BGP Role model: tracking the adoption of RFC 9234¶
Summary¶
Cloudflare evaluates how widely RFC 9234
(Route Leak Prevention using Roles in UPDATE and OPEN messages) has been adopted on
the Internet, using its global peering footprint. RFC 9234 moves route-leak prevention
into the protocol itself: a negotiated BGP Role capability makes two neighbors
agree on their relationship at session setup, and an Only-to-Customer (OTC) path
attribute marks a route so it can only propagate downward to customers — a router that
understands OTC can reject a leaked route with no operator-written policy. By monitoring
which peer ASes send OTC equal to their own ASN across three months of BMP feeds,
Cloudflare identifies 67 ASes setting OTC. It then runs a controlled anycast
experiment (announce a prefix with OTC=13335, then withdraw to trigger path hunting)
and discovers that two large Tier-1 networks — AS3257 (GTT) and AS1299 (Arelion) —
strip the OTC attribute, defeating leak prevention for ASes several hops away.
Together these two appear in 96.6% of IPv4 and 92.9% of IPv6 OTC-absent paths.
After Cloudflare's outreach, Arelion began preserving OTC; GTT still strips it.
Key takeaways¶
-
RFC 9234 expresses routing intent in-band. Historically each network enforced valley-free export policy by hand with error-prone prefix filters and IRR-derived policies; RFC 9234 makes a router reject a leaked route on its own once Roles are configured. (Source: article intro)
-
A BGP Role is declared per eBGP session and has five values — Provider, Customer, Peer, RS, RS-Client. Only five pairings are valid (Provider↔Customer, RS↔RS-Client, Peer↔Peer); any other pairing rejects the session with a Role Mismatch notification (code 2, subcode 11) — surfacing a latent relationship disagreement at the handshake instead of later as an incident. (Source: "BGP Roles" section)
-
Partial deployment is the default; strict mode is opt-in. If you send the Role capability and the neighbor does not, the session still comes up and your locally configured Role still drives partial leak prevention. "Strict mode" rejects sessions where the neighbor sends no Role capability — but the adoption numbers show it is not yet realistic for most networks. (Source: "BGP Roles")
-
Roles select the ASPA algorithm too. A route from a provider may contain a full up/side/down motion; a route from a non-provider must only ramp downward. The BGP Role tells the router which ASPA validation variant to run, so Roles and ASPA should be configured together. (Source: "BGP Roles")
-
The OTC attribute is an optional transitive path attribute (type code 35) carrying one ASN — the AS that first sent the route sideways or downward, i.e. the peak of the path. Once set it MUST be preserved unchanged, and because it is optional transitive, even a router with no RFC 9234 support is expected to pass it along. (Source: "OTC attribute")
-
Setting/checking rules are dual-sided. Set OTC on egress to a customer/peer/RS-client (carrying your ASN) or on ingress from a provider/peer/RS (carrying their ASN) when absent. Once OTC is present, never announce it to a provider/peer/RS; an OTC route from a customer/RS-client is a leak (reject); from a peer with any value ≠ that peer's ASN is a leak. OTC has two chances to stop a hairpin leak — at the compliant leaker's egress, and at the receiving provider's ingress — either alone suffices. (Source: "Setting/Checking OTC")
-
Detecting adopters is genuinely hard because dual-sided stamping obfuscates who set OTC: on path
64506 64507withOTC=64507you can't tell if 64507 set it on egress or 64506 filled it in on ingress. Naive counting of distinct OTC values over public RIB dumps (RouteViews + RIPE RIS) yields 361 candidate setters — heavily inflated. (Source: "Using public BGP data") -
Cloudflare's BMP method is clean. Because Cloudflare peers directly with thousands of ASes, it monitors OTC received from direct peers and checks
OTC == peer ASN, with no intermediate ambiguity. Over three months it found 67 ASes setting OTC. Route Servers adopt fastest (YYCIX was first to deploy), partly because they run open-source BGP stacks — and RSes protect a large slice of the Internet since they sit in the propagation path of many routes. Individually-owned ASes also feature highly (open-source inclination). (Source: "Using Cloudflare's global peering") -
Two Tier-1s strip OTC. A controlled experiment (announce IPv4+IPv6 prefixes with
OTC=13335from all peering locations via anycast, then withdraw to trigger path hunting, parsing MRT + BMP Updates with BGPKIT) found AS3257 (GTT) and AS1299 (Arelion) stripping OTC — plus a seed-and-propagate algorithm surfacing 9 more droppers. 33.1% of IPv4 and 17% of IPv6 distinct AS_PATHs had OTC stripped; the two Tier-1s account for 96.6% (IPv4) and 92.9% (IPv6) of OTC-absent paths (Arelion the vast majority). (Source: "Where was OTC being stripped?") -
Stripping is a defensive habit, not malice — and it undermines RFC 9234. Both operators confirmed they strip unrecognized transitive attributes as defensive practice after past BGP error-handling incidents (a malformed transitive attribute could once trigger far-away session resets; RFC 7606 fixed the root risk by treating malformed attributes as withdraw rather than resetting the session). After outreach, Arelion rolled out OTC preservation (verified via
monocle); GTT still strips. (Source: "Experiment to find ASes stripping OTC" + operator confirmation) -
Vendor support gates rollout (August 2026): Junos/Junos Evolved, RouterOS, BIRD, OpenBGPD, and FRR support RFC 9234; Cisco IOS XR ships it in 26.4.1; Arista EOS, Nokia SR OS, Huawei, Extreme SLX-OS, ArcOS, GoBGP, ExaBGP do not. Roles require a session reset to apply, so rollout happens in maintenance windows. Cloudflare has begun gradual fleet-wide deployment. (Source: "Configure BGP Roles in your network")
Systems / concepts extracted¶
- concepts/bgp — new concept page; five roles, five valid pairings, Role Mismatch notification, strict vs partial mode, complex-relationship prohibition, ASPA-algorithm selection
- only-to-customer — heavily extended; type-35 optional transitive attribute, dual-sided set/check rules, RS/RS-client handling, the OTC-stripping finding
- optional-transitive-attribute — new concept page; RFC 4271 §5 handling, Partial bit, why stripping is a spec violation, RFC 7606 relationship
- route-server — RS acts as provider to all clients, re-announcing prefixes between IX members; fastest RFC 9234 adopters
- concepts/bgp — BMP feeds from Cloudflare routers, the measurement substrate
- concepts/bgp — withdrawal-triggered exploration that reveals extra paths for stripping analysis
- concepts/bgp / concepts/valley-free-routing — the anomaly class RFC 9234 targets
- systems/aspa — configured together with Roles; Role selects the ASPA algorithm variant
- systems/bgpkit-monocle — MRT/Update parsing + verification query (
monocle search) - systems/ripe-ris / systems/routeviews — public BGP collectors used for the naive-count baseline and MRT dumps
Operational numbers¶
| Metric | Value |
|---|---|
| ASes setting OTC (BMP, direct peers, 3 months) | 67 |
| Naive distinct-OTC-value count (public RIB) | 361 (inflated) |
| First-AS = OTC-value setters (public data) | 9 |
| Potential RFC 9234-compliant ASes (public method) | 36 |
ASes dropping OTC found (first pass, ASX AS13335) |
6 (incl. 2 Tier-1s) |
| Additional droppers via seed-and-propagate | 9 |
| Distinct IPv4 AS_PATHs with OTC stripped | 33.1% |
| Distinct IPv6 AS_PATHs with OTC stripped | 17% |
| OTC-absent paths incl. AS1299/AS3257 (IPv4) | 96.6% |
| OTC-absent paths incl. AS1299/AS3257 (IPv6) | 92.9% |
| Arelion (AS1299) OTC-absent share when next hop of AS13335 (IPv4) | 71.4% |
| Arelion (AS1299) OTC-absent share when next hop of AS13335 (IPv6) | 40.7% |
| GTT (AS3257) | consistently strips |
| OTC attribute type code | 35 |
| Role Mismatch notification | code 2, subcode 11 |
Caveats¶
- BGP topology is only partially observable: public collectors + BMP see a fraction of all AS paths, so both the adopter count and the stripping rate are lower bounds / estimates.
- Dual-sided OTC stamping means public-data methods cannot attribute who set OTC; the 67-ASes
figure relies on direct-peer BMP where
OTC == peer ASNis unambiguous, but misses adopters Cloudflare doesn't peer with. - The seed-and-propagate stripping-attribution algorithm relies on transitivity: it only attributes a path when exactly one non-trusted AS remains, so it can miss droppers on always-mixed paths.
- Arelion's fix is verified only for Cloudflare's experiment prefixes via
monocleat a point in time; consistency across their whole network over time is not proven in the post.
Source¶
- Original: https://blog.cloudflare.com/rfc9234-bgp-role-model/
- Raw markdown:
raw/cloudflare/2026-08-18-bgp-role-model-tracking-the-adoption-of-rfc-9234-28a6cdd9.md
Related¶
- sources/2026-07-24-cloudflare-bgp-origin-attribute-manipulation — sibling BGP-measurement post; same anycast-announce + path-hunting + BGPKIT/BMP methodology, applied to ORIGIN rewriting instead of OTC stripping. Both find Tier-1s bending a "SHOULD/MUST preserve" attribute rule.
- sources/2026-06-03-cloudflare-enforcing-the-first-as-in-bgp-as-paths — sibling routing-security measurement; First-AS enforcement failures across Tier-1s.
- sources/2026-01-08-cloudflare-a-closer-look-at-a-bgp-anomaly-in-venezuela — the route-leak forensic post that first introduced OTC + ASPA to the wiki as the two-part answer.
- concepts/bgp — parent concept
- only-to-customer — central concept, extended by this ingest
- concepts/bgp — new concept created by this ingest
- systems/aspa — complementary path-validation mechanism