Revised Validation Procedure for BGP Flow Specifications
RFC 9117, “Revised Validation Procedure for BGP Flow Specifications”, is a Proposed Standard document published in August 2021 by J. Uttaro, J. Alcaide, C. Filsfils, D. Smith, P. Mohapatra. It updates RFC 8955. The canonical text is published by the RFC Editor.
Abstract
This document describes a modification to the validation procedure defined for the dissemination of BGP Flow Specifications. The dissemination of BGP Flow Specifications as specified in RFC 8955 requires that the originator of the Flow Specification match the originator of the best-match unicast route for the destination prefix embedded in the Flow Specification. For an Internal Border Gateway Protocol (iBGP) received route, the originator is typically a border router within the same autonomous system (AS). The objective is to allow only BGP speakers within the data forwarding path to originate BGP Flow Specifications. Sometimes it is desirable to originate the BGP Flow Specification from any place within the autonomous system itself, for example, from a centralized BGP route controller. However, the validation procedure described in RFC 8955 will fail in this scenario. The modification proposed herein relaxes the validation rule to enable Flow Specifications to be originated within the same autonomous system as the BGP speaker performing the validation. Additionally, this document revises the AS_PATH validation rules so Flow Specifications received from an External Border Gateway Protocol (eBGP) peer can be validated when such a peer is a BGP route server.
This document updates the validation procedure in RFC 8955.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9117 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9118 Enhanced JSON Web Token Claim Constraints for Secure Telephone Identity Revisited Certificates
- RFC 9115 An Automatic Certificate Management Environment Profile for Generating Delegated Certificates
- RFC 9119 Multicast Considerations over IEEE 802 Wireless Media
- RFC 9120 Nameservers for the Address and Routing Parameter Area Domain
- RFC 9109 Network Time Protocol Version 4: Port Randomization
- RFC 9125 Gateway Auto-Discovery and Route Advertisement for Site Interconnection Using Segment Routing
- RFC 9108 YANG Types for DNS Classes and Resource Record Types
- RFC 9126 OAuth 2.0 Pushed Authorization Requests