Summary
- RFC 5398 reserves 64496–64511 and 65536–65551 for documentation and sample code, separating realistic examples from both public assignments and private-use deployments.
- A documentation ASN can be syntactically valid in BGP tooling while remaining invalid as the identity of an operating network; successful parsing is not an allocation or deployment receipt.
- Reliable controls trace example values from prose and test fixtures into generated configuration, then reject them again at production admission and verify the observed route state.
The copy action changed the meaning
Inside a guide, 64496 can help a reader follow a relationship between two autonomous systems. Inside a production neighbour statement, the same token makes a claim about who is speaking BGP. The digits have not changed. Their context and consequence have.
RFC 5398 exists because using assigned or merely unallocated numbers in examples is unsafe. Assigned values can refer to real operators. Unallocated values may later be assigned. Private-use values are not blank either: RFC 6996 describes them as operational resources used inside organisations, including data-centre networks. An example built from a private-use ASN can collide with a reader’s actual internal design.
The documentation reservation creates a third category. IANA records 64496–64511 for examples that fit the older 16-bit presentation and 65536–65551 for examples that require four-octet AS numbers. These are intentionally realistic. They allow books, RFCs, laboratories and sample code to show the same shapes that operators encounter without borrowing an operating identity.
That realism is useful only while purpose travels with the value. A copied example loses its surrounding prose first. A rendered template may then lose the file path that identified it as a laboratory fixture. A reviewer sees valid syntax and a plausible number. By the time a router accepts the configuration, the original warning may be several systems away.
The operational question is therefore not “will the parser accept this ASN?” It is “what evidence authorises this number to identify this network in this environment?” RFC 5398 supplies evidence for the opposite answer: the number is reserved so documents can discuss networks without designating one.
Two blocks preserve two kinds of fidelity
The paired reservations are not decorative duplication. One block is below 65536 and can be expressed in the traditional 16-bit ASN space. The other begins at 65536 and therefore exercises the four-octet space described by RFC 6793. An author can demonstrate old-width and new-width behaviour without switching to a live allocation.
That distinction matters in examples about transition. RFC 6793 defines mechanisms that let newer BGP speakers carry four-octet values through environments that include older speakers. It also gives AS_TRANS, 23456, a specific interoperability role. AS_TRANS is not a convenient teaching number and it is not an identity to assign casually. Documentation blocks let an explanation show a genuine four-octet ASN without misusing the transition token.
The same design principle appears elsewhere. RFC 3849 gives IPv6 documentation the prefix 2001:DB8::/32. RFC 5737 gives IPv4 documentation three TEST-NET blocks. Those reservations allow examples to remain structurally honest while avoiding someone else’s address. RFC 5398 applies the principle to routing identity.
Fidelity creates a control obligation. A test should be realistic enough to reveal width assumptions, serialisation bugs and policy mistakes. It should not be so weakly bounded that its identifiers can become production truth. The correct architecture does not make examples less realistic; it makes their permitted destination explicit.
Private use is not the same kind of safety
It is tempting to treat all non-public numbers as interchangeable. RFC 6996 makes that impossible. Private-use ASNs are intended for real BGP use within bounded contexts. They may originate prefixes inside an organisation, appear in internal paths and support operational topologies. Because they are not globally unique, RFC 6996 requires their removal from path attributes before routes reach the global Internet.
A documentation ASN has a different purpose. It exists so an example does not collide with either a public assignment or an organisation’s private deployment. Replacing a documentation number with a private-use number does not make a tutorial safer for every reader; it may substitute the reader’s own internal identity into the example.
This distinction should survive in data models. One boolean named reserved is too coarse. A validator needs to know the reservation class, the permitted environment, the authority that supplied the rule, the registry snapshot date and the consequence of a match. A documentation ASN in a Markdown example is expected. The same value in a production local-AS field is a release blocker. A private-use ASN in a laboratory may be intentional, while its appearance in a global AS path demands a different response.
Collapsing these cases creates bad automation. A generic “strip reserved ASNs” feature could remove evidence that should instead cause a failed deployment. A generic “allow non-public numbers” rule could admit documentation values as live identity. The policy has to preserve purpose, not merely numeric range.
Validation must follow the value
The earliest useful control sits with the document author. Examples should use the RFC 5398 blocks deliberately and say that they are documentation-only. Source repositories can label fixtures and maintain allowlists for contexts where those values are expected. This makes the example’s intent machine-readable before it is copied.
The next control is generation. Configuration systems should retain provenance from source fragment to rendered line. A rendered local-AS or remote-AS value should be traceable to an inventory object or an approved parameter, not merely to a literal embedded in a sample. If a documentation ASN reaches a field that asserts production identity, generation should fail with the source location and applicable registry rule.
Review remains valuable but cannot carry the whole burden. The numbers look plausible, and a reviewer may be concentrating on policy order, authentication or maintenance timing. Static checks should scan structured values after templating as well as the source text before templating. Otherwise concatenation, defaults or environment substitution can evade a simple search.
Production admission is the authoritative boundary. It should evaluate the fully rendered configuration against the intended device, role and environment. The decision record should include the detected ASN, field semantics, rule version, IANA evidence and disposition. “Lint passed” proves that one earlier representation was examined; it does not prove that the device received the same representation.
Finally, observed state closes the loop. Configuration acceptance is not evidence that no documentation ASN appears in originated or propagated paths. Route telemetry, neighbour state and exported configuration can show what took effect. The result should be correlated with the change that introduced it, without promoting an observation of a documentation value into proof that a real autonomous system exists.
A sighting is a clue, not an entity
When 64496 or 65536 appears in telemetry, analysts may be tempted to enrich it like a normal network identity. That is the wrong default. The registry says the value is a documentation token. Its appearance can indicate a lab feed, synthetic monitoring, anonymised teaching data, parser test, copied configuration or an actual control failure. The number alone does not choose among them.
The first response is classification. Which collector saw it? Was the feed explicitly synthetic? Did the value occur in configuration, an AS path, an alert payload, a screenshot or prose? Does the timestamp align with a test window? What device and neighbour supplied the observation? Was the route exported beyond the intended boundary?
Only then should the organisation decide whether it has an operational incident. A documentation value in a closed conformance test is expected. The same value configured as a production local AS is a defect even if no route escaped. Its appearance on an external session adds exposure but does not retroactively create a legitimate ASN holder.
This is a small example of a larger intelligence discipline: registries define categories, observations describe events, and neither should be silently converted into an entity claim. A dashboard that labels a documentation ASN as an operator manufactures certainty from a token chosen precisely not to identify one.
The control chain is broader than routers
The likely escape path includes documentation portals, examples in tickets, copied snippets, infrastructure repositories, CI variables, device templates, approval systems and deployment tools. A router-side check is useful, but it sees the error late. Leadership should make the boundary visible across this chain.
Repositories can distinguish sample directories from deployable modules. CI can permit RFC 5398 values only in test scopes. Inventory systems can require public allocation evidence or an approved private-use policy for production AS fields. Change systems can display reservation class next to the numeric value. Device admission can reject documentation ranges. Telemetry can detect any later appearance.
Each stage produces a different receipt. A source scan proves that known literals were absent or confined. A template test proves how one input rendered. Inventory proves what identity was approved. Admission proves what configuration was allowed. Telemetry proves what was observed. No one receipt substitutes for all the others.
This layered design also reduces false alarms. Documentation values are supposed to appear in documents and tests. Controls that ignore context will train teams to dismiss alerts. Controls that understand environment can be permissive in a fenced fixture and uncompromising at the production edge.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
