Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Diagnostics-only BGP troubleshooting patterns for neighbor state, route exchange, prefix policy, AS path inspection, and safe evidence collection.
.claude/skills/network-bgp-diagnostics/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | — | — |
| case-05 | ✗→✓ | ▲ Improved | — | — |
| case-10 | ✗→✓ | ▲ Improved | — | — |
| case-22 | ✗→✗ | = Same ✗ | — | — |
| case-14 | ✗→✗ | = Same ✗ | — | — |
Use this skill when a BGP session is down, flapping, established with missing routes, or advertising unexpected prefixes. The default workflow is read-only evidence collection; policy and reset actions belong in a reviewed change window.
routes.
supports those commands.
textshow bgp summary show bgp neighbors <peer> show ip route <peer> show tcp brief | include <peer>|:179 show logging | include BGP|<peer> show running-config | section router bgp show ip prefix-list show route-map
Use platform-specific address-family commands when the device uses VRFs, IPv6, VPNv4, or EVPN. Do not assume global IPv4 unicast.
| State | First checks | | --- | --- | | Established with prefix count | Route exchange is up; inspect policy and table selection | | Established with zero prefixes | Check inbound policy, max-prefix, advertised routes, and AFI/SAFI | | Active | TCP session is not completing; check routing, source, ACLs, and peer reachability | | Connect | TCP connection is in progress; check path and remote listener | | OpenSent/OpenConfirm | TCP works; check ASN, authentication, timers, capabilities, and logs | | Idle | Neighbor may be disabled, missing config, blocked by policy, or backoff timer |
textping <peer> source <local-source> traceroute <peer> source <local-source> show ip route <peer> show bgp neighbors <peer> | include BGP state|Last reset|Local host|Foreign host
If the peer is sourced from a loopback, confirm both directions route to the loopback addresses and that the neighbor config uses the expected update source.
Avoid disabling ACLs or firewall policy as a diagnostic shortcut. Read hit counters, logs, and path state first.
textshow bgp neighbors <peer> advertised-routes show bgp neighbors <peer> routes show ip prefix-list <name> show route-map <name> show bgp <prefix>
Some platforms require additional configuration before received-routes is available. Do not add that configuration during incident triage unless the operator approves the change.
textshow bgp regexp _65001_ show bgp regexp ^65001$ show bgp <prefix> show bgp neighbors <peer> advertised-routes | include Network|Path|<prefix>
Use AS-path regex carefully. _65001_ matches AS 65001 as a token. Plain 65001 can match longer ASNs or unrelated text.
pythonimport re from typing import Any BGP_SUMMARY_RE = re.compile( r"^(?P<neighbor>\d{1,3}(?:\.\d{1,3}){3})\s+" r"(?P<version>\d+)\s+" r"(?P<remote_as>\d+)\s+" r"(?P<msg_rcvd>\d+)\s+" r"(?P<msg_sent>\d+)\s+" r"(?P<table_version>\d+)\s+" r"(?P<input_queue>\d+)\s+" r"(?P<output_queue>\d+)\s+" r"(?P<uptime>\S+)\s+" r"(?P<state_or_prefixes>\S+)$", re.M, ) def parse_bgp_summary(raw: str) -> list[dict[str, Any]]: rows = [] for match in BGP_SUMMARY_RE.finditer(raw): state_or_prefixes = match.group("state_or_prefixes") if state_or_prefixes.isdigit(): state = "Established" prefixes_received = int(state_or_prefixes) else: state = state_or_prefixes prefixes_received = None rows.append({ "neighbor": match.group("neighbor"), "remote_as": int(match.group("remote_as")), "state": state, "prefixes_received": prefixes_received, "uptime": match.group("uptime"), }) return rows
Prefer structured parser output when available, but store raw output with the incident record because BGP summary formats vary by platform and address family.
These actions can affect routing and should not be suggested as automatic diagnostics:
prefix-lists.
If a reset is approved, prefer the least disruptive soft or route-refresh option supported by the platform and document exactly why it is safe.
Active always means the remote side is down.received-routes output as proof that no routes arrived.cisco-ios-patternsnetwork-config-validationnetwork-interface-health| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-22 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-14 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-12 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-11 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-13 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-01 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-20 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-06 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-19 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-15 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-07 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-08 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-09 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-04 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-17 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-16 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-03 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-18 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-21 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-02 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-05 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-10 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +14 percentage points is the difference between those two pass rates over the 22 comparable cases.
The per-case answers from this run were removed by the retention sweep, so the case table below shows the verdicts without the text either arm produced. The counts above were recorded at the time and are unaffected. Answers are now kept for 180 days.
Other measured skills in the registry, with their headline benchmark lift.