Summary
- NSFNET’s 1995 retirement depended on proving a distributed successor architecture, not merely reaching a shutdown date; retained backup paths could make an incomplete migration look healthy.
- Gerich and a broad operating community paired irrevocable termination notices with a test peering cut, while the old routing-policy database remained alive until the replacement had demonstrated parity.
At midnight on 30 April 1995, NSFNET nodes were powered down in their own time zones. That is the clean ending. The more revealing event happened five days earlier, when Merit removed the backbone’s external peering so networks had to use their new commercial connections. It was a test with consequences: reachability that had been quietly falling back to NSFNET would suddenly fail in public.
Calling this a dress rehearsal is an editorial description, not the historical name. Susan R. Harris and Elise Gerich, in their contemporary account of the retirement, called it a test shutdown. The distinction matters because the test was not theatre. It was a deliberate withdrawal of the safety net while engineers still had several days to diagnose what emerged.
Gerich stood at the centre of the calendar and the formal notices, but the transition was collective. Harris co-authored the detailed record. Merit worked with NSF, ANS, IBM, MCI, regional networks, commercial Internet providers, Network Access Point operators, USC ISI and Routing Arbiter staff. Hundreds of operational decisions were made by people who owned circuits, routers, route policy, monitoring and customer relationships. Gerich’s contribution was to help make those interdependent decisions legible as one retirement process.
The deadline was a system, not a date
NSF’s withdrawal from operating a general-purpose backbone had been prepared well before 1995. In 1992 the agency extended its agreement with Merit for 18 months so it could issue a follow-on solicitation, give commercial providers time to develop and step back from direct network operations. The 1993 solicitation produced a deliberately decomposed architecture. Early in 1994, awards covered four different surfaces: Network Access Points for exchange, a Routing Arbiter project led by Merit with USC ISI, MCI’s very high-speed Backbone Network Service for research, and commercial Internet service for the regional networks.
The old backbone therefore had no single successor. Retirement required four conditions to converge. The NAPs had to operate in production. NSFNET and the regional networks’ chosen providers had to reach those exchanges. Route Servers and a usable routing registry had to exist. Each regional network had to move its traffic to a commercial provider. A green light on one condition could not compensate for red on another.
Initial dates slipped because paper readiness and operating readiness were different things. The primary and backup Route Servers shipped in November 1994, but a route service also needed circuits, front ends, controllers, switches, bridges, addressing, security, round-the-clock monitoring and out-of-band access. Concerns about the readiness and performance of ATM at the Pacific Bell and Ameritech NAPs led to contingency FDDI configurations in March 1995. The transition was building not one replacement machine but a federation of independently owned services.
This architecture changed the nature of authority. NSF could set the retirement objective and finance the transition. Merit could coordinate and operate the outgoing backbone. Neither could declare the new Internet ready by inspecting its own equipment. Readiness had to be demonstrated across organisational boundaries.
A migration could be complete on paper and false in traffic
Regional transitions made that gap visible. Gerich received calendars and engineering overviews from the regional networks, working with NSF networking director Priscilla Huston. No region met the original 31 October target. Some were three or four months late. More significantly, some networks that had moved were returned to full NSFNET service when deployment problems appeared.
Rollback was not proof of failure; it was a useful option while the process was reversible. But a backup that remained indefinitely could hide failure. By mid-April only seven regional networks had completely severed their NSFNET connections. Other networks had commercial service yet still kept the federal backbone available as a secondary path. Their normal traffic could look migrated while an unnoticed route, capacity shortfall or diagnostic habit still depended on the old system.
Gerich warned the community in March that traffic was not falling quickly enough. Merit circulated a histogram of the ten largest remaining traffic originators. This was not a vanity chart. It converted a declared project state—“we have a new provider”—into observed dependency: “packets are still choosing the old backbone.” The retirement team also removed the T1 safety net. Each withdrawal made the remaining coupling more measurable.
Irrevocable notices separated confidence from commitment
The formal 60-day termination notices were designed to be irreversible. Once one was sent, NSFNET service through that node would not be restored. The first notice covered Atlanta after SURAnet was ready. On 28 February, Gerich sent the formal notice for 19 remaining locations, setting 30 April as their end date.
That mechanism prevented endless optionality, but only because it followed evidence. A notice converted technical confidence into institutional commitment: regional operators, providers and customers could no longer assume the old node would be rescued after the deadline. It also concentrated responsibility. If an organisation needed more capacity, a different route or a replacement diagnostic path, it had to surface the need before the commitment became irreversible.
Merit initially planned to terminate peering on 21 April, restore it, repeat the action permanently on 28 April and end operations on 30 April. Networks raised concrete dependencies involving capacity, connectivity and diagnosis. The team accommodated individual problems without moving the final deadline. In that design, listening was not the opposite of firmness. It was how a firm deadline became survivable.
The test itself then exposed another hidden dependency: the retiring system’s ability to generate its own final configuration. Thousands of simultaneous routing changes caused files to truncate or become corrupt. The test had to be postponed while operators provided more space and reduced the network lists. Harris and Gerich’s account notes the irony plainly: the old Policy Routing Database machinery could not handle the scale of change required to turn the old service off.
Peering was finally removed on 25 April. Most of the event was quiet, though calls still arrived. That quiet was earned by the noisy work before it: late migrations, rollbacks, traffic measurements, exception handling and a failed first attempt. The nodes were then powered off at midnight in each local time zone on 30 April.
The control plane outlived the transport
The last date in the story is not 30 April but 8 May. NSFNET’s Policy Routing Database, the PRDB, remained in service after the backbone nodes went dark because the replacement Routing Arbiter Database had a different migration clock.
The RADB began empty while existing tools relied on PRDB attributes. The transition involved roughly 40,000 network-prefix policies and about 100 configuration files totalling around 250,000 lines on a two-week production cycle. Operators agreed on a temporary advisory attribute, converted data, introduced Maintainer and Autonomous System objects and ran the databases in parallel. Repeated line-by-line comparisons were needed before the RADB could be trusted to replace the PRDB. RFC 1786, co-authored by Gerich and other routing-registry practitioners in 1995, documented the shared RIPE-81++ representation being used across registries.
The PRDB was retired on 8 May only after configuration parity and the ANS handover were ready. That sequence is easy to miss because the physical shutdown supplies the better photograph. Operationally, however, it is the strongest evidence of discipline. The institution did not force every dependency to share one ceremonial date. It allowed the old control surface to persist until its successor had passed a different proof.
Gerich’s later Internet Hall of Fame profile describes her as overseeing the retirement and the move to commercial providers; it also records her earlier coordination of the T1 and T3 NSFNET and her co-founding of NANOG with Mark Knopper. Those facts fit the character of the 1995 work. The transferable skill was not mastery of one router. It was the creation of forums, calendars, evidence and commitments through which operators could retire shared infrastructure without pretending that one organisation controlled the whole system.
The record does not justify a claim of a flawless transition or of no outages. It shows something more useful: an orderly exit can include missed dates, rollbacks and a failed rehearsal, provided those events reveal dependencies before the irreversible step. The success of the shutdown lay less in silence on 30 April than in making hidden reliance visible by 25 April—and keeping the database alive until 8 May.
Sources
- https://archive.icann.org/meetings/buenosaires2013/en/schedule/leader/gerich-elise.html
- https://nsarchive.gwu.edu/sites/default/files/documents/5989803/National-Security-Archive-National-Science.pdf
- https://www.internethalloffame.org/2020/06/03/forging-connections-and-collaboration-internet/
- https://www.internethalloffame.org/inductee/elise-gerich/
- https://www.merit.edu/about/resource/nsfnet-backbone-service-chronicling-the-end-of-an-era/
- https://www.merit.edu/research/projects/the-nsfnet-backbone-service/
- https://www.merit.edu/research/projects/the-routing-arbiter-project/
- https://www.merit.edu/wp-content/uploads/2024/10/Merit-Network_NSFNET-A-Partnership-for-High-Speed-Networking.pdf
- https://www.merit.edu/wp-content/uploads/2024/10/Merit-Network_Retiring-the-NSFNET-Backbone-Service_-Chronicling-the-End-of-an-Era.pdf
- https://www.nsf.gov/about/history/nsf0050/pdf/internet.pdf
- https://www.nsf.gov/impacts/internet
- https://www.rfc-editor.org/rfc/rfc1786.html
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
