Home / Companies / Cloudflare / Blog / Post Details
Content Deep Dive

BGP Role model: tracking the adoption of RFC 9234

Blog post from Cloudflare

Post Details
Company
Date Published
Author
-
Word Count
3,887
Company Posts That Month
44
Language
English
Hacker News Points
-
Post removed?
No
Summary

Route leaks occur when BGP announcements travel beyond their intended customer-provider or peer-to-peer relationships, potentially causing traffic misdirection, congestion, latency, and outages. RFC 9234 addresses this problem by introducing BGP Roles, which let neighboring networks declare and validate their relationship, and the Only to Customer (OTC) attribute, which marks routes that should only continue toward customers and allows routers to reject leaked paths automatically. Cloudflare assessed adoption through public routing data and direct observations from its global peering network, identifying relatively limited deployment, with 67 peer ASes observed sending OTC attributes and route servers appearing among the earliest adopters. Its experiments also found that several networks stripped OTC attributes despite their required transitive handling, including Tier-1 providers GTT and Arelion; these providers said the practice originated as a defense against historical BGP error-handling risks, and Arelion subsequently began preserving OTC following Cloudflare’s outreach. Because a small number of high-tier networks can affect a large share of Internet paths, retaining OTC is important for effective route-leak prevention during partial deployment. Cloudflare recommends that operators configure BGP Roles where supported, coordinate deployments during maintenance windows because sessions must reset, and encourage vendors without RFC 9234 support to implement it.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.