Summary
- RFC 8212 requires an EBGP speaker with no import policy to accept no routes and one with no export policy to announce none.
- Import and export are independent, while upgraded installations may retain earlier behaviour; session state alone therefore does not prove policy state.
A session is not permission
BGP transport state answers whether two speakers can exchange protocol messages. It does not answer whether either side authorised a route to cross the boundary. RFC 8212 updates RFC 4271 by defining the missing-policy case: absence is not permission.
Import policy controls what may enter the local routing system. Export policy controls what it may disclose or propagate. One direction can be complete while the other is absent, so the checks are independent.
This is a normative default, not proof that every deployed router already behaves this way. RFC 8212’s transition appendix anticipates staged implementation and says upgraded installations may preserve previous behaviour depending on configuration. A green session indicator is weak evidence; operators need the effective policy attached to that session.
What default reject changes
A fail-closed boundary limits the chance that an omitted policy becomes unintended propagation for peers, customers and downstream users. RFC 7908 supplies route-leak context, but does not establish that default reject prevents every leak or quantify an incident-reduction rate.
The control also moves cost forward. Every external session needs explicit policy, an owner, an approval record and a test that distinguishes an intentional empty result from broken configuration. Ownership and auditability are operational inferences; no claim is made about any named network, universal vendor conformance or measured deployment share.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance