Summary
- Route Flap Damping accumulates a decaying penalty from a prefix’s recent update history and can suppress the route when a local threshold is crossed.
- Suppression explains why one router stops using or advertising that route. It does not identify the fault, establish intent or show that other observers saw the same history.
- Reuse means the local penalty has decayed far enough for reconsideration. Recovery still requires a diagnosed cause, a repair, usable forwarding and traffic, and a stable observation window.
When quiet is created by the observer
Imagine an access circuit that alternates between up and down. Its customer prefix is withdrawn, re-advertised and withdrawn again. The NOC initially sees every transition. Then the update graph goes flat, the route vanishes from one edge, and the incident summary says that the network has stabilised.
The physical fault has not stopped. The edge has crossed its damping threshold and now suppresses the prefix. The calm graph is real, but it records the behaviour of the observer as much as the behaviour of the source.
RFC 2439 designed Route Flap Damping to contain instability and reduce the processing burden of repeated BGP changes. It assigns a figure of merit to recent instability, increases it when routes change, and lets the value decay with time. When the figure crosses a suppress boundary, an unstable route may be withheld until confidence in its stability improves.
That mechanism answers a precise question: given the events this implementation observed and the parameters it applies, should this route currently be accepted, used or announced? It does not answer why the events occurred. The cause could be a marginal link, a resetting router, an automation loop, an origin policy change, a maintenance action or deliberately induced false flapping.
The standard is candid about that limit. RFC 2439 says future stability cannot be predicted accurately; recent history is used as an estimate. A penalty is therefore not a fault code. It is a compressed, time-weighted account of transitions.
The same prefix can have several damping truths
Route Flap Damping is local. Two routers may receive different subsets or timings of updates. They may also use different penalty increments, suppress thresholds, reuse thresholds, half-lives and maximum suppression times. One can suppress while another continues to select or advertise the prefix.
RFC 7196 explains why this matters. Earlier settings could penalise well-connected sites severely because topological richness amplifies the number of update messages. The document says there was no consensus on a single default parameter set, and its measurements showed sharply different results as the suppress threshold changed.
Its recommendation is not to pretend that every transition is harmless. It is to make damping less destructive: a suppress threshold no lower than 6,000 for a still-aggressive posture, or no lower than 12,000 for a conservative one. RFC 7454 likewise recommends following the adjusted IETF and RIPE guidance rather than treating old defaults as timeless truth.
The implication for incident evidence is important. “The prefix was damped” is incomplete without the observer, policy, parameter set, raw event sequence and time. Even with those fields, it remains evidence of local suppression rather than a diagnosis of the remote system.
Reuse is not a repair receipt
A suppressed route does not remain suppressed forever. Its penalty decays. When it falls below the reuse threshold, the implementation may reconsider the route. That transition is useful operational evidence: a named local counter crossed a named configured boundary at a named time.
But no repair object is carried across that threshold. Reuse does not say that an interface was replaced, a power fault cleared, a policy loop stopped or an attacker lost access. Nor does it prove that the route became the selected path, entered the forwarding table or delivered packets successfully.
RFC 4271 keeps received routing information, local route selection and outgoing advertisements conceptually distinct. The packet path adds further stages. A prefix eligible for reuse may still lose selection to another path, fail installation, encounter stale next-hop resolution or carry traffic into a continuing fault.
This is why RFC 7196’s calculate-but-do-not-damp mode is more than a tuning convenience. It lets an operator compare the penalty model with the raw routing stream without removing reachability. It also exposes whether a supposed improvement is a real reduction in instability or merely a consequence of hiding the route.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

