Juniper Networks headquarters in Sunnyvale, California
– Getty Images

Juniper Networks’ latest Junos OS includes support for RFC 9234, a standard designed to prevent and detect BGP route leaks.

The standard, developed by the Internet Engineering Task Force (IETF), is designed to address route leaks, which occur when routing misconfigurations, often by network operators or internet service providers (ISPs), causing prefixes to be announced beyond their intended recipients.

BGP leaks are a common occurrence in the internet routing space. Figures from Noction suggest that between March and October 2023, some 207 BGP leaks occurred. While that may seem small, each incident represents traffic being misdirected.

RFC 9234 makes route leak prevention stronger by replacing error-prone manual filters with automatic, role-aware enforcement. During BGP session setup, routers declare their relationship (provider, customer, peer, etc.), and the protocol uses the only-to-customer (OTC) attribute to ensure certain routes never propagate beyond their intended boundaries.

For those less technically minded, it's akin to adding address labels to internet traffic so routers automatically know who they can and can’t forward it to, cutting out the guesswork that can lead to costly mistakes.

Some three years after the standard was published, Juniper has rolled it into its latest OS update to plug the security gap. The networking giant said the feature helps operators “maintain intended routing policies and prevent network delays and denial-of-service (DoS) attacks.”

From the release notes: “The [RFC 9234] feature ensures that routes from providers or peers are only propagated to customers, reducing misconfigurations and errors.

“The BGP speaker automatically sets the OTC based on its configured role, and then advertises a prefix based on the OTC presence in the BGP update message, making the configuration straightforward and minimizing manual intervention.”

Alexander Azimov, head of network R&D at Yandex and one of the architects of RFC 9234, welcomed the move: “Innovation takes time, innovation in routing security takes a lot of time, but it's a huge step forward.”

In the three years since the IETF’s standard was published, Juniper was acquired by Hewlett Packard Enterprise (HPE) in a deal worth $14 billion after receiving a rubber stamp from the Department of Justice (DOJ) in late June.

The deal remains under scrutiny, however, with several leading Democrats urging a Tunney Act review, arguing that the required judicial review, notice, and comment period for the DOJ settlement did not occur.