RFC 9234 Adoption Faces Hurdles as Tier-1 Networks Strip Key Route Leak Prevention Attribute
Cloudflare's analysis of RFC 9234 adoption reveals that two major Tier-1 networks are stripping the 'Only to Customer' (OTC) attribute, undermining its effectiveness in preventing critical BGP route leaks.

Route leaks, a persistent problem in Border Gateway Protocol (BGP) routing, cause traffic to be misdirected through unintended network paths, leading to increased latency and potential service disruptions. These leaks occur when routing announcements propagate beyond their intended scope, violating the established customer-provider and peer-to-peer relationships that govern Internet traffic flow. Historically, preventing such leaks has relied on complex, error-prone manual policies implemented by individual network operators.
RFC 9234, titled 'Route Leak Prevention and Detection Using Roles in UPDATE and OPEN Messages,' aims to standardize and simplify this process by embedding intent directly into the BGP protocol. It introduces two key features: the 'BGP Role' capability, which requires BGP neighbors to agree on their relationship at session establishment, and the 'Only to Customer' (OTC) path attribute. The OTC attribute specifically marks routes that should not be announced beyond a customer network, providing a protocol-level mechanism for route leak prevention.
Cloudflare, a major player in Internet infrastructure, has undertaken an analysis to track the adoption and effectiveness of RFC 9234. By monitoring the propagation of the OTC attribute from its peering partners, Cloudflare developed a unique method to assess how widely BGP Roles are being implemented. Their findings, however, highlight a significant obstacle to widespread adoption and effective route leak prevention.
The analysis revealed that two prominent Tier-1 networks, which form the backbone of the Internet, are actively stripping the OTC attribute from routes they forward. This action effectively negates the route leak prevention capabilities that RFC 9234 is designed to provide for networks that have adopted the standard. Cloudflare has reportedly engaged with these Tier-1 networks to encourage the propagation of the OTC attribute, emphasizing its importance for overall Internet stability.
BGP Roles define the relationship between two directly connected Autonomous Systems (ASes) on an eBGP session. These roles include Provider, Customer, Peer, Route Server (RS), and RS-Client. RFC 9234 specifies five valid pairings for these roles, ensuring that the declared relationships align with expected Internet routing hierarchies. When a BGP session is established, if both neighbors support the BGP Role capability and their declared roles do not match one of the five valid pairings, the session is rejected, providing an immediate alert to a potential misconfiguration or policy violation.
The 'Only to Customer' (OTC) attribute is crucial for enforcing the 'valley-free' routing principle. This principle dictates that routes learned from a provider or peer should only be announced to customers, not back up to other providers or peers. When an AS announces a route learned from a provider to another provider, it creates a 'valley' in the routing hierarchy, often resulting in inefficient traffic paths and potential congestion. The OTC attribute, when properly propagated, allows BGP routers to automatically reject such unauthorized announcements.
The stripping of the OTC attribute by major Tier-1 networks presents a significant challenge. While individual networks can implement BGP Roles and the OTC attribute, their effectiveness is diminished if the core transit providers do not honor and propagate these attributes. This situation places a greater burden back on network operators to implement their own, potentially complex, filtering mechanisms to mitigate route leaks, undermining the very purpose of RFC 9234's standardization efforts.
Cloudflare's ongoing engagement with these Tier-1 networks underscores the collaborative effort required to secure Internet routing. As adoption of RFC 9234 continues, addressing the behavior of these critical infrastructure providers will be paramount to realizing the full potential of BGP Roles and the OTC attribute in creating a more stable and predictable Internet.