Summary

  • BMP replaces fragile screen scraping with structured snapshots and incremental BGP observations, but each feed represents a particular router, instance, peer, address family, RIB stage and reporting mode.
  • Route Monitoring can compress intermediate state; Route Mirroring can expose exact PDUs but may be sampled, lose messages and consume resources; Loc-RIB can be filtered and still does not prove FIB installation.
  • A defensible conclusion records the observation entitlement and loss state, secures the route data, and correlates pre-policy, post-policy, selected, exported, programmed and measured outcomes without treating one collector as an oracle.

An incident dashboard shows three green facts. The offending route reached the border router. Import policy accepted it. The same route was exported to a customer. The team reconstructs a leak and changes the filter.

Hours later, the reconstruction collapses. The first panel came from pre-policy Adj-RIB-In and therefore showed what the peer offered, including routes later rejected. The second came from a filtered Loc-RIB feed that omitted the relevant VRF. The third inferred export from a label attached to a peer group rather than observing the post-policy Adj-RIB-Out of the customer session. Every BMP record on the dashboard was genuine. The relationship between them was invented.

This is the authority problem inside the BGP Monitoring Protocol. BMP exists because operators and researchers needed continuous access to routing information without scraping command-line screens. RFC 7854 provides a structured TCP stream carrying route state, peer lifecycle and statistics from a monitored router to one or more monitoring stations.

The specification is explicit about its limit: BMP is not a routing protocol. The station observes; it does not become a BGP peer that changes reachability through BMP messages. All BMP options are configured on the monitored router, and no BMP message travels from the station back to it. The separation is a useful minimum specification: shared telemetry without a central collector acquiring routing authority.

Observation is not one surface. RFC 4271 separates BGP information into stages. Pre-policy Adj-RIB-In contains unprocessed information advertised by a peer. Post-policy Adj-RIB-In contains what remains after inbound filtering and attribute modification, but before route selection. Loc-RIB contains routes selected by the Decision Process. Adj-RIB-Out contains routes prepared for advertisement to particular peers.

Those nouns form an evidence ladder. A prefix in pre-policy Adj-RIB-In proves that the monitored speaker received an advertisement within the represented session epoch. It does not prove acceptance, best-path selection, recursive resolution, FIB installation, advertisement to another peer or packet use. Moving from one rung to the next requires another observation.

BMP's base message vocabulary supports that work. Peer Up and Peer Down report the BGP session lifecycle and relevant OPEN information. Initiation describes the monitored system. Termination explains the end of a BMP session. Statistics Reports provide counters and gauges. Route Monitoring carries RIB state. Route Mirroring can carry verbatim received BGP messages, including malformed messages useful in revised-error-handling diagnosis.

Normal Route Monitoring begins with a snapshot of the configured RIB view for each monitored peer. It encodes routes in BGP UPDATE PDUs inside BMP messages. The dump has no required route order. An End-of-RIB marker closes the initial view for that peer.

The snapshot is not taken in a frozen world. Incremental changes can flow while the initial dump is still being walked. If a prefix is dumped and later withdrawn, the station must remove it. If the withdrawal arrives before the dump ever reaches that prefix, the station may see a withdrawal for an object it never stored and safely ignore it. Collector correctness is partly a streaming database problem.

An EOR marker proves completion of that initial epoch, not eternal completeness. A subsequent BMP transport gap, router queue overflow, station restart, identity collision or unprocessed message can still make the replica stale. A dashboard that displays “synchronized” needs to explain the last complete epoch and every discontinuity since it.

Route Monitoring is state-oriented, not necessarily wire-faithful. A router may receive several changes for one prefix before it generates and sends an RM message. RFC 7854 permits it to report the final state only. That state compression is valuable: it controls volume and protects routing work. It also means the feed cannot support every forensic question about intermediate order or oscillation.

The generated UPDATE can differ in encoding from the peer's exact PDU because implementations may format attributes differently. Timestamps also require care. They can be unavailable, and precision is implementation dependent. A collector-ingest time measures arrival at the station, not necessarily peer arrival, policy application, selection, FIB programming or the first affected packet.

Route Mirroring offers a different witness. Its purpose includes full-fidelity duplication of messages as received and capture of an errored PDU that was treated as withdrawn under RFC 7606. If a forensic question depends on the exact bytes and intermediate sequence, mirroring may be the correct source.

But “mirroring” is not a synonym for “lossless.” RFC 7854 permits sampled or lossless operation and defines a Messages Lost information code. It also warns that full fidelity may demand unbounded buffering, exhaust router resources, interfere with sending or receiving BGP UPDATEs and slow convergence. The observability system must never injure the system it is supposed to explain.

That creates a deliberate evidence trade. Route Monitoring usually preserves current state efficiently while discarding some intermediate history. Route Mirroring preserves more history at potentially much greater cost. A serious design assigns questions to modes: policy-state reconstruction may use RM; malformed-PDU forensics may require mirroring; neither should be activated everywhere merely because storage is cheap at the collector.

Loss proof belongs on both sides. The router reports queue depth, dropped or compressed state and session lifecycle where supported. The transport reports resets and stalls. The collector records ingress sequence, decode failure, backpressure, storage commit and replay position. Two monitoring stations are not independent witnesses if both consume the same producer queue or share the same implementation defect.

RFC 7854 originally focused on Adj-RIB-In, with an L flag distinguishing pre-policy and post-policy streams. That flag changes the claim. Pre-policy shows what arrived before local import judgment. Post-policy shows the locally accepted or modified set before route selection. A policy audit needs both views for the same peer, AFI/SAFI and epoch; counts from different stages cannot be subtracted casually.

RFC 8671 extended BMP to Adj-RIB-Out and added the O flag to distinguish output from input. Post-policy Adj-RIB-Out must convey what was actually transmitted to the peer after outbound filtering, modification and transmission-time attributes. It is the strongest BMP witness for an egress-policy claim.

Pre-policy Adj-RIB-Out answers a different question: what routes were available to outbound policy for that peering type. It does not necessarily equal the entire Loc-RIB. IBGP, route-reflector client, EBGP, confederation and route-server relationships establish different eligibility before a configured export policy runs.

Some mandatory attributes may not yet have their transmitted form in the pre-policy view. Next hop can be zero, empty or provisional until export. Treating that record as the wire message creates a false discrepancy or, worse, validates a message that was never sent.

The useful audit is a scoped diff. For one peer, address family and stable epoch, compare pre-policy and post-policy Adj-RIB-Out. Explain each removed route and each modified attribute through the active outbound policy. Then compare the post-policy BMP view with a receiver-side observation where the consequence matters. “The wholesale group is clean” is not enough if only one representative peer was observed.

Peer and update groups are implementation efficiencies. RFC 8671 warns that they are not a true representation of what is conveyed to every peer. Members may inherit group policy differently, carry per-neighbor exceptions or support different capabilities. An administrative label such as type=wholesale remains locally assigned metadata, not a universal relationship fact.

RFC 9069 added direct Loc-RIB monitoring. Before it, an operator might infer a router's selected routes by arranging another BGP session and monitoring what that other router received. The inference introduced policy transformation, aggregation, missing attributes and identity-correlation errors. Direct Loc-RIB makes the selected-state question cleaner.

It also creates a new synthetic peer type. Peer Type 3 represents a Loc-RIB instance rather than a remote BGP neighbor. A distinguisher, router ID and optional VRF or table name help identify the instance. Capabilities are represented through an emulated Peer Up. The collector must treat this identity as an explicit namespace, not join every table called “global” across routers.

Loc-RIB can be filtered before export to a BMP station. A network may expose EBGP-selected routes but omit IGP or private VRF routes. RFC 9069 requires the F flag when the view is filtered. That flag is not a cosmetic footnote. It changes “these are the selected routes” into “these are an authorized subset of the selected routes.”

Filtering may be correct for privacy, scale and separation of duty. A security analyst may not need customer VPN routes. An external research collector should not receive internal routing policy. The control failure occurs when a partial feed loses its F flag, its filter contract or its visible coverage statement and a consumer treats absence as nonexistence.

Loc-RIB monitoring can itself compress state. RFC 9069 gives the example of five changes within a second becoming one final update. Granularity varies with the sender implementation. An unchanged Loc-RIB feed can therefore mean that many inputs churned but selection stayed stable, that selection changes were compressed, that reporting stalled or that nothing changed. Other signals distinguish those cases.

Most importantly, Loc-RIB is not FIB. It shows routes selected by the BGP Decision Process, including locally originated or redistributed routes. A selected next hop may still fail recursion. Hardware may install fewer ECMP members. A line card may lag. Policy-based forwarding, tunnelling or protection state may change packet behavior. BMP does not turn selected control-plane state into forwarding proof.

The distinction matters in both directions. Large Adj-RIB-In churn may cause no Loc-RIB change and no service impact. One Loc-RIB change may cause a large FIB rewrite or no hardware change if an alternate maps to the same adjacency. The monitoring system needs event correlation, not a rule that equates route count with risk.

RFC 9972, published in May 2026, expands BMP statistics across the RIB stages. It adds gauges for pre- and post-policy inputs, selected state and pre- or post-policy outputs, including feature-specific states such as damping, route limits, licensing boundaries and RPKI origin-validation classifications.

These richer counts sharpen questions; they do not replace route evidence. A gauge is a value at a reporting moment, not an event ledger. Some types should appear only when the underlying feature is enabled. Scheduling and thresholds are implementation dependent. A counter that never arrives may mean zero, unsupported, disabled, suppressed, delayed or lost.

RFC 9972 explicitly refuses a tempting shortcut. Global counts and the sum of per-AFI/SAFI counts may disagree because of race conditions or partial failures. Producers and collectors can run consistency checks and should warn, but must not assume strict dependencies or stop the protocol. The inconsistency is evidence to investigate, not a reason to repair one value silently.

Gauges can reset through manual clearance or overflow, and both sides must track the discontinuity. During critical Graceful Restart or Long-Lived Graceful Restart work, a producer may sample, buffer or temporarily suspend some statistics so convergence retains priority. A quieter graph during failure can therefore mean that telemetry yielded resources to routing.

Current products expose the operational bargain. Cisco IOS XE documentation updated in April 2026 describes multiple stations, initial-refresh pacing, buffers and delays intended to avoid excessive load. Current IOS XR documentation allows parallel pre-policy, post-policy and Loc-RIB modes on specific releases and platforms, with advertisement and scan intervals. Junos exposes station memory limits and management-instance placement.

Those commands are not one portable contract. Platform, release, address family, storage mode and scanning implementation shape what is emitted. The deployment inventory must record observed capabilities, not infer them from the letters BMP or from another chassis in the same network.

Security is part of evidence quality. A full RIB dump can expose L3VPN reachability, peer structure, attributes and policy effects that are not public. Comparing pre- and post-policy feeds can reveal the import rules themselves. A station account with broad BMP access may hold a more complete map of routing intent than many router administrators.

The base specification notes that, without mutual authentication, an attacker can impersonate a router and feed false information or impersonate a station and acquire data. Without confidentiality, traffic can be read or altered. Where these concerns apply, RFC 7854 recommends IPsec tunnel mode with pre-shared keys. TCP alone supplies neither identity nor secrecy.

The modern control adds network placement, authenticated endpoint inventory, encryption, tenant separation, collector authorization, retention limits and tamper-evident storage. It also adds revocation: an operator must be able to stop one station's access without disabling BGP or destroying the evidence retained by another authorized party.

The first operational artefact should be an observation-entitlement matrix. For every router, BGP instance, peer, AFI/SAFI and station, it records whether pre/post-policy input, pre/post-policy output, Loc-RIB, RM, mirroring and statistics are enabled. It records L, O and F semantics, filter version, cadence, compression mode, buffer ceiling and owner.

The second is a replica-health ledger. It records the BMP TCP epoch, Peer Up and Down, initial EOR per source, last source timestamp, timestamp precision, router queue state, Messages Lost, gauge discontinuities, collector ingest gaps, decode errors and storage commit watermarks. “Connected” is merely one field.

The third is a policy-stage diff for sentinel prefixes. Preserve the received route before import, the result after import, all selected alternatives, the Loc-RIB winner, pre-export eligibility, post-export message and receiver observation. Each transition has a policy version, decision reason and accountable owner.

The fourth crosses the plane boundary. Resolve the selected next hop, inspect programmed FIB and ASIC adjacency, test the expected egress, record flows or packets and verify the reverse path. If the BMP-selected route and packet path disagree, the divergence is the finding; the dashboard does not get to declare the packet wrong.

Rollout should start with a small set of peers and address families. Exercise an accepted route, rejected route, attribute rewrite, best-path change, export suppression, peer flap, BMP flap, station backpressure, queue loss, filtered Loc-RIB, timestamp zero, counter reset and collector restart. Measure router CPU, memory, convergence and update latency with and without each mode.

Rollback must be independent of routing. Reducing a scan rate, disabling mirroring, narrowing a filter or revoking a collector should not reset the monitored BGP sessions. The operator should predict which evidence becomes unavailable and preserve an explicit coverage gap instead of silently showing an empty graph.

Authority should be separated. Routing teams own routing policy. Platform teams own producer capacity. Telemetry teams maintain transport and parsing. Security controls disclosure and integrity. Incident reviewers decide which witness supports a conclusion. Service owners verify forwarding. A collector operator should not be able to define the feed, suppress its gaps and certify its conclusion alone.

Heng Lu's minimum initial specification fits BMP's best form: a thin, deterministic observation format that participating routers can emit without delegating route choice. Localized future decision remains with each operator through stage selection, filtering, cadence, station choice and revocation. A new RFC or dashboard field becomes operationally real only when the deployed producer and collector implement it correctly.

Running-code primacy also sets the hierarchy. Configuration says what should be observed. A BMP record says what one control-plane stage reported. A collector database says what it retained. The Loc-RIB says what BGP selected. The FIB says what was programmed. The packet says what occurred. No lower rung may borrow the authority of a higher one.

Practical data sovereignty means more than owning the collector. It means controlling which routes leave which router, knowing which party can correlate them, limiting how long they persist, detecting alteration, exporting them in a usable format and ending access without asking the vendor or the monitoring provider for permission.

BMP can be an extraordinary witness. It can show a route before policy and after policy, expose exact outbound effects, preserve malformed messages, identify selected state and quantify routing pressure. Its value comes from being precise about its jurisdiction.

The monitor saw a route. The responsible question is: which route, at which stage, from which instance, through which lossy or compressed path, under whose filter, and corroborated by what forwarding evidence?

Sources