Back to feed
Dev.to
Dev.to
7/12/2026
Competing Origins: When Two ASes Announce the Same Prefix, Who Do You Believe?

Competing Origins: When Two ASes Announce the Same Prefix, Who Do You Believe?

Short summary

This hands-on lab demonstrates what happens when two autonomous systems announce the same BGP prefix, creating competing origins that an observer router sees as two paths. The exercise uses three virtual routers in a Docker/containerlab environment with FRRouting, showing that BGP alone cannot determine which origin AS is authorized. The lab sets up the foundation for understanding route leaks, hijacks, and why RPKI origin validation is needed to answer authorization questions.

  • Two ASes announcing the same prefix creates competing origins visible as multiple BGP paths
  • BGP tables alone cannot verify which origin AS is actually authorized to announce a prefix
  • RPKI origin validation is the tool that answers authorization — covered in the next lab

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more