BGP Role model: tracking the adoption of RFC 9234

Curated from Cloudflare Blog

If you manage BGP peering, RFC 9234 is no longer just theoretical. This analysis provides hard data on the actual deployment landscape, highlighting a critical gap between standard adoption and operational reality. The discovery that two Tier 1 networks are stripping the Only to Customer attribute is a significant red flag for anyone relying on automated route leak mitigation. It exposes a dangerous inconsistency in how upstream providers interpret and implement these controls, potentially undermining the security benefits for downstream customers. For working engineers, this serves as a wake-up call to verify how your specific upstreams handle these attributes rather than assuming standard compliance. The concrete takeaway is to immediately audit your peer configurations and test route propagation behavior against RFC 9234 expectations, ensuring you are not silently exposed to route leaks due to upstream misconfiguration.

RFC 9234 lets routers reject route leaks on their own, using BGP Roles and the Only to Customer attribute. We measured who has deployed it, and found two Tier 1 networks unexpectedly stripping OTC.

— Cloudflare Blog

Read the full article on Cloudflare Blog →