Skip to content

Archive

Route Leaks

1 articles
Cybersecurity 23 Sep 2026 4 min read

BGP Roles and OTC Constrain Route Leak Propagation

A BGP route can carry a valid origin and still travel beyond the scope intended by the networks that exchanged it. That distinction matters because origin authorization and route-leak control address different properties. RFC 7908 defines a route leak as propagation of routing announcements beyond their intended scope, commonly in conflict with policies tied to customer, provider, or peer relationships. RFC 9234 adds protocol machinery for that relationship context. BGP Roles identify the relationship at an eBGP session, while the Only to Customer attribute, abbreviated OTC, marks routes whose subsequent propagation is constrained. The mechanism targets route propagation policy; it does not turn BGP into a cryptographically authenticated path protocol.