Which BGP AS path access list permits only routes originated in AS 100?

Answer Correct answer: B — Use ip as-path access-list 1 permit ^100$ to allow only routes originated in AS 100.

Refer to the exhibit. Customer B has decided not to receive any routes from R1 that originated outside the AS 100. Which AS path access list must the engineer choose to meet this requirement? - image - image

  1. ip as-path access-list 1 permit ^10[0-9]*$
  2. ip as-path access-list 1 permit ^100$ Correct Answer
  3. ip as-path access-list 1 permit _100$
  4. ip as-path access-list 1 permit _100_

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tested is the regex anchor use in BGP AS-path filters; the trap is choosing _100$ or _100_ which match 100 anywhere rather than as the sole origin AS.

This question tests BGP AS path access lists for filtering routes originated outside AS 100. The page explains why the correct filter is ^100$, permitting only routes whose entire AS path is 100.

Many select _100$ (C) thinking it matches routes ending in AS 100, but routes originated outside AS 100 arrive with AS path '100 <origin>', so they do not end in 100; only ^100$ ensures the route originated in AS 100.

Community Discussion (8 comments)

vitalizator 👍 5 Selected: B
Correct answer is B since AS100 is the neighboring AS of R6 so it will be always the 1st in the AS path, and we don't want to see any other AS behind AS100, so it has to be ^100$
Anarky19 👍 1 Selected: B
In R6 if we notice the bgp table, the sentence > Net: 6.6.6.6/32 ............ Path: 100 500, I think it should be: > Net: 6.6.6.6/32 ............ Path: 500 100 Shouldn't it?
jabal93 👍 3
^ means AS number start with $ means AS number end with so, we only want routes from AS100 then ^100$
jabal93 👍 1 Selected: B
Indeed B is correct (Agree with Vitalizator & dapardo & Pietjeplukgeluk & SeMoOoOoO)
[Removed] 👍 1 Selected: B
Indeed B is correct (Agree with Vitalizator & dapardo & Pietjeplukgeluk)
[Removed] 👍 1 Selected: B
Indeed B is correct (Agree with Vitalizator & dapardo & Pietjeplukgeluk)
Pietjeplukgeluk 👍 2 Selected: B
Indeed B is correct (Agree with Vitalizator & dapardo)
dapardo 👍 3 Selected: B
Agree with Vitalizator, B is the right one

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement is to allow Customer B to receive only routes that originated within AS 100 from R1. Because R1 is in AS 100, every route it advertises to an eBGP peer begins with AS 100. A route originated in AS 100 will have an AS path of exactly "100", while a route originated outside AS 100 will have an AS path like "100 200" or "100 65001 200". The regex ^100$ anchors to both the start and the end of the AS path, so it matches only the single-AS path "100". Option B therefore permits exactly the routes that originated in AS 100 and denies all others. This aligns with the community consensus, with vitalizator noting that AS100 is the neighboring AS and is always first, so no other AS should appear behind it.

Why the Other Options Are Wrong

Option A (^10[0-9]*$) is broader than needed: it matches any AS path consisting of a single AS number that starts with "10", such as 10, 100, 101, or 1000. While currently the neighbor is AS 100, the filter is not semantically restricted to AS 100 and could permit unintended origins if the topology changed. Option C (_100$) uses a trailing anchor and matches any AS path that ends with AS 100; a route originated in AS 200 and advertised through a path like "300 100" would incorrectly match if such a path existed, though from R1 the typical outside-origin path ends with the origin AS, not 100. Option D (_100_) matches AS 100 anywhere in the path, including "100 200", which would permit every route from R1 and fail the requirement entirely. Only B enforces that the whole path is exactly AS 100.

Community Comment Notes

The community overwhelmingly favors B. Vitalizator's explanation is the most cited: "AS100 is the neighboring AS of R6 so it will be always the 1st in the AS path" and no other AS should appear behind it. Jabal93 reinforced the regex logic: "$ means AS number end with so, we only want routes from AS100". Dapardo and Pietjeplukgeluk simply agreed with vitalizator, adding to the consensus. Anarky19 raised a side observation about the exhibit showing "Path: 100 500" and wondered if it should be "500 100", but that reflects normal AS path ordering where the neighbor AS is leftmost; it does not change the correct filter.

Official Reference

Exam Strategy

Memorize the regex anchors: ^ matches the beginning of the AS path, $ matches the end, and _ matches a space, comma, brace, or beginning/end. For origin filtering, use ^<AS>$ when you need routes that both start and end with that AS. Practice distinguishing origin (whole path) from transit (anywhere in path) filters.

Frequently Asked Questions

Why does _100$ not meet the requirement to block routes originated outside AS 100?

It matches any AS path ending in 100, but routes originated outside AS 100 arrive from R1 as 100 <origin-AS>, so they do not end in 100 and would still be permitted.

What is the difference between ^100$ and _100_ in BGP AS path filtering?

^100$ matches only an AS path that is exactly AS 100, while _100_ matches 100 anywhere in the path, including transit paths like 100 200.

More 300-410 FAQ →

Related Analysis

Practice All 300-410 Questions

Access 159 questions with complete answers and detailed explanations.

View Full 300-410 Practice Test →

← Back to 300-410 Study Guide