A BGP community is a tag attached to a route that lets networks group prefixes and apply routing policy to the whole group at once, instead of matching each prefix by hand.
It is an optional, transitive BGP attribute: a 32-bit value, usually written as two numbers like 65000:100, that travels with the route across networks. The first half is normally the AS number that defined the community; the second is a value meaningful to that AS.
Some communities are well-known and standard, such as NO_EXPORT, which tells a network not to advertise the route beyond itself. Most others are private conventions an operator publishes.
- A BGP community is a tag attached to a route to group it for policy
- It is a 32-bit, optional, transitive attribute, usually written AS:value
- Well-known communities like NO_EXPORT have a standard meaning everywhere
- Most communities are private conventions an operator defines and publishes
- They let networks signal routing policy to each other without custom filters
On this page
What it isWhat a BGP community is
The BGP community solves a scaling problem in routing policy: applying rules to thousands of prefixes in the BGP table at once.
It is a tag for grouping routes. RFC 1997 defines the community attribute as a way to group destinations so that a routing decision can be applied to the whole group. Rather than a policy that lists every prefix, a network tags the prefixes with a community and writes one policy that matches the tag.
It is an optional, transitive attribute. The community is an optional transitive BGP attribute, meaning a router that does not understand it passes it along unchanged. Because it is transitive, the tag travels with the route from one network to the next unless a network deliberately strips it.
It carries no forwarding meaning by itself. A community does not change where a packet goes on its own. It is a marker; what happens is decided by the policy each network applies when it sees the tag. The community is the signal, and the policy is the action.
The formatThe format of a BGP community
The number is small, and its structure is a convention worth knowing.
It is 32 bits, four octets. The community attribute is a set of four-octet values, each specifying one community. A route can carry several communities at once, each a separate 32-bit value.
It is written as AS:value. By convention the 32 bits are split into two 16-bit halves and written as two numbers, such as 65000:100. The first number is normally the AS number that defined the community, and the second is a value that means something to that AS.
Some ranges are reserved. RFC 1997 reserves the values from 0x00000000 to 0x0000FFFF and from 0xFFFF0000 to 0xFFFFFFFF; the rest are available for networks to use as AS:value. The reserved top range is where the well-known communities live.
Well-known onesWell-known communities
A handful of communities mean the same thing on every network, and they are the ones to memorize.
NO_EXPORT keeps a route inside. The NO_EXPORT community, 0xFFFFFF01, tells a network not to advertise the route to any peer outside the local AS or confederation. It is how a route is kept internal even though it is carried in BGP.
NO_ADVERTISE hides it entirely. The NO_ADVERTISE community, 0xFFFFFF02, tells a network not to advertise the route to any peer at all, internal or external. The route stops at the router that receives it.
NO_EXPORT_SUBCONFED stays in the sub-AS. The NO_EXPORT_SUBCONFED community, 0xFFFFFF03, keeps the route from being advertised to other sub-autonomous-systems within a confederation. These well-known communities are standard, so any compliant router acts on them without a private agreement.
Two more were registered later. RFC 3765 added NOPEER, 0xFFFFFF04, which lets the origin AS ask that a route not be readvertised across bilateral peering sessions. RFC 7999 added BLACKHOLE, 0xFFFF029A, and notes that its low-order two octets in decimal are 666, so it is written 65535:666.
In a router configuration the well-known communities appear as keywords, not as numbers. The FRRouting documentation lists them this way:
| Keyword in the config | Well-known BGP community | Value |
|---|---|---|
| no-export | NO_EXPORT | 0xFFFFFF01 |
| no-advertise | NO_ADVERTISE | 0xFFFFFF02 |
| local-AS | NO_EXPORT_SUBCONFED | 0xFFFFFF03 |
| no-peer | NOPEER | 0xFFFFFF04 |
| blackhole | BLACKHOLE | 0xFFFF029A |
In practiceHow communities are used in practice
The real power of BGP communities is that they let one network drive another's policy, by agreement. On the internet that is mostly a customer steering traffic through its transit providers.
Providers publish what their communities do. A transit provider defines communities that customers can set to control how their routes are handled: one to set the local preference, one to prepend the AS path toward certain regions, one to block export to a particular peer. The provider publishes the list, and the customer just tags the route.
They enable remotely triggered blackholing. A widely used case is blackhole communities: a customer under a DDoS attack tags the targeted prefix with the provider's blackhole community, and the provider drops traffic to it at its edge. One tag triggers a policy the customer could not apply themselves.
Their meaning is by convention. Apart from the well-known ones, a community is just a number until two networks agree what it means. The same 65000:100 can mean completely different things on two different networks, so the operator's documentation is what gives a private community its meaning.
Large and extendedLarge and extended communities
The original 32-bit format ran short, and two extensions fill the gap.
Extended communities add structure. Extended communities are eight octets and carry a type, which lets them encode structured information such as route targets in MPLS VPNs, beyond the plain tag of a standard community.
Large communities fit 32-bit AS numbers. A standard community's 16-bit first half cannot hold a modern 32-bit AS number. Large communities, defined in RFC 8092, are twelve octets, written as three numbers, so a network with a 32-bit ASN can still express AS:function:parameter tags.
Standard communities remain the common case. For most day-to-day policy signaling the plain 32-bit community is still what operators use and publish, with large communities filling in where the AS number no longer fits.
Setting and matchingSetting, matching and removing communities
BGP communities are worked in a routing policy in three ways, and knowing them makes the mechanism concrete. On most routers the policy is a route map, and the match is a BGP community list.
A router sets communities on a route. As a prefix is learned or advertised, a router policy can add one or more communities to it, stamping the network intent onto the route before it is passed to peers. This is where an autonomous system marks its own routes.
Policy matches communities to act. On the receiving side, a router matches routes carrying a given community and applies the action: raise or lower local preference, prepend the AS path, filter the prefix, or set another attribute. Matching the tag is how one policy governs many advertised prefixes at once.
Communities can be added or stripped. A network can add communities to the routes it originates, keep the values it receives from peers, or delete them so downstream networks do not inherit them. Controlling which communities survive on which routes is part of a clean routing policy.
They complement the other attributes. Communities do not replace local preference, AS path or MED; they are a signaling layer on top, a compact way to ask that those attributes be set. The action a community triggers is usually a change to one of the classic BGP path attributes the routing decision already uses.
ConfigurationA BGP community configuration example
The syntax below is FRRouting's, which is what pfSense and many Linux routers run, and the structure is the same on most platforms: a community list to match, a route map to act, and a neighbor statement to apply it.
In this example AS 65000 tags the routes it sends to an upstream neighbor, and raises local preference on routes a customer has tagged.
bgp community-list standard CUSTOMER-PRIMARY permit 65000:100
!
route-map FROM-CUSTOMER permit 10
match community CUSTOMER-PRIMARY
set local-preference 200
route-map FROM-CUSTOMER permit 20
!
route-map TO-UPSTREAM permit 10
set community 65000:300 additive
!
router bgp 65000
neighbor 192.0.2.1 remote-as 64500
neighbor 192.0.2.1 route-map TO-UPSTREAM out
neighbor 198.51.100.2 remote-as 64600
neighbor 198.51.100.2 route-map FROM-CUSTOMER in
Three details in that configuration cause most of the trouble.
The additive keyword. FRRouting's documentation says that set community replaces whatever the route already carried unless additive is given, in which case the new value is appended. Leaving it out silently strips every BGP community a customer sent.
The empty permit at the end. A route map ends with an implicit deny. Without the second permit statement, every route that does not match the community list is dropped, not just left alone.
Whether the neighbor is sent communities at all. FRRouting gives send-community as enabled by default. Do not assume that default on other routers: if a neighbor never sees your tags, check that sending communities to that neighbor is configured before you debug the policy.
To verify, look at one prefix in the BGP table. On FRRouting, show bgp ipv4 unicast with the prefix prints the communities attached to each path, which shows at once whether the tag arrived, was replaced or was never sent.
PitfallsWhere people go wrong
Expecting a community to route by itself. A community changes nothing until a network has a policy that acts on it. Tagging a route with a community the receiving network ignores does nothing at all.
Assuming a private community is universal. Only the well-known communities mean the same everywhere. A provider's community works only on that provider, so the value has to come from that provider's published list.
Forgetting communities are transitive. Because a community travels with the route by default, one set upstream can keep affecting policy far downstream. A network that does not want to inherit tags has to strip them deliberately.
Confusing standard, extended and large communities. They are different attributes with different sizes and uses. A large community is not a bigger standard community that any router reads; both ends must support the format.
Mistyping the AS:value pair. The two halves matter: the wrong AS number or the wrong value invokes a different policy or none. A community that silently does nothing is often just the wrong number for that network.
ComparisonStandard, extended and large communities
| Criterion | Standard community | Extended community | Large community |
|---|---|---|---|
| Size | 32 bits, four octets | Eight octets | Twelve octets |
| Notation | AS:value | Type-based | AS:function:parameter |
| Fits a 32-bit ASN | No | Partly | Yes |
| Standard | RFC 1997 | RFC 4360 | RFC 8092 |
| Typical use | General policy tagging | Route targets, structured tags | Policy with 32-bit ASNs |
The standard community is the everyday tool; extended and large communities exist for structured tags and for the 32-bit AS numbers the original format cannot hold.
FAQFrequently asked questions
What is a BGP community?
A tag attached to a route that lets networks group prefixes and apply routing policy to the whole group at once. It is an optional, transitive BGP attribute, a 32-bit value usually written as AS:value, that travels with the route and signals what a network should do with it.
What does a BGP community do?
By itself, nothing: it is a marker. It takes effect when a network has a policy that matches the community and acts on it, such as setting local preference, prepending the AS path, or not exporting the route. The community is the signal; the policy is the action.
What is the format of a BGP community?
A 32-bit value, four octets, conventionally written as two 16-bit numbers separated by a colon, such as 65000:100. The first number is normally the AS that defined the community and the second is a value meaningful to that AS.
What is NO_EXPORT?
A well-known community, 0xFFFFFF01, that tells a network not to advertise the route to any peer outside the local AS or confederation. It keeps a route internal while still carrying it in BGP.
What is NO_ADVERTISE?
A well-known community, 0xFFFFFF02, that tells a network not to advertise the route to any peer at all, internal or external. The route stops at the router that receives it.
What are well-known communities?
Communities with a standard meaning defined in RFC 1997, such as NO_EXPORT, NO_ADVERTISE and NO_EXPORT_SUBCONFED. Any compliant router acts on them without a private agreement between networks.
Are BGP communities transitive?
Yes. The community is an optional transitive attribute, so it travels with the route from network to network by default. A network that does not want a route to keep its tags must strip them deliberately.
How do providers use BGP communities?
A provider publishes a list of communities a customer can set to control handling of their routes: set local preference, prepend the AS path toward certain regions, block export to a peer, or trigger blackholing during a DDoS. The customer tags the route and the provider applies the matching policy.
What is a blackhole community?
A community a provider defines so a customer can ask for traffic to a prefix to be dropped at the provider's edge, typically during a DDoS attack. Tagging the targeted prefix with the blackhole community triggers the drop the customer could not apply upstream themselves.
What is the difference between a standard and a large community?
A standard community is 32 bits and cannot hold a modern 32-bit AS number in its 16-bit first half. A large community, from RFC 8092, is twelve octets and is written as three numbers, so it can express tags for networks with 32-bit AS numbers.
What is an extended community?
An eight-octet BGP community that carries a type field, letting it encode structured information such as route targets in MPLS VPNs, beyond the plain value of a standard community.
Why is my BGP community being ignored?
Usually because the receiving network has no policy that acts on it, or the value is from the wrong AS or is mistyped. Apart from the well-known communities, a community means nothing unless the network reading it has agreed what to do with it.
What is a BGP community list?
A BGP community list is a named filter that matches routes by the community values attached to them. A route map then refers to the BGP community list to set local preference, prepend the AS path, or drop the route. It lets one policy act on many prefixes without listing them.
Keep readingRelated concepts
Read next · Routing What Is BGP? The routing protocol the community is an attribute of. Open this next12 min- Infrastructure · 11 min MPLS Explained Where extended communities carry route targets for VPNs.
- Routing · 10 min BGP States, and Why Only Three of the Six Ever Appear on Screen The neighbor states a BGP session goes through before routes flow.