OFICIAL Cloudflare Blog

BGP Role model: tracking the adoption of RFC 9234

What happened
Based on Cloudflare Blog · Aug 18, 2026

Cloudflare evaluates RFC 9234, a BGP enhancement designed to prevent route leaks by embedding routing intent directly into the protocol, and identifies gaps in adoption among Tier-1 networks.

BGP Role model: tracking the adoption of RFC 9234
Cloudflare Blog — Cloudflare
Key points
·
Route leaks push traffic down paths it was never meant to take.
·
We have written and spoken publicly in the past about route leaks in Border Gateway Protocol (BGP), depicting these events as impactful incidents that cause misdirection of traffic through unintended network paths.
·
BGP routing is driven by the relationships between Autonomous Systems (ASes), i.e., customer-provider and peer-peer.
·
These relationships help define routing rules that form plausible paths.
Key numbers
·
The company has engaged with affected Tier-1 providers to restore OTC propagation, emphasizing the importance of consistent implementation for the protocol’s effectiveness.

Route leaks occur when Border Gateway Protocol (BGP) announcements propagate beyond their intended scope, often due to misconfigured routing policies that violate the valley-free hierarchy of Autonomous Systems (ASes). These incidents can disrupt traffic flows, increase latency, or cause outages by redirecting data through unintended paths. Historically, network operators have relied on manual, error-prone configurations to enforce routing rules, but RFC 9234 introduces a standardized approach by embedding routing intent within BGP itself.

RFC 9234 introduces two key mechanisms: a BGP Role capability, which requires neighboring ASes to explicitly declare their relationship during session establishment, and the "Only to Customer" (OTC) path attribute, which marks routes that must not propagate beyond customer networks. Routers supporting OTC can automatically reject leaked routes without operator intervention. Cloudflare assessed RFC 9234’s adoption by monitoring OTC attribute propagation from peer ASes, discovering that two major Tier-1 networks strip the OTC attribute, undermining its effectiveness for early adopters.

The BGP Role capability categorizes relationships as Provider, Customer, Peer, RS (Route Server), or RS-Client, with strict validation ensuring sessions only proceed if roles are compatible. Misconfigured roles trigger immediate session rejection, preventing latent misunderstandings that could later lead to route leaks. The OTC attribute, a transitive path attribute, records the AS where a route first moves sideways or downward, ensuring it cannot later be announced upward or sideways to providers or peers. Together, these features automate route leak prevention, reducing reliance on manual routing policies.

Cloudflare’s analysis highlights the practical challenges of deploying RFC 9234, particularly the need for widespread adoption among Tier-1 networks to preserve OTC attributes. The company has engaged with affected Tier-1 providers to restore OTC propagation, emphasizing the importance of consistent implementation for the protocol’s effectiveness. Operators are encouraged to configure BGP Roles and OTC attributes to enhance route leak resilience, though full deployment remains an ongoing effort.

Original source → Deals on Clipraptor.com →