Summary

  • RFC 9723 reuses ordinary IPv6 unicast routing and the Color Extended Community to advertise SRv6 locator prefixes associated with intent; an SRv6 Service SID is steered by longest-prefix matching against those colored prefixes.
  • A visible color is only one control-plane assertion. It does not prove that every AS uses the same current intent dictionary, that the route reached and entered each FIB, that the expected prefix won the match, or that packets met the promised latency, isolation or availability result.
  • The defensible operating record joins vocabulary ownership, locator allocation, BGP propagation, per-domain (next hop, color) resolution, exact RIB/FIB state, packet observation, service measurement and reverse-order withdrawal.

A perfect control-plane story with a missing middle

Imagine an enterprise service assigned an SRv6 Service SID under a locator marked for low delay. At the source PE, the expected IPv6 colored prefix is present. A route collector in the destination AS shows the same Color Extended Community. The service desk sees green at both ends.

Yet the path crosses three autonomous systems. The middle AS has not enabled Colored Prefix Routing. Its border router ignores the color and resolves the next hop over best effort, exactly the incremental-deployment behavior permitted by RFC 9723. The colored route continues downstream. The number arrives intact. The intended path does not.

This is not a protocol contradiction. It is an evidence error. The first and third domains can truthfully report a colored prefix while the end-to-end service remains unable to support a low-delay conclusion. The important question is therefore not whether color exists. It is who can prove what happened at each transition.

The RFC Editor record and IETF Datatracker identify RFC 9723 as an Informational RFC published in May 2025. It is not an Internet Standards Track specification. The errata search is a status surface, not an implementation certificate.

The address now carries a routing intention

RFC 9723 avoids inventing another BGP address family. It reuses IPv6 Unicast, AFI/SAFI 2/1, whose inter-domain foundation comes from RFC 2545, and attaches the existing Color Extended Community defined within the BGP Tunnel Encapsulation framework. The IANA BGP Extended Communities registry records the shared protocol allocation surface. RFC 9723 itself requests no new IANA action.

At an SRv6 PE, a base locator can be divided into more-specific sub-locators. Each sub-locator is associated with an intent represented by a color: low delay, high bandwidth, or another locally agreed meaning. The PE advertises those sub-locators as colored IPv6 prefixes and may advertise the covering base locator without color.

An SRv6 service with a particular intent receives a Service SID under the corresponding colored locator. Its service route follows RFC 9252. Under the Option C model described by RFC 9723, the service route keeps the originating PE as next hop and need not carry the Color Extended Community itself: the address structure places the Service SID under the intended locator.

That economy is the design's attraction. A router can use the Service SID as the outer IPv6 destination and perform ordinary longest-prefix matching. If the matching colored locator route has been received and installed, the selected next hop points toward a color-aware intra-domain path. The process repeats at each border. A dedicated inter-domain transport SID or label is unnecessary.

The same economy creates the central audit risk. Intent is no longer repeated on the service route. It is inferred from a relationship among the Service SID, a covering prefix, the winning longest match and the color attached to that route at that moment. Any stale or more-specific route can change the inference without changing the service identifier.

The color dictionary is a governed asset

RFC 9723's normal case assumes a consistent color domain: the same value represents the same intent through all participating ASes. It also recognizes a special case in which two domains use different color values for the same intent and a border node rewrites the Color Extended Community according to a mapping policy.

Neither case is self-proving. BGP can carry the value; it does not authenticate the business meaning “low delay,” the measurement threshold behind it, the owner of that definition or the date on which it changed. An authenticated BGP session can protect a relationship with a peer while leaving the semantic agreement outside the protocol.

The color dictionary therefore needs its own receipt: color value, natural-language intent, measurable objective, scope of ASes and services, version, owner, approver, start time, retirement time and permitted mappings. Each border policy should cite the exact dictionary versions it joins. A route record without this provenance proves only that a number was carried.

RFC 9723 calls two copies of the same colored prefix with different Color Extended Communities a misconfiguration. That is a useful deterministic conflict boundary. Operations should preserve both conflicting observations, stop automatic assurance claims, identify which origin or policy produced each copy and record the resolution. Silently choosing one route may restore reachability while destroying the audit trail.

(N, C) is a request to local machinery

When a border receives a CPR route, it can resolve the tuple (N, C)—BGP next hop and color—to a color-aware intra-domain path. RFC 9723 deliberately permits several mechanisms: SRv6 Policy, SR-MPLS Policy, SRv6 Flex-Algo, SR-MPLS Flex-Algo or RSVP-TE. The detailed resolution policy stays local.

That means the same inter-domain color can trigger different machinery in each AS. One controller may bind C1 to an explicit SR Policy. Another may use a Flex-Algo topology. A third may fall back when no valid color-aware path exists. RFC 9256 shows that SR Policy selection has its own candidate-path validity, preference, active-path and fallback states. A valid color value is an input to that selection, not its result.

For every domain, preserve the received prefix, next hop and color; mapping-policy version; eligible path mechanisms; selected candidate and reason; validity and liveness state; fallback rule; and the programmed next hop. A controller's intended state must not be substituted for router readback.

Longest match can preserve reachability and erase intent

The base locator covers its colored sub-locators. RFC 9723 therefore requires aggregation to be disabled for IPv6 unicast routes carrying the Color Extended Community. Without the more-specific routes, an ingress PE can continue matching the broad base locator while losing the intended color-aware treatment.

This is the failure that dashboards often mislabel as recovery. A colored /68 disappears, but an uncolored /64 remains. The Service SID is still reachable, so a basic probe succeeds. Longest-prefix matching has changed, however, and the packet now follows a different path. Connectivity was restored; the intended service was not demonstrated.

The inverse also matters. An unexpected more-specific route can shadow the authorized colored prefix. A FIB audit must therefore ask not merely whether the expected prefix exists, but which prefix actually wins for representative Service SIDs. Store the entire relevant covering chain, route age and withdrawal history. Test positive and negative canaries at the prefix boundaries.

Control-plane receipt is still not FIB evidence. RFC 9723 says border nodes and ingress PEs need the colored locator prefixes in both RIB and FIB. The gap between these stores is operationally material: policy rejection, recursive-resolution failure, hardware capacity, programming delay or stale line-card state can leave a route visible without changing packets.

Incremental deployment is also an explicit downgrade path

Legacy transit domains may ignore the Color Extended Community and resolve the CPR route to best effort while advertising it onward. This preserves interoperability and reachability. It also creates a precisely located assurance break.

An operator should not hide that break under a general “supported end to end” label. The route needs a capability path: which ASes and border nodes support CPR; which accepted and resolved the color; which ignored it; where fallback began; and whether the service owner authorized that downgrade. A downstream AS seeing the color cannot infer how an upstream legacy domain treated the packet.

Local BGP policy adds another decision surface. With multiple EBGP paths, a speaker may consider route attributes and link properties to select the path that better meets the intent. RFC 9723 leaves the detailed policy out of scope and says policies across domains need consistency. That sentence is an operating obligation, not evidence that consistency exists.

The trusted domain is not a measurement result

RFC 9723 confines the mechanism to interconnected ASes under one operator or an operational trust model. RFC 8402 describes the Segment Routing trusted-domain assumption and also says SID advertisements need trusted sources, conflicts need deterministic handling and OAM is necessary to validate path effectiveness, liveness and performance. Default delivery remains best effort.

Trust should be decomposed into named controls: BGP peer authorization, route filters, origin and next-hop policy, color-dictionary custody, controller write authority, configuration review, RIB/FIB readback and data-plane observation. Calling several ASes “trusted” does not show that every one runs the same policy version or that an on-path compromise is absent.

The privacy boundary is also real. RFC 9723 notes that color-to-intent mappings are observable to BGP nodes in the domain and may allow an on-path attacker to identify traffic associated with a particular intent. RFC 4271 and the BGP vulnerability analysis remain relevant to session and route risk; RFC 8754 and RFC 8986 supply the SRv6 data-plane and behavior boundaries.

RFC 9723 points to RFC 9602, which allocates 5f00::/16 for SRv6 SIDs, and describes a common-agreement model that drops the broader block by default while permitting colored prefixes actually in use. The filter configuration, hardware installation, exception list and packet result each need independent evidence. Agreement on a filter does not install it.

Measure the service that the color was meant to describe

The final receipt belongs to the service owner. For a low-delay intent, measure one-way or round-trip delay with clock and vantage-point provenance, plus loss, jitter and availability over an agreed window. For isolation, prove the relevant forwarding and resource boundary, not merely a distinct color. For bandwidth, distinguish path capacity, allocation, congestion and delivered throughput.

Packet evidence should be joinable to the control state: Service SID, winning prefix, FIB next hop, domain entry and exit, encapsulation or segment list, observation time and policy version. A test packet sent after a route change cannot validate the state that existed before the change. A healthy average can hide one legacy-AS downgrade or a regional tail.

Withdrawal needs the same discipline in reverse. When a colored locator is retired, record the origin withdrawal, each downstream disappearance, controller invalidation, FIB removal, fallback activation and last packet on the old treatment. The base locator may keep the service reachable; that makes explicit declassification more important, not less.

This is where Lu Heng's Running-Code Primacy is useful as a disclosed analytical frame: publication and control-plane symbols do not outrank the running network. His Minimum Initial Specification, Localized Future Decision, and Voluntary Adoption helps separate the thin interoperable carriage from each operator's adopted policy. On Reality Layers sharpens the last distinction: the color is a coordination fact; the installed path and measured service are executable facts.

RFC 9723 makes intent easier to carry. It does not make intent easier to prove. The durable achievement is not a color that crosses three ASes. It is an evidence chain that can show where the color was interpreted, where it was ignored, which prefix won, which path ran and what the service actually delivered.

Sources

Primary specification set: RFC 9723, RFC Editor record, IETF Datatracker, RFC 9723 errata search, RFC 2545, RFC 4271, RFC 4272, RFC 8402, RFC 8754, RFC 8986, RFC 9012, RFC 9252, RFC 9256, RFC 9602 and the IANA BGP Extended Communities registry.

Attributed analytical framework: Running-Code Primacy, Minimum Initial Specification, Localized Future Decision, and Voluntary Adoption and On Reality Layers.