Route Leak Prevention and Detection Using Roles in UPDATE and OPEN Messages
RFC 9234, “Route Leak Prevention and Detection Using Roles in UPDATE and OPEN Messages”, is a Proposed Standard document published in May 2022 by A. Azimov, E. Bogomazov, R. Bush, K. Patel, K. Sriram. The canonical text is published by the RFC Editor.
Abstract
Route leaks are the propagation of BGP prefixes that violate assumptions of BGP topology relationships, e.g., announcing a route learned from one transit provider to another transit provider or a lateral (i.e., non-transit) peer or announcing a route learned from one lateral peer to another lateral peer or a transit provider. These are usually the result of misconfigured or absent BGP route filtering or lack of coordination between autonomous systems (ASes). Existing approaches to leak prevention rely on marking routes by operator configuration, with no check that the configuration corresponds to that of the External BGP (eBGP) neighbor, or enforcement of the two eBGP speakers agreeing on the peering relationship. This document enhances the BGP OPEN message to establish an agreement of the peering relationship on each eBGP session between autonomous systems in order to enforce appropriate configuration on both sides. Propagated routes are then marked according to the agreed relationship, allowing both prevention and detection of route leaks.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9234 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9233 Internationalized Domain Names for Applications 2008 and Unicode 12.0.0
- RFC 9235 TCP Authentication Option Test Vectors
- RFC 9232 Network Telemetry Framework
- RFC 9236 Architectural Considerations of Information-Centric Networking Using a Name Resolution Service
- RFC 9231 Additional XML Security Uniform Resource Identifiers
- RFC 9237 An Authorization Information Format for Authentication and Authorization for Constrained Environments
- RFC 9230 Oblivious DNS over HTTPS
- RFC 9238 Loading Manufacturer Usage Description URLs from QR Codes