hardMultiple Choice
300-410 Practice Question: An engineer is troubleshooting a BGP peering…
An engineer is troubleshooting a BGP peering problem between two routers, R1 (AS 65001) and R2 (AS 65002), connected via a firewall. The BGP session is flapping every few seconds. The engineer notices that the TCP connection is established, but BGP OPEN messages are not exchanged. The firewall logs show that TCP port 179 is allowed, but packets with the BGP marker (0xFFFFFFFF) are being dropped. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall is dropping BGP packets because the BGP marker (0xFFFFFFFF) is being flagged as a potential attack or malformed packet.
BGP uses a 16-byte marker (all 0xFF) in its messages. Some firewalls or intrusion prevention systems may misinterpret this as a malformed packet and drop it, preventing BGP from establishing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The firewall is dropping BGP packets because the BGP marker (0xFFFFFFFF) is being flagged as a potential attack or malformed packet.
Why this is correct
Some firewalls with BGP inspection or anomaly detection treat the all-ones 16-byte marker as suspicious, dropping the packet even though TCP/179 is permitted. Because the marker fails validation, the OPEN message never reaches the peer, so the session resets repeatedly.
- ✗
The BGP session is flapping because the keepalive timer is set too low on both routers.
Why it's wrong here
Keepalive timers govern session hold time after OPEN negotiation; here OPEN messages never complete because the firewall drops packets carrying the BGP marker, so timer tuning cannot restore the session. Lowering keepalives is tempting when sessions flap after establishment, but that addresses post-OPEN instability, not marker-based filtering.
- ✗
The BGP session is flapping because the routers have mismatched BGP AS numbers.
Why it's wrong here
Mismatched AS numbers would cause a NOTIFICATION after OPEN exchange, yet the stem shows OPEN messages never leaving the router because the firewall drops the 0xFFFFFFFF marker. AS mismatch is tempting since it commonly breaks eBGP peering, but it manifests as an OPEN error, not silent marker drops.
- ✗
The BGP session is flapping because the firewall is performing TCP sequence number randomization, breaking the BGP session.
Why it's wrong here
TCP sequence randomisation would corrupt the established TCP session itself, but the stem confirms TCP is established and only marker-bearing BGP packets are dropped. Randomisation is tempting because firewalls often break BGP this way, yet here the firewall log explicitly identifies marker 0xFFFFFFFF as the dropped element.
Visual reference
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.