[c-nsp] Cogent IOS upgrade == BGP-3, "update malformed"

Tima Maryin timamaryin at mail.ru
Tue Aug 24 07:24:21 EDT 2010


Cogent probably hit CSCsy27511

I saw such thing when router affected by that bug sent malformed update 
to router that do not support 4 byte ASn.


On 23.08.2010 2:49, randal k wrote:
> Cogent did an IOS upgrade to our local router, and immediately after our
> peering with them started flapping wildly - gets about 10 seconds and
> ~69,000 prefixes in and resets with the following:
>
> 729078: Aug 22 16:21:39 MDT: %BGP-3-NOTIFICATION: sent to neighbor A.B.C.D
> 3/1 (update malformed) 21 bytes 31FE420C 31FE58C8 124683E8 0206CC67 00
> 729079: Aug 22 16:21:39 MDT: BGP: A.B.C.D Bad attributes FFFF FFFF FFFF FFFF
> FFFF FFFF FFFF FFFF 0060 0200 0000 4140 0101 0040 020C 0205 00AE 0CB9 235A
> 2046 5BA0 4003 0426 6532 7580 0404 0000 5DE8 C008 0800 AE52 0800 AE55 FD31
> FE42 0C31 FE58 C812 4683 E802 06CC 6700 0000 0002 1854 1608 1854 1609
>
> I of course thought max as-path issues, but we already fixed that network
> wide and confirmed that it is already set to 100. Our transit_input
> route-map strips off everything; any idea what they could be sending us that
> would cause our router to kill the session? Anybody seen anything similar?
> We are thinking may something random with 4-byte ASNs or something community
> related; as such we've asked for a similar stripper on their output, and if
> that doesn't work, a code downgrade.
>
> They're on a 7609 running God-knows-what, we were on 12.4(13c) and upgraded
> to 12.4(24)T3, same issue.


More information about the cisco-nsp mailing list