Network tools · Vendor-neutral / Cisco NX-OS examples

BGP Neighbor States: Idle, Active, OpenSent and Established

BGP's state shows which stage of neighbor establishment has been reached. Active does not mean the peer is successfully exchanging routes. Established means the BGP session is up, but policies and address-family settings still determine which routes are exchanged and usable.

Scope: Protocol concepts are vendor neutral. Listed commands are Cisco NX-OS IPv4 unicast examples in the default VRF; consult platform syntax for other families.

The six states #

StateWhat it meansFirst evidence to inspect
IdleThe session is not progressing through establishmentAdministrative status and the last reset reason
ConnectTCP establishment is in progressRoutes to the peer and TCP reachability
ActiveBGP is attempting to obtain a TCP connectionBoth peer addresses, source selection and filtering
OpenSentA BGP OPEN has been sentOPEN acceptance, ASN settings and notification details
OpenConfirmBGP is waiting for confirmation through KEEPALIVE processingPeer logs and connection stability
EstablishedThe session can exchange BGP messagesAddress families, received routes and policies

Treat the table as a starting point, not a one-to-one fault decoder. A session can move quickly through several states or repeatedly restart. The last notification and the time since the reset usually provide more context than a single summary snapshot.

Read-only evidence collection #

Read-only evidence collection
Vendor-neutral / Cisco NX-OS examples · Cisco NX-OS operational CLI; default VRF, IPv4 unicast

Read-only
show ip bgp summary
Read-only

Replace these example values: 192.0.2.2.

show ip bgp neighbors 192.0.2.2
Read-only

Replace these example values: 192.0.2.2.

show ip bgp neighbors 192.0.2.2 routes
Read-only

Replace these example values: 192.0.2.2.

show ip bgp neighbors 192.0.2.2 advertised-routes

Use the correct VRF and address-family equivalent on your platform. Compare the configured peer address and ASN at both ends. Inspect the actual local address used for the session, particularly when peering from a loopback. A successful ping from an unrelated address is not proof that the BGP source is reachable.

Common reset messages #

A hold-timer expiry means the required BGP message activity was not received in time; it does not prove a particular cable or firewall caused the failure. An OPEN error requires examination of its error code and subcode. Cease also has subcodes: administrative shutdown and maximum-prefix conditions require different responses. Read the detail before changing timers or resetting the neighbor.

Established with no routes #

Separate session health from route acceptance. Check whether the expected family is negotiated, whether the peer advertises the prefix and whether import policy accepts it. Then inspect next-hop reachability and route selection. Some received-route views depend on stored pre-policy information and cannot be assumed available everywhere. Preserve the evidence before any disruptive clear command; the inspection commands above do not reset the session.

Sources

Documentation reviewed: 8 October 2026