Internet Engineering Task Force (IETF) W. Kumari
Request for Comments: 6472 Google, Inc.
BCP: 172 K. Sriram
Category: Best Current Practice U.S. NIST
ISSN: 2070-1721 December 2011
Recommendation for Not Using AS_SET and AS_CONFED_SET in BGP
Kumari & Sriram Best Current Practice [Page 1]
RFC 6472 AS_SET, AS_CONFED_SET Use Deprecation December 2011
Table of Contents
1. Introduction
The AS_SET path segment type of the AS_PATH attribute (Sections 4.3 and 5.1.2 of [RFC4271]) is created by a router that is performing route aggregation and contains an unordered set of Autonomous Systems (ASes) that the update has traversed. The AS_CONFED_SET path type ([RFC5065]) of the AS_PATH attribute is created by a router that is performing route aggregation and contains an unordered set of Member AS Numbers in the local confederation that the update has traversed. It is very similar to AS_SETs but is used within a confederation.
Kumari & Sriram Best Current Practice [Page 2]
RFC 6472 AS_SET, AS_CONFED_SET Use Deprecation December 2011 2. Requirements NotationThe key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119].
3. Recommendation to Network Operators
It is RECOMMENDED that operators not generate any new announcements containing AS_SETs or AS_CONFED_SETs. If they have already announced routes with AS_SETs or AS_CONFED_SETs in them, then they SHOULD withdraw those routes and re-announce routes for the component prefixes (i.e., the additional specifics of the previously aggregated prefix) without AS_SETs in the updates. This involves undoing the aggregation that was previously performed (with AS_SETs), and announcing more specifics (without AS_SETs). Route aggregation that was previously performed by proxy aggregation (i.e., without the use of AS_SETs) is still possible under some conditions. As with any change, the operator should understand the full implications of the change.
Kumari & Sriram Best Current Practice [Page 3]
RFC 6472 AS_SET, AS_CONFED_SET Use Deprecation December 2011 4. Security ConsiderationsThis document discourages the use of aggregation techniques that create AS_SETs. Future work may update the protocol to remove support for the AS_SET path segment type of the AS_PATH attribute. This future work will remove complexity and code that are not exercised very often, thereby decreasing the attack surface. This future work will also simplify the design and implementation of the Resource Public Key Infrastructure (RPKI) and systems that will rely on it.
5. Acknowledgements
The authors would like to thank Tony Li, Randy Bush, John Scudder, Curtis Villamizar, Danny McPherson, Chris Morrow, Tom Petch, and Ilya Varlashkin, as well as Douglas Montgomery, Enke Chen, Florian Weimer, Jakob Heitz, John Leslie, Keyur Patel, Paul Jakma, Rob Austein, Russ Housley, Sandra Murphy, Steve Bellovin, Steve Kent, Steve Padgett, Alfred Hoenes, Alvaro Retana, everyone in the IDR working group, and everyone else who provided input.6. References 6.1. Normative References[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate
6.2. Informative References
[Analysis] Sriram, K. and D. Montgomery, "Measurement Data on AS_SET
Kumari & Sriram Best Current Practice [Page 4]
RFC 6472 AS_SET, AS_CONFED_SET Use Deprecation December 2011
[RFC4271] Rekhter, Y., Ed., Li, T., Ed., and S. Hares, Ed., "A