Dev.to
7/12/2026

Competing Origins: When Two ASes Announce the Same Prefix, Who Do You Believe?
Short summary
This hands-on lab demonstrates what happens when two autonomous systems announce the same BGP prefix, creating competing origins that an observer router sees as two paths. The exercise uses three virtual routers in a Docker/containerlab environment with FRRouting, showing that BGP alone cannot determine which origin AS is authorized. The lab sets up the foundation for understanding route leaks, hijacks, and why RPKI origin validation is needed to answer authorization questions.
- •Two ASes announcing the same prefix creates competing origins visible as multiple BGP paths
- •BGP tables alone cannot verify which origin AS is actually authorized to announce a prefix
- •RPKI origin validation is the tool that answers authorization — covered in the next lab
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



