Verify session state, route acceptance, selected path, exported attributes, advertised routes, forwarding and the negative test. Local advertisement does not prove remote selection.
13. Rollback
Revert only the new policy action, re-evaluate policy with the least disruptive supported method, and confirm both providers return to baseline. Roll back immediately for loss of all reachability, unintended transit, unapproved deaggregation or export outside the approved prefix set.
14. Production lessons
Conditional advertisement is a policy-state machine. Document exactly what route constitutes the condition, how quickly it changes, and what false positives could trigger the backup advertisement.
15. Knowledge check
map?
policy?
leaking?
- Why is
advertised-routesstronger evidence than displaying a route - Which parts are controlled locally and which depend on upstream
- What negative test proves the restricted/backup advertisement is not
Answers
inbound selection are remote policy.
routes in the healthy state.
- It validates resulting per-neighbor export state.
- Local selection/export are local; remote LOCAL_PREF, propagation and
- Verify the protected prefix is absent from the neighbor's advertised
16. Sources
- RFC 4271 --- BGP-4 base behavior
- Cisco IOS XE 17.x --- BGP VRF-Aware Conditional Advertisement