Summary
- Level 3 stopped exchanging traffic directly with Cogent on 5 October 2005. The public record shows that some customers lost reachability to destinations across the split, while the complete customer and prefix impact remains unknown. [1][21][22]
- Cogent publicly asked Level 3 to restore the connection before further negotiation. Level 3's preserved public position said the trial arrangement no longer met its conditions. These are attributed commercial positions, not findings that either carrier breached a contract or acted unlawfully. [1][22]
- A registered prefix and a customer contract did not create a working path. Reachability depended on routes that AS174 and AS3356 exchanged, accepted and selected, together with whatever alternate transit or multihoming customers actually had.
- Merit used selected RouteViews observations to study reachability to Cogent's 38.0.0.0/8. RouteViews and RIPE RIS can preserve announcements and withdrawals from participating collectors, but they cannot reveal every private policy, local preference, customer path or commercial term. [8]-[10]
- Multihoming reduced risk only where alternate providers, accepted advertisements, capacity and application dependencies were genuinely independent. A second contract without an effective alternate route was not continuity.
- On 28 October the carriers announced a modified settlement-free agreement with traffic obligations, conditional payments and a process intended to protect customers if the relationship later expired or violations were not cured. The public release describes a control design, not proof that all future interconnection risk disappeared. [2]
- Later BGP, MANRS and NIST guidance helps define measurable controls such as explicit policy, route monitoring, max-prefix limits, coordination and incident evidence. It is comparison material, not retroactive law for the 2005 event. [13]-[20]
- The accountability standard is operational: map dependent customers, prove alternate reachability before termination, observe route and transaction impact during the change, preserve a bounded cure process and verify restoration from outside both carrier networks.
Internet reachability is often sold as though it were a stable property. A customer receives an address, connects to an upstream carrier and sees routes to destinations around the world. From that perspective, “the Internet” appears to be one continuous service. In the control plane, however, reachability is not an institutional promise. It is the current result of independent networks advertising prefixes, accepting or rejecting those advertisements, selecting paths and forwarding traffic under their own policies.
The October 2005 dispute between Cogent Communications, operating AS174, and Level 3 Communications, operating AS3356, exposed that difference. On 5 October, Level 3 stopped exchanging traffic directly with Cogent. Contemporary statements and reporting described customers on the two networks losing access to some destinations across the resulting divide. The companies remained connected to other parts of the Internet, and the event did not partition the entire global network.
But where no acceptable alternate route joined a Cogent-reachable destination to a Level 3-reachable source, registration records and customer expectations could not make packets cross the missing interconnection.
This was deliberate depeering, not a route leak, route hijack or accidental BGP announcement. The operational failure came from the removal of a path that had previously carried traffic between two large networks. That distinction determines what evidence matters. Investigators must examine the interconnection decision, BGP route changes, alternate paths, customer dependency, multihoming, communication and restoration. A generic account of a commercial disagreement misses the mechanism that made the disagreement consequential.
The episode also tests a particular kind of accountability. Peering and transit are different commercial arrangements, and the public record describes the restored relationship as settlement-free peering rather than paid transit. Yet both companies sold connectivity within an ecosystem whose value depended on interdomain reachability. The accountability question is therefore not whether two autonomous networks must peer for free. It is whether carriers that control a consequential interconnection can identify customer dependency, manage termination without obscuring the operational consequences, preserve evidence and prove restoration.
Reachability Exists in the Running Path
An IP address allocation can identify the holder of a block. An autonomous-system number can identify a routing domain. A contract can state what a customer bought, and an interconnection agreement can describe what two carriers expect from each other. None of those records, by itself, installs a route in a router’s forwarding table.
For a packet to travel from a customer behind AS174 to a destination behind AS3356, the relevant networks needed a sequence of accepted routes in both directions. That sequence might use the direct Cogent-Level 3 interconnection. It might instead pass through another carrier if export policies, commercial relationships, capacity and route selection permitted that path. If no network advertised an acceptable alternative, the destination could remain validly registered and correctly originated while still being unreachable from the other side.
This makes “full-Internet reachability” an operational shorthand rather than an absolute guarantee that every host will always answer. Firewalls, application failures and local policies can make a particular service unavailable even when a network route exists. The relevant question in the 2005 dispute is narrower: did ordinary interdomain routing provide usable paths between prefixes whose practical connection had depended on the AS174-AS3356 relationship?
A carrier’s market label cannot answer that question. Describing a network as a major backbone or a Tier 1 operator may indicate scale or commercial position, but it does not create a globally enforced routing obligation. Each autonomous system retains control over the routes it exports, the routes it accepts and the paths it prefers. The Internet has no central router that can order two networks to exchange traffic after they end a bilateral relationship.
That independence is one of the Internet’s strengths. It allows networks to make distinct security, engineering and commercial decisions without asking a central authority for permission. The same independence creates a continuity problem: a bilateral decision can have effects beyond the two parties when customers have no usable path around it. Accountability must therefore follow practical control rather than labels.
The operator controlling a session controls whether that session remains available; an operator selling connectivity controls what resilience it supplies or recommends; a customer controls its own redundancy only within technical and financial limits.
The 2005 event brought these layers together. The companies had a commercial disagreement, but its customer-facing effect was expressed through BGP. The decisive facts were not simply what the parties believed the agreement required. They were which routes ceased to be exchanged, which alternative routes remained acceptable, which customers depended on the removed path and how the direct relationship was restored.
A Bounded Chronology of the October Dispute
The defensible chronology begins on 5 October 2005, when Level 3 stopped direct traffic exchange with Cogent. Public material describes the action as termination of the companies’ direct peering relationship. The available evidence does not establish the complete physical layout of that interconnection, the number of sessions or ports involved, or the capacity at each location. “The connection” should therefore not be read as proof that one cable or one router represented the entire relationship.
Contemporary reporting quickly framed the consequence as a reachability problem. Some users and businesses connected through one network reportedly could not reach destinations dependent on the other. Those accounts support the conclusion that the depeering had real customer effects. They do not establish a complete list of affected prefixes, a universal outage across either carrier, equal impact on both sides or a precise percentage of the Internet that became unreachable.
On 7 October, Cogent publicly called for Level 3 to restore the interconnection before the companies continued negotiations. That statement is evidence of Cogent’s position and proposed sequence: restore customer connectivity first, then address the dispute. It does not independently establish the confidential obligations of either party, nor does it decide whether the earlier arrangement satisfied its terms.
Level 3 offered a different public explanation. Its statement, preserved in contemporary coverage, described the discontinued relationship as a trial peering arrangement that no longer met the applicable conditions. That is evidence of Level 3’s stated reason. The public record does not supply the complete agreement, the measurements used to evaluate it, the precise traffic characteristics at issue, or the internal deliberations that led to termination. It cannot support a finding that Cogent breached a particular unpublished term or that Level 3’s assessment was incorrect.
Operator discussion archived by NANOG documented contemporary questions about paths and reachability. Such messages are valuable because they show what network engineers were observing and testing while the event unfolded. They are not a controlled census of the Internet. Entities had different vantage points, commercial relationships and access to routing information. A report from one network could accurately describe that network’s path without establishing what every other network saw.
On 28 October, Cogent and Level 3 jointly announced that they had reached a modified settlement-free peering agreement. Their release described obligations concerning traffic characteristics and volume, payments if those obligations were not satisfied, and a process intended to reduce harm to customers if the relationship later expired or a violation remained uncured. The announcement is the strongest shared public evidence for the structure of the remediation because both companies issued it together.
The release still was not the complete contract. It did not publicly disclose all thresholds, measurement methods, cure periods, operational procedures or decision rights. Nor does its existence prove that every customer path was restored at the same moment or that all later interconnection risks disappeared. It shows that the companies restored their relationship under revised terms and publicly identified customer-protection procedures as part of the solution.
Later FCC records discussed the event in broader analyses of Internet interconnection, backbone competition and customer reachability. Those records help explain why a dispute between large networks could affect parties that were not signatories to the peering arrangement. They should not be converted into a legal judgment about the 2005 conduct. The cited materials do not establish that either carrier violated a law, regulation or contract.
What Changed in BGP
BGP allows autonomous systems to exchange reachability information. A route advertisement identifies a reachable prefix and carries attributes that help receiving networks apply policy and select paths. The AS path records autonomous systems through which the advertisement has propagated, while other attributes and locally configured preferences influence which route a network installs.
The decision process is decentralized. Cogent could advertise customer and internal prefixes to Level 3 under its export policy. Level 3 could accept, filter or prefer those advertisements under its import policy, then expose selected routes to appropriate customers or peers. The reverse process applied to Level 3 routes reaching Cogent. Neither company controlled every intervening network, and neither could compel a third party to export an alternate path.
When a direct external BGP relationship is terminated, routes learned exclusively through that relationship cease to be usable after withdrawals, session loss or policy removal. Routers then reconsider other available paths. If a different carrier advertises an acceptable route, traffic may move to that route. If alternatives are absent, filtered or commercially unavailable, the affected router has no usable path for the destination.
This is why the same depeering can produce different outcomes for different customers. One network may have another upstream carrying a path between the two sides. Another may learn only the routes that disappeared with the direct session. A third may see an alternate path but reject it because of policy, prefix-length rules or relationship constraints. A fourth may select an alternate route whose capacity or return path does not support reliable application traffic.
The loss of the direct path also need not produce symmetric symptoms. BGP decisions are made separately by each network, and data traffic requires workable forward and return paths. A packet may reach a destination while its response follows no usable route back. Different local preferences can send the two directions through different autonomous systems. Consequently, a successful route observation in one direction does not prove complete bidirectional service.
The public record does not expose Cogent’s and Level 3’s complete local-preference configurations. It does not reveal every route filter, community treatment, private peer or third-party transit arrangement. Public AS paths can suggest how traffic might have moved, but they cannot disclose all the internal policies that determined route selection.
BGP communities add another potential layer of evidence. RFC 1997, which predates the event, defines a way to attach policy-relevant tags to routes. Networks can use communities to request or signal propagation behavior. The meaning and implementation of many communities are network-specific, however. Even when a community appears in a public update, it does not automatically disclose the private agreement governing the route or prove that every router applied the intended policy.
The event therefore cannot be reduced to “the routes vanished everywhere.” AS174 and AS3356 continued operating, and prefixes associated with them could remain visible from many locations. The narrower issue was whether paths crossing the former relationship remained available through other networks. A prefix visible at one collector might be unreachable from a particular customer. Conversely, a route missing at one collector might remain reachable elsewhere through a private or differently selected path.
Nor can route validity guarantee connectivity. A correctly originated prefix can be unreachable because no acceptable route reaches a given network. Modern origin-validation mechanisms can help determine whether an origin is authorized, but they cannot force two autonomous systems to maintain a peering session or require a third network to carry traffic between them. The 2005 failure was about path availability and policy, not simply address ownership or origin authenticity.
Why Some Networks Could Route Around the Split
Multihoming is the most obvious resilience mechanism in a depeering event. A customer connected to more than one upstream may advertise its prefix through multiple networks and learn destinations through more than one path. If one upstream loses reachability to part of the Internet, the other may preserve a usable route.
That description is technically sound but incomplete as an accountability answer. Multihoming requires more than signing a second access contract. The customer may need address space that both upstreams will accept, an autonomous-system number, compatible routing equipment, staff able to operate BGP, route filters, monitoring, security controls and sufficient capacity on the alternate connection. The return path must also converge on a working route. Applications with stateful firewalls, address dependencies or sensitivity to path changes may need additional engineering.
Commercial policy matters as well. An alternate carrier must be willing and able to export the relevant routes. A customer cannot assume that any two connections create a path across every dispute between upstream networks. Prefix-length filters can prevent more-specific announcements from propagating. An alternate circuit sized for emergency management traffic may not carry ordinary production load. A nominally diverse connection may share physical facilities or a common upstream dependency.
For those reasons, the existence of multihoming does not prove that every multihomed customer retained service. It establishes a possible control whose effectiveness must be tested. Similarly, the absence of multihoming does not by itself establish imprudence. Small customers may lack the budget, expertise, address resources or bargaining power to operate independently routed connections. A service sold as ordinary Internet access may reasonably be consumed without the customer building a miniature backbone.
Single-homed customers faced a sharper dependency. If their only upstream lacked an acceptable route to destinations on the other side, they could not recreate a backbone interconnection after the depeering. They could seek emergency service from another carrier, but provisioning, routing acceptance, equipment and contracts take time. The party controlling the removed interconnection could change route availability far faster than many dependent customers could replace it.
Third-party carriers were another part of the path. An alternate network might have relationships with both Cogent and Level 3, yet its export policy might not permit it to act as an intermediary between them. Interdomain routing commonly reflects commercial roles: a carrier may announce customer routes broadly while declining to provide free transit between peers. Public BGP paths can support inferences about these relationships, but CAIDA’s documentation emphasizes that the underlying commercial arrangements are generally confidential and must often be inferred.
This matters because a topological drawing can overstate resilience. Two networks can both connect to a third autonomous system without gaining a usable path through it. The relevant question is not whether a line exists on a map. It is whether routes are exported, accepted and selected under real policy, with enough forwarding capacity to carry the resulting traffic.
A defensible continuity assessment would therefore classify customers by observed dependency rather than by a simple multihomed-or-single-homed label. It would ask which prefixes had verified alternate paths, which services had bidirectional reachability, whether capacity remained adequate, and how long each customer cohort experienced impairment. The frozen public evidence does not provide that complete matrix for October 2005, so claims about the distribution of impact must remain limited.
Reconstructing the Event From Public Route Evidence
Public route collectors provide an important but partial window into the incident. RouteViews archived BGP updates from October 2005, allowing investigators to inspect announcements and withdrawals received from participating peers. RIPE RIS explains the comparable role of distributed collectors: they record routing information visible from networks that choose to peer with them.
Merit’s BGP inspection case study treats the Cogent-Level 3 event as a route-analysis exercise and examines reachability involving Cogent’s 38.0.0.0/8 from selected RouteViews peers. That is a useful bounded inquiry. It does not transform one aggregate and a set of selected vantage points into a complete inventory of Cogent customers, Level 3 customers or globally affected routes.
A rigorous reconstruction starts by separating event anchors from route observations. The company statements establish that the direct relationship was deliberately terminated and later restored. Collector data can then show how particular routes appeared to participating peers before, during and after those changes. Contemporary operator messages, traceroutes and customer reports can test whether the observed control-plane changes corresponded to forwarding or application failures.
The timestamp alignment matters. BGP update streams contain ordinary routing churn as well as incident-related changes. Sessions reset for many reasons; prefixes can be withdrawn and reannounced independently of a peering dispute. An investigator should not label every update near 5 October as caused by the depeering. The stronger inference comes from repeated changes involving relevant paths, consistent timing across independent vantage points and corroboration from operational observations.
Collector diversity matters equally. A RouteViews peer supplies the routes it selected and chose to export to the collector. It does not expose every route that peer considered, every route rejected by policy or every forwarding-table entry inside the network. A RIS collector has the same basic constraint. Adding collectors increases visibility, but no finite set produces a god’s-eye view of every private interconnection and every router.
AS-path evidence also requires restraint. The visible path identifies the autonomous systems listed in the selected advertisement. It does not reveal internal router hops, port utilization, contractual prices or all traffic actually forwarded along that path. Local preference usually does not propagate between autonomous systems, so an external observer may not know why one path won. Private peering can remain absent from public collector data.
A withdrawal is similarly ambiguous without context. It can mean that a route is no longer available to the announcing peer, that export policy changed, or that a session failed. It does not by itself identify the business decision behind the change. In this case, the companies’ statements supply the intent that raw updates cannot: the interconnection ended deliberately.
Traceroutes add forwarding clues but not omniscience. Routers may suppress responses, use addresses unrelated to the apparent path or forward traffic asymmetrically. A traceroute that stops does not always identify the exact point of failure. A successful traceroute from one location does not establish reachability from all locations. Still, repeated traces from independent networks can help distinguish a local application problem from a broader absence of interdomain paths.
Customer reports supply another layer. A business unable to reach a site across the divide provides evidence of practical harm. Yet the report alone may not identify which upstream, route policy or return path caused the failure. The most defensible account aligns the complaint with source and destination prefixes, timestamps, BGP observations and, where available, forward and reverse path tests.
The resulting evidence should be stated in confidence levels. A direct company announcement can establish that the relationship was terminated or restored. A collector can establish that a participating peer advertised a particular path at a particular time. Multiple independent route and forwarding observations can support a broader inference. None of these alone supplies the full customer list, private contract or precise worldwide impact.
FCC materials add market context rather than packet-level proof. Their discussion of backbone interconnection and network effects helps explain why customers value access to destinations outside their own carrier. Later regulatory references to the Cogent-Level 3 dispute show its relevance to interconnection policy. They do not replace route evidence, and they do not decide legal responsibility for individual customer losses.
Why This Was Not a Route Leak or Hijack
A route leak generally involves propagation of routing information beyond the scope intended by the relevant relationships. The resulting problem is often the presence or selection of an unintended path. A hijack generally involves an unauthorized origin or other false routing claim that diverts or intercepts traffic. Both can create reachability and security failures, but their mechanisms differ from deliberate depeering.
The Cogent-Level 3 event concerned the removal of direct route exchange. The public statements describe an intentional interconnection decision. The central failure was that some paths were no longer available, not that one carrier falsely originated the other’s prefixes or accidentally announced itself as transit for routes it should not have propagated.
That difference changes the appropriate controls. Prefix filtering and origin validation can reduce acceptance of unauthorized announcements. Relationship-aware export policy can reduce route leaks. Those mechanisms do not compel an operator to continue a valid peering relationship. A perfectly filtered router can still have no route to a destination after a deliberate session termination.
Raw BGP data cannot always reveal the distinction on its own. A collector may see withdrawals, replacement paths or loss of visibility. The intent becomes clear only when those observations are combined with the companies’ public explanations. Calling the episode a leak or hijack would misstate both the evidence and the control surface.
The distinction also protects the historical comparison from hindsight. Later route-leak taxonomies and relationship-role mechanisms help today’s operators express and check routing intent. They do not prove that the 2005 termination was an accidental policy escape, and they do not create retroactive duties governing the companies’ commercial decision.
Commercial Positions and Operational Accountability
The confidential peering terms matter to any contractual dispute, but they are not necessary to identify the customer-continuity problem. The two companies publicly disagreed about whether the trial relationship continued to satisfy its conditions. Without the full agreement and underlying measurements, an outside account cannot determine which commercial interpretation was correct.
Operational accountability begins at a different point. Once an operator knows that terminating an interconnection may remove the only workable path for some customers, the decision has measurable continuity consequences. Those consequences can be examined without declaring that the operator lacked a contractual right to terminate.
This separation avoids two opposite errors. The first is to assume that any customer impact proves misconduct. Networks must retain the ability to enforce agreements, protect infrastructure and end relationships. A continuity standard that effectively mandates perpetual settlement-free peering would erase legitimate operational and commercial autonomy.
The second error is to treat a bilateral contract dispute as having only bilateral effects. Customers were not parties to the peering relationship, yet some depended on routes exchanged through it. If neither carrier had mapped that dependency, tested alternatives or established a bounded termination procedure, the absence of those controls would remain important even if the termination were contractually permitted.
Accountability is therefore not synonymous with blame. It is an evidence discipline that asks who controlled each decision, what each party could reasonably observe, which safeguards existed and whether the outcome was verified. Legal liability requires additional facts and governing law. The public record here does not establish breach, negligence, bad faith, monopoly conduct or a regulatory violation.
Traffic imbalance claims illustrate why attribution is essential. Level 3’s public explanation referred to conditions for the trial arrangement, while the later joint release described traffic characteristics, volume obligations and conditional payments. Those statements show that traffic-related commercial criteria were part of the public dispute and remediation. They do not disclose the exact ratios, thresholds, measurement intervals or prices.
A route collector cannot fill that gap. AS paths show advertised reachability, not traffic volume. Even interface counters would need context about location, direction, aggregation and contractual measurement. Inferring confidential peering thresholds from public BGP data would confuse the routing control plane with commercial accounting.
The proper conclusion is bounded: a commercial disagreement led to deliberate removal of direct route exchange; some customers reportedly lost reachability; the parties publicly advanced different explanations; and they later restored interconnection under revised terms that included customer-protection procedures. The evidence does not decide the unpublished contractual merits.
A Control Map for the Failure
Level 3 controlled its decision to end the direct peering relationship and its side of the relevant BGP sessions. It also controlled the routes it accepted and exported, its internal escalation, its communication with customers, and any staged or immediate termination procedure it used. Those areas define its operational accountability without resolving whether termination was commercially justified.
Cogent controlled its own sessions, route advertisements, import and export policies, customer communications and resilience offerings. Its 7 October statement proposed immediate restoration before further negotiation, but public advocacy does not eliminate its own responsibilities. Cogent was positioned to understand which customers depended on its upstream and peer relationships, what alternatives it could supply, and what limitations accompanied the connectivity it sold.
Both carriers shared control over bilateral restoration. One side could offer to restore a session, but working interconnection required compatible action on both sides: active sessions, accepted routes, workable policy and functioning forwarding. The joint announcement indicates that the relationship was restored through agreement rather than unilateral routing action.
Other carriers controlled potential alternate paths. Their policies determined whether they would carry routes between the two sides and under what commercial relationship. They also controlled capacity, filtering and incident communication within their own networks. Their presence in the topology did not guarantee that they would provide an acceptable path.
Customers controlled some resilience choices, including whether to purchase diverse connections, operate BGP, distribute services across networks or monitor external reachability. That control was constrained by cost, technical capability, address resources, contract availability and provisioning time. It would be inaccurate to treat every affected customer as capable of instant multihoming.
Registries controlled records concerning autonomous-system numbers and address resources. Those records supported identity and routing administration, but they did not enforce a working path between AS174 and AS3356. A correct registry entry could help an operator know who originated a prefix or whom to contact. It could not restore a terminated BGP relationship.
Route-collector operators controlled measurement infrastructure, not the production paths. Their archives make later analysis possible, but a collector cannot cause a carrier to accept a route. Measurement is an accountability ledger: it records part of what participating networks exposed. It is not a substitute for operational continuity.
Regulators could examine market structure and exercise powers granted by law, but they did not operate the routers. FCC records provide context about interconnection incentives and network effects. They do not establish that the agency directed the 2005 restoration or found either company legally at fault.
This map prevents responsibility from collapsing onto one convenient actor. The termination decision, the commercial dispute, the alternate-path inventory, customer resilience and restoration were controlled by different parties. Effective accountability records those divisions instead of assuming that one actor’s role cancels all others.
The 28 October Agreement as a Remediation Design
The joint announcement on 28 October matters because it moved beyond competing public statements. Cogent and Level 3 said they had reached a modified settlement-free peering arrangement. The release described obligations tied to traffic characteristics and volume, payments when obligations were not met, and a process intended to protect customer connectivity if the relationship expired or violations remained unresolved.
Those elements address several distinct failure pressures. Measurable traffic obligations can make the commercial criteria less ambiguous between the parties. Conditional payments can provide an alternative to immediate termination when operational service continues despite a commercial imbalance. A defined expiration or uncured-violation procedure can create time to notify customers and arrange alternate paths.
The public description does not show exactly how those mechanisms worked. It does not reveal thresholds, formulas, deadlines, escalation owners or the evidence required to establish compliance. It also does not prove that conditional payment was available in every circumstance. Any stronger description would reconstruct private terms that were never published.
The customer-protection provision is nevertheless significant. Its inclusion indicates that the parties treated connectivity impact as something an interconnection agreement could address procedurally. That is different from saying the agreement guaranteed uninterrupted global reachability. A procedure can reduce risk while still failing under unforeseen conditions, inadequate capacity or incomplete implementation.
Restoration also requires more than signing terms or bringing a BGP session into an established state. Routes must be exchanged, accepted and selected. Forwarding must work in both directions. Alternate paths that became active during the interruption may need to converge back without causing new instability. Customer endpoints must become reachable from relevant networks.
The public announcement establishes the restored arrangement, but it does not provide a complete per-customer restoration record. A bounded account should therefore say that the companies restored direct interconnection under revised terms, not that every affected application recovered simultaneously or that all consequences ended at one universal time.
Later Guidance as Comparison, Not Retroactive Law
RFC 4271 formalizes the BGP-4 route-exchange and decision framework. It was published after the October 2005 dispute, although it documents the protocol family already operating across the Internet. It helps explain how routes are advertised, withdrawn and selected. It does not impose a commercial obligation on two autonomous systems to maintain settlement-free peering.
RFC 7454, published much later, collects operational security practices for BGP sessions. It discusses filtering, session protection, prefix limits and policy controls. Those practices are useful for evaluating how an operator can make interconnection behavior more predictable and observable. They do not decide whether either company met the standards reasonably applicable in 2005, and they do not guarantee continuity after an intentional session shutdown.
RFC 8212 establishes explicit import and export policy as a safer default for external BGP. That approach reduces accidental propagation caused by missing policy. The Cogent-Level 3 event was not an example of routes being exported accidentally because an empty configuration defaulted to permissive behavior. Explicit policy could document intent, but it would still permit a deliberate decision to exchange no routes.
RFC 7908 classifies route leaks. Its taxonomy helps distinguish unintended propagation from legitimate customer, peer and transit relationships. The 2005 event belongs outside that taxonomy’s central failure mode because the evidence concerns deliberate depeering. Applying the terminology carefully prevents a missing path from being mislabeled as an excessive or unauthorized path.
RFC 9234 later introduced BGP Roles and mechanisms for expressing relationship intent between neighboring autonomous systems. Better expression of roles can help identify incompatible configurations and constrain route propagation. It cannot encode every private commercial condition, and it does not compel two networks to remain interconnected after a relationship ends.
RFC 1997 is historically different because BGP communities were already standardized before the dispute. Communities could help networks signal route-treatment preferences. Their availability does not prove how AS174 or AS3356 used them in October 2005. Nor does it turn a community value observed at a collector into a complete statement of contractual intent.
MANRS guidance later articulated operator actions involving filtering, coordination, global validation and anti-spoofing. NIST’s later interdomain-routing guidance similarly emphasizes resilient configuration, monitoring and incident response. These materials provide useful contemporary comparison points: operators can maintain contact information, observe route changes, validate policy and prepare response procedures.
None is retroactive law. None supplies the missing 2005 contract, traffic measurements or internal escalation records. None proves negligence merely because an operator’s historical conduct differs from a later recommendation. Their proper use is prospective: they help translate the episode into controls that current networks can measure.
Modern RPKI-based origin validation deserves the same caution. It can help a network reject an invalid origin announcement. It does not establish whether a peer should carry a valid route, whether capacity exists or whether a commercial relationship must continue. A route can be cryptographically consistent with an authorized origin and still be unreachable because no acceptable path crosses the relevant network boundary.
The most transferable later lesson is therefore not that one security mechanism would have solved the dispute. It is that relationship intent, route policy, monitoring, coordination and continuity planning must be connected. A network needs to know what it intends to exchange, what it is actually exchanging, which customers depend on that state and how it will verify a controlled exit.
A Measurable Termination-and-Restoration Standard
A useful accountability standard must remain neutral about the commercial outcome. It should not require indefinite peering, dictate settlement terms or presume that either entity is entitled to free transit. It should require operators to make the continuity consequences of a planned termination observable and bounded.
The first measure is dependency coverage. Before ending a consequential interconnection, each carrier should identify the customer prefixes, destination groups or service classes for which the direct relationship is the only verified path. The measurable result is not a claim to know the whole Internet. It is the proportion of the operator’s in-scope customer inventory for which dependency has been assessed and time-stamped.
A dependency record should distinguish direct observation from inference. A route seen through the interconnection is not necessarily dependent on it if another acceptable path exists. An alternate path shown in a topology is not verified if the operator has never tested whether it is exported, accepted and usable. The record should therefore state the vantage points, route policies and forwarding tests supporting each classification.
The second measure is alternate-path verification. For each dependency group, the carrier should record whether at least one tested alternate route exists, whether forward and return paths work, and whether the path has sufficient operational capacity for the intended service. The relevant metric is verified coverage: tested reachable units divided by all units expected to need an alternative.
That ratio must carry scope information. A high result measured only from the operator’s own routers does not establish external reachability. Testing should include independent networks representing materially different paths. The standard need not prescribe one universal number of vantage points; it should require the carrier to declare why its chosen set represents the customers and regions at risk.
The third measure is policy readiness. The operator should preserve the import and export policy intended before, during and after termination, together with the responsible owner and activation time. That evidence makes it possible to distinguish a planned withdrawal from an accidental leak, configuration error or unrelated session failure.
Policy readiness also includes a simulation or controlled test where feasible. An operator can reduce preference for the direct route or test selected customer prefixes through alternatives before ending the relationship. Such testing may not be possible in every architecture and can itself create risk. The accountable requirement is to document whether it was performed, what it covered and why any untested dependency was accepted.
The fourth measure is capacity readiness. An alternate BGP path is not a continuity control if it collapses under ordinary redirected traffic. Operators should record the tested capacity of relevant alternatives, the traffic classes included and the time of the test. This does not require publishing confidential volumes. It requires internal evidence sufficient to establish that routing around the interconnection was more than a theoretical possibility.
The fifth measure is notice and escalation. A termination plan should identify the decision owner, the network operations owner, the customer-communication owner and the counterparty contact. It should record when each was notified and when customers in identified dependency groups received actionable information.
Actionable notice must explain the operational risk rather than merely describing a commercial dispute. A customer needs to know which services may lose reachability, what alternate connectivity is available, what tests it should perform and where to report a failure. The metric is coverage and elapsed time: how many identified dependent customers received notice, and how long before or after the routing change that notice occurred.
The standard should allow an emergency exception. Security incidents, uncontrolled failures or immediate contractual risks may make advance notice impossible. An exception should not erase evidence. It should record the reason for immediate action, the person authorizing it, the safeguards considered and the earliest time at which customers and the counterparty were informed.
The sixth measure is event observability. At termination, both carriers should preserve session state, route counts, relevant announcements and withdrawals, accepted-path changes and forwarding-test results. A single “session down” entry is limited public evidence because the customer effect depends on the routes and paths that disappear with it.
Observability should produce a reachability matrix rather than one global percentage. Rows can represent tested source networks or customer cohorts; columns can represent relevant destination prefixes or services. Each cell can record reachable, unreachable, degraded or unverified, with a timestamp and vantage point. This exposes uncertainty instead of converting unmeasured space into assumed success.
The seventh measure is detection performance. An operator should know how long it took monitoring to identify loss of reachability after the routing change. The clock should not stop when the BGP session changes state. It should stop when the system identifies the customer-facing consequence with enough specificity for action.
Detection should separate control-plane and data-plane signals. A route withdrawal may predict harm, while active probes establish whether packets still travel through an alternate path. Application checks can show whether a service works after routing converges. Keeping these measures separate prevents a route-table entry from being mistaken for completed customer service.
The eighth measure is incident communication. During the interruption, status statements should distinguish verified facts from hypotheses and attributed commercial positions. An operator should report what changed, what scope it has measured, what remains unknown and when it will provide another update. Statements such as “the Internet remains available” are inadequate if they hide known partitions between customer groups.
The ninth measure is bounded restoration. Restoration begins when the parties take corrective action, but it is not complete merely because a session returns to an established state. A carrier should verify that expected prefixes are being exchanged, policies are accepting them, selected paths are stable and forwarding succeeds from representative external networks.
A restoration record should preserve separate timestamps for session establishment, route acceptance, first successful data-plane tests, recovery of each customer cohort and closure of outstanding complaints. These timestamps prevent a technically convenient event—such as the first BGP keepalive—from being presented as the universal end of customer harm.
The tenth measure is route-state reconciliation. Paths used during the interruption may remain preferred after direct peering returns, or traffic may oscillate while policies reconverge. Operators should compare the intended post-restoration state with observed routes and investigate material differences. The goal is not to force every route back to its earlier path; it is to ensure that the resulting state is understood and usable.
The eleventh measure is unverified exposure. Every termination record should state how many in-scope prefixes, customer groups or external regions were not tested. Unknown coverage is an accountability fact, not an empty field. Reporting it prevents a limited successful sample from becoming an unsupported claim of universal recovery.
The twelfth measure is evidence retention. Route observations, configuration changes, notices, incident messages and restoration tests should be retained under a consistent timeline. Public collectors remain valuable independent references, but the carriers’ own evidence should be more complete because they can see local preference, rejected routes, internal topology and customer association.
These measures can be summarized as a continuity chain:
- Identify who depends on the interconnection.
- Verify which alternate paths actually work.
- Record policy, capacity and decision ownership.
- Notify the counterparty and affected customers under a declared procedure.
- Observe both route state and packet delivery during the change.
- Measure harm by bounded cohorts and independent vantage points.
- Restore sessions, accepted routes and forwarding.
- Reconcile the resulting state and preserve unresolved uncertainty.
No public evidence shows that this complete chain existed for either carrier in 2005. The standard should not be presented as a historical obligation that the companies necessarily violated. It is a way to convert the event’s demonstrated failure pressures into measurable current practice.
It also avoids imposing an impossible guarantee. No operator can prove reachability from every network to every endpoint at every moment. What an operator can prove is the scope it assessed, the alternatives it tested, the observations it retained, the customers it warned and the conditions under which it declared restoration.
What the Public Record Still Cannot Establish
The complete peering contract remains unavailable. The public statements do not reveal all traffic ratios, measurement windows, port capacities, prices, cure periods or termination rights. Without those facts, an outside account cannot determine whether either company met or violated its private obligations.
The complete routing state is also unknown. RouteViews, RIPE RIS and Merit provide valuable observations, but they do not expose every private peer, local preference, rejected route or forwarding decision. The surviving public data cannot identify every affected prefix or customer.
Customer harm cannot be quantified precisely from the frozen record. Contemporary reporting supports the conclusion that some businesses and users experienced reachability failures. It does not establish total lost revenue, duration for every customer, application-level consequences across all services or equal effects on both networks.
Internal decision ownership is not public. Level 3 controlled its termination action, but the available material does not identify every executive or operational approver, the escalation sequence or the internal tests performed before the change. Cogent’s internal response process and resilience assessment are similarly incomplete.
The revised agreement is evidence of remediation design, not complete proof of implementation. Its public description indicates traffic obligations, conditional payments and a customer-protection process. It does not show how each control was subsequently tested or whether it would have addressed every future failure scenario.
The legal allocation is unresolved here. Later FCC discussions provide regulatory context, but the cited records do not establish a finding of illegality, contractual breach, negligence or bad faith in this event. Operational control and measurable accountability can be analyzed without converting them into legal conclusions.
Continuity Is Proved by Routes That Work
The 2005 Cogent-Level 3 depeering remains instructive because it stripped away the assumption that major-network status guarantees universal reachability. AS174 and AS3356 each remained identifiable networks with registered resources, customers and connections elsewhere. Yet some paths across their former relationship stopped working, and some customers reportedly could not route around the split.
The event’s central fact was not merely that two companies disagreed. It was that a bilateral commercial decision changed interdomain route availability. BGP withdrawals, alternate propagation, import and export policy, multihoming and restoration determined the practical result.
Public evidence supports a careful conclusion. Level 3 deliberately ended direct peering on 5 October. Cogent publicly sought restoration before further negotiation. Level 3 said the trial arrangement no longer met its conditions. Some customer reachability was disrupted, although the complete scope is unknown. On 28 October, the companies announced restored settlement-free peering under revised terms that included a process intended to protect customers during a future expiration or unresolved violation.
Nothing in that conclusion requires deciding the private contractual merits. Nor does it require mandatory peering. It requires recognizing that autonomous control carries an evidentiary duty when its exercise can isolate dependent customers.
A registry can record who holds an address block. A contract can record commercial obligations. A status statement can record a party’s position. Full-Internet reachability is proved somewhere else: in routes that are actually advertised, accepted, selected and forwarded, with observable alternatives when a direct relationship ends.
That is the enduring accountability test. Before terminating a consequential interconnection, know which customers depend on it. During the change, measure what disappears rather than assuming the rest of the Internet will route around it. After restoration, verify customer paths rather than stopping at the contract signature or BGP session state. The record is useful only when it corresponds to a running path.
Sources
- https://www.cogentco.com/en/news/press-releases/227-cogents-standing-offer-to-level-3-turn-the-connection-back-on-then-negotiate
- https://www.cogentco.com/en/news/press-releases/225-level-3-and-cogent-reach-agreement-on-equitable-peering-terms
- https://docs.fcc.gov/public/attachments/FCC-15-24A1.pdf
- https://docs.fcc.gov/public/attachments/DOC-327292A1.pdf
- https://docs.fcc.gov/public/attachments/DA-11-1643A1.pdf
- https://docs.fcc.gov/public/attachments/FCC-05-184A1.pdf
- https://lists.nanog.org/archives/list/nanog%40lists.nanog.org/2005/10/
- https://www.merit.edu/wp-content/uploads/2024/10/Merit-Network-BGP-Inspect-Project.pdf
- https://archive.routeviews.org/bgpdata/2005.10/UPDATES/
- https://www.ripe.net/analyse/internet-measurements/routing-information-service-ris/
- https://asrank.caida.org/algorithm
- https://www.caida.org/projects/econ/
- https://www.rfc-editor.org/rfc/rfc4271.html
- https://www.rfc-editor.org/rfc/rfc7454.html
- https://www.rfc-editor.org/rfc/rfc8212.html
- https://www.rfc-editor.org/rfc/rfc7908.html
- https://www.rfc-editor.org/rfc/rfc1997.html
- https://www.rfc-editor.org/rfc/rfc9234.html
- https://www.manrs.org/wp-content/uploads/2021/02/MANRS-Network-Operators-Actions-v2.4.4.pdf
- https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-189.pdf
- https://www.theregister.com/2005/10/06/level-3-depeers-cogent/
- https://convergedigest.com/level-3-issues-statement-concerning/
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
