← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Cloudflare Tracks Adoption of BGP Role Model (RFC 9234) for Route Leak Prevention

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • RFC 9234 introduces BGP Role and OTC attribute for route leak prevention.
  • Cloudflare tracked RFC 9234 adoption by monitoring OTC attribute propagation.
  • Two Tier-1 networks were found to be stripping the OTC attribute.
  • Stripping OTC hinders route leak prevention for early RFC 9234 adopters.

Understanding BGP Route Leaks

Route leaks in Border Gateway Protocol (BGP) cause internet traffic to be misdirected through unintended network paths. These leaks occur when the intended routing rules, based on customer-provider and peer-peer relationships between Autonomous Systems (ASes), are violated. Historically, preventing these leaks required each network to implement complex and error-prone routing policies manually.

RFC 9234: A New Approach to Route Leak Prevention

RFC 9234 (Route Leak Prevention and Detection Using Roles in UPDATE and OPEN Messages) simplifies route leak prevention by embedding routing intent directly into the protocol. It introduces a "BGP Role" capability, requiring BGP neighbors to agree on their relationship, and an "Only to Customer" (OTC) path attribute. The OTC attribute marks routes that should not propagate beyond customers, allowing routers that understand OTC to reject leaked routes without manual operator policies.

Tracking Adoption and Unexpected Findings

Cloudflare conducted an evaluation of RFC 9234's adoption by monitoring which peer ASes sent the OTC attribute to their network. During this analysis, it was discovered that two large Tier-1 networks were stripping the OTC attribute from routes they forwarded. This action prevents the OTC attribute from propagating through their networks, thereby undermining the route leak prevention capabilities for early adopters of RFC 9234.

Impact of OTC Stripping

The stripping of the OTC attribute by Tier-1 networks is significant because it limits the effectiveness of RFC 9234. For networks that have implemented the standard, the inability of the OTC attribute to propagate globally means that their efforts to prevent route leaks using this automated mechanism are hampered. Cloudflare is engaging with these Tier-1 networks to address the issue and enable proper OTC attribute propagation.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~32 min · 27 stories · Aug 18

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Cloudflare evaluated the adoption of RFC 9234, which introduces BGP Role and Only to Customer (OTC) attributes to prevent route leaks by expressing routing intent within the BGP protocol itself. The analysis revealed that two large Tier-1 networks are stripping the OTC attribute, hindering the effectiveness of this new standard for early adopters. This matters because RFC 9234 simplifies route leak prevention, which traditionally relies on complex, error-prone manual policies.