Mastering Local AS - Private Mode¶
Juhie Mohan Motiani - 11/03/2025
A detailed breakdown of the Private option for the local-AS setting in BGP on Juniper devices, showing how this mode influences AS-path prepending in both eBGP and iBGP peering. It covers configuration examples, route propagation scenarios, and illustrates how the local AS and global AS values are prepended differently depending on peer type.
Introduction¶
This series of techpost will provide a comprehensive overview of the various BGP local AS configuration options available on Juniper devices. Local AS is a powerful feature used in scenarios such as network migrations, mergers, and acquisitions. It enables BGP sessions to present a local AS number instead of the global AS when establishing peerings. We will detail the behavior of each configuration option, covering both the iBGP and eBGP use cases. A summary table of AS paths of all the routes after each local AS option is included for quick reference and comparison.
Five local AS options are available, each catering to a range of use cases, from seamless network migrations to complex multi-homing scenarios:
These options allow network operators to modify AS path information, influencing how routes are perceived and propagated within and beyond their autonomous system. The following sections provide an in-depth exploration of the default option, highlighting its strengths and limitations.
Private Local-AS Option¶
Syntax: local-as
The local AS private option allows the local AS to be used only during session establishment with the eBGP neighbor and is hidden in AS paths sent to other external peers. Therefore, only global AS will be included in AS paths advertised to other external peers. This is useful when peering locally with devices still configured with the old AS, but you want to prevent the local AS from being propagated beyond the immediate neighbor. This helps maintain legacy peerings without exposing the local AS globally.
Example configuration:
Key behaviors:
- Peer Establishment: BGP sessions use the local ASN in their OPEN message.
- Local AS applied to eBGP peer:
- Routes advertised from eBGP peers with local-as private configuration to other eBGP peers will only have the global ASN number prepended to the AS path and not the local ASN as it is private.
- Routes advertised from eBGP peers with local-as private configuration to iBGP will NOT have the local ASN or the global ASN prepended to the AS path as the local ASN is private.
- Local AS applied to iBGP peer:
- Routes advertised from iBGP peers with local-as private configuration to other eBGP peers will only have the global ASN prepended to the AS path.
- Routes advertised from iBGP peers with local-as private configuration to other iBGP peers will NOT have the local ASN or the global ASN prepended to the AS path.
- Cannot be used with the alias option.
Scenario Overview¶
The primary goal of this document is to validate the behavior of the private local AS option and understand how the AS path is prepended or modified in different scenarios. It takes various route propagation scenarios into account and lists the expected AS path for each route.
AS Path Verification Points¶
We examine the AS path in three distinct contexts:
- Show route advertising-protocol output. Displays the AS path that will be advertised to the neighbor, including the AS numbers being prepended.
- Actual BGP UPDATE message content (captured via traceoptions). Reflects the AS path as it appears within the real BGP UPDATE message sent to the peer.
- Local routing table (RIB) representation. Shows the AS path stored in the local routing table prior to any AS path modifications.
Capturing both the show route advertising-protocol output and the actual BGP UPDATE message allows us to identify and analyze any discrepancies between the intended advertisement and the actual message transmitted.
Topology¶
The example environment consists of five routers arranged in a star topology, with router R3 serving as the central node and Device Under Test (DUT). Each router's global AS number is indicated within the square boxes. This is the base topology and currently does not show local-as configuration. The local-as configuration will be applied on R3 (DUT) towards either R1 (eBGP) or R4 (iBGP), depending on the specific example scenario. For each example, the topology will indicate where local-as is applied and how the route propagates. This topology is purposefully designed to thoroughly evaluate various route propagation behaviors and to analyze the effects of local AS configurations in each context.

Assumptions and Considerations¶
- R3 is the Device Under Test (DUT), and all observations are made through R3's lens.
- The local-as configuration is always applied on R3 (DUT) towards R1 for eBGP scenarios and towards R4 for iBGP scenarios.
- Local-as configuration is only applied towards one router (either R1 or R4) for a given eBGP/iBGP scenario.
- AS number 65551 refers to the Local AS, and AS number 64503 refers to the Global AS.
- The topology used in this document is only for educational purposes and should not be used as a reference for any other purpose.
Configuration: Local AS Private configured towards eBGP peer (R1)¶
The following five example scenarios cover all the cases where local AS private configuration on an eBGP setup impacts the AS path.
Please note that "*" in below examples marks the neighbor on which R3 (DUT) has the local-as configuration applied.
Example 1: Route propagation from eBGP* (R1) to eBGP (R2)¶
This example describes the propagation of routes learned via eBGP from R1 to the eBGP peer R2, where R3 applies a local AS private on its eBGP session with R1. R1 advertises its loopback address 192.0.2.1/32 to R3, which then re-advertises the prefix to R2.
AS path of prefix 192.0.2.1/32 in the routing table inet.0 on R3:
AS path of prefix 192.0.2.1/32 in the show route advertising-protocol output on R3:
AS path of prefix 192.0.2.1/32 in the BGP UPDATE message sent to R2:
Example 2: Route propagation from eBGP* (R1) to iBGP (R4)¶
This example describes the propagation of routes learned via eBGP from R1 to the iBGP peer R4, where R3 applies a local AS private on its eBGP session with R1. R1 advertises its loopback address 192.0.2.1/32 to R3, which then re-advertises the prefix to R4.
AS path of prefix 192.0.2.1/32 in the routing table inet.0 on R3:
AS path of prefix 192.0.2.1/32 in the show route advertising-protocol output on R3:
AS path of prefix 192.0.2.1/32 in the BGP UPDATE message sent to R4:
Example 3: Route propagation from DUT (R3) to eBGP* (R1)¶
This example examines the AS path of a direct/static route advertised to an eBGP peer. R3 advertises its loopback address 192.0.2.3/32 to R1.
AS path of prefix 192.0.2.3/32 in the routing table inet.0 on R3:
The AS path of prefix 192.0.2.3/32, as shown in the output of the show route advertising-protocol command on R3:
The example above includes square brackets to indicate the AS number being prepended to the AS path before advertisement
AS path of prefix 192.0.2.1/32 in the BGP UPDATE message sent to R1:
Example 4: Route propagation from eBGP (R2) to eBGP* (R1)¶
This example describes the propagation of routes learned via eBGP from R2 to the eBGP peer R1, where R3 applies a local AS private on its eBGP session with R1. R2 advertises its loopback address 192.0.2.2/32 to R3, which then re-advertises the prefix to R1.
AS path of prefix 192.0.2.2/32 in the routing table inet.0 on R3:
AS path of prefix 192.0.2.2/32 in the show route advertising-protocol output on R3:
AS path of prefix 192.0.2.2/32 in the BGP UPDATE message sent to R1:
Example 5: Route propagation from iBGP (R4) to eBGP* (R1)¶
This example describes the propagation of routes learned via iBGP from R4 to the eBGP peer R1, where R3 applies a local AS private on its eBGP session with R1. R4 advertises its loopback address 192.0.2.4/32 to R3, which then re-advertises the prefix to R1.
AS path of prefix 192.0.2.4/32 in the routing table inet.0 on R3:
AS path of prefix 192.0.2.4/32 in the show route advertising-protocol output on R3:
AS path of prefix 192.0.2.4/32 in the BGP UPDATE message sent to R1:
Private local AS Option Behavior for an eBGP Peer¶
| Route Direction(S -> DUT -> D) | As PathLocal RIB | AS Path(show adv to "D") | UPDATE MESSAGEto "D" | ASPATH_PREPENDby DUT |
|---|---|---|---|---|
| R1 -> R3 -> R2 | 64501 I | [64503] 64501 I | 64503 64501 I | Global-as |
| R1 -> R3 -> R4 | 64501 I | [64503] 64501 I | 64501 I | |
| R3 -> R1 | I | [65551] I | 65551 I | Local-as |
| R2 -> R3 -> R1 | 64502 I | 64503 64502 I | 65551 64503 64502 I | Local-as, Global-as |
| R4 -> R3 -> R1 | I | 64503 I | 65551 64503 I | Local-as, Global-as |
Configuration: Local AS Private configured towards iBGP peer (R4)¶
The following five example scenarios cover all the cases where local AS private configuration on an iBGP setup impacts the AS path.
Example 1: Route propagation from iBGP* (R4) to eBGP (R1)¶
This example describes the propagation of routes learned via iBGP from R4 to the eBGP peer R1, where R3 applies a local AS private on its iBGP session with R4. R4 advertises its loopback address 192.0.2.4/32 to R3, which then re-advertises the prefix to R1.
AS path of prefix 192.0.2.4/32 in the routing table inet.0 on R3:
AS path of prefix 192.0.2.4/32 in the show route advertising-protocol output on R3:
AS path of prefix 192.0.2.4/32 as seen in the BGP UPDATE message sent to R1:
Example 2: Route propagation from iBGP* (R4) to iBGP (R5)¶
This example describes the propagation of routes learned via iBGP from R4 to the iBGP peer R5, where R3 applies a local AS private on its iBGP session with R4. R4 advertises its loopback address 192.0.2.4/32 to R3, which then re-advertises the prefix to R5.
AS path of prefix 192.0.2.4/32 in the routing table inet.0 on R3:
AS path of prefix 192.0.2.4/32 in the show route advertising-protocol output on R3:
AS path of prefix as seen in the BGP UPDATE message sent to R5:
Example 3: Route propagation from DUT (R3) to iBGP* (R4)¶
This example examines the AS path of a direct/static route advertised to an iBGP peer. R3 advertises its loopback address 192.0.2.3/32 to R4.
AS path of prefix 192.0.2.3/32 in the routing table inet.0 on R3:
AS path of prefix 192.0.2.3/32 in the show route advertising-protocol output on R3:
AS path of prefix 192.0.2.3/32 as seen in the BGP UPDATE message sent to R4:
Example 4: Route propagation from eBGP (R1) to iBGP* (R4)¶
This example describes the propagation of routes learned via eBGP from R1 to the iBGP peer R4, where R3 applies a local AS private on its iBGP session with R4. R1 advertises its loopback address 192.0.2.1/32 to R3, which then re-advertises the prefix to R4.
AS path of prefix 192.0.2.1/32 in the routing table inet.0 on R3:
AS path of prefix 192.0.2.1/32 in the show route advertising-protocol output on R3:
AS path of prefix 192.0.2.1/32 as seen in the BGP UPDATE message sent to R4:
Example 5: Route propagation from iBGP (R5) to iBGP* (R4)¶
This example describes the propagation of routes learned via iBGP from R5 to the iBGP peer R4, where R3 applies a local AS private on its iBGP session with R4. R5 advertises its loopback address 192.0.2.5/32 to R3, which then re-advertises the prefix to R4.
AS path of prefix 192.0.2.5/32 in the routing table inet.0 on R3:
AS path of prefix 192.0.2.5/32 in the show route advertising-protocol output on R3:
AS path of prefix 192.0.2.5/32 as seen in the BGP UDPATE message sent to R4:
Private local AS Option Behavior for an iBGP Peer¶
| Route Direction(S -> DUT -> D) | As PathLocal RIB | AS Path(show adv to "D") | UPDATE MESSAGEto "D" | ASPATH_PREPENDby DUT |
|---|---|---|---|---|
| R4 -> R3 -> R1 | I | [64503] I | 64503 I | Global-as |
| R4 -> R3 -> R5 | I | [64503] I | ||
| R3 -> R4 | I | [65551] I | ||
| R1 -> R3 -> R4 | 64501 I | 64503 64501 I | 64503 64501 I | Global-as |
| R5 -> R3 -> R4 | I | 64503 I | 64503 I | Global-as |
Conclusion¶
This article covered the details of Private Local AS option, please check the articles in the section below for the other options.
Useful links¶
Local-AS options articles:
Glossary¶
- AS(N): Autonomous System (Number)
- BGP: Border Gateway Protocol
- DUT: Device Under Test
- ISP: Internet Service Provider
- RIB: Routing Information Base
Comments¶
If you want to reach out for comments, feedback or questions, drop us an email at: