Summary
- RFC 9825 lets OSPF attach one or more 32-bit administrative identifiers to every supported prefix type. It standardizes the carrier while leaving each tag's precise use to local policy.
- Tag order has no semantic meaning, yet an ABR must preserve it when propagating multiple values so routers with smaller limits retain a consistent first subset. Consistency is not completeness.
- Summarization, equal-cost contributors, BGP-LS projection and management access each create a new evidence boundary. A received tag is not proof of a common dictionary, a policy match, a forwarding change or a service result.
The first two values were correct and the decision was still wrong
The opening is a constructed case, not a reported deployment. Its point is the shape of the receipt. A team can prove byte order and still fail to prove that the full administrative statement crossed the boundary. If the dashboard records only “tags preserved”, the missing third value disappears inside a successful check.
RFC 9825, Extensions to OSPF for Advertising Prefix Administrative Tags, gives OSPFv2 and OSPFv3 a common way to associate multiple administrative tags with prefixes. The RFC Editor record and IETF Datatracker record identify it as a Standards Track RFC published in July 2025. Its history, references, referenced-by graph and errata surface establish public document context. They do not establish support in a named router, use by an operator or a forwarding outcome.
Earlier OSPF encodings allowed one tag for AS-external and Not-So-Stubby-Area prefixes. RFC 9825 uses the flexible prefix containers supplied by RFC 7684 for OSPFv2 and RFC 8362 for OSPFv3 to extend tags to all supported prefix types. It also allows the mechanism within the SRv6 Locator LSA defined by RFC 9513. The base protocol contexts remain OSPFv2 in RFC 2328 and OSPFv3 in RFC 5340.
The new sub-TLV carries a variable list of one or more unsigned 32-bit integers. The length must be a positive multiple of four octets. If it is zero or misaligned, a receiver must ignore the sub-TLV and should log the reception subject to rate limiting. The current IANA OSPFv2 parameters assign sub-TLV 13, while the OSPFv3 registry records 39 for Extended LSAs and 6 for SRv6 Locator LSAs.
Those allocations coordinate syntax. They do not allocate the operational meaning of a tag. RFC 9825 says the precise usage is outside its scope. It lists redistribution control, selective priority for faster convergence or forwarding-plane installation, and selective Loop-Free Alternative protection as possible applications. The same integer can matter only through a dictionary and policy known to the consuming system.
Order is a compatibility device, not a hierarchy of meaning
A supporting router must be able to advertise and interpret at least one tag for all prefix types. Supporting multiple tags, and carrying multiple tags between areas, is optional. The maximum is explicitly a local implementation matter tied to the applications that use the values.
The protocol then imposes two rules that look contradictory until their purposes are separated. First, tag order must not change meaning: each value is an autonomous identifier, and placing tag A before or after tag B should not alter either one. Second, when an ABR propagates several tags, it must preserve their order. That second rule gives limited implementations a consistent view. If several routers accept only the first two values, preserving order makes them agree on which two they see.
Agreement about a subset is useful. It is not evidence that the subset was sufficient. The specification's default management behavior is to advertise or propagate the lesser of the associated tag count and the implementation maximum. Nothing in that rule negotiates an application's minimum required set. An operator who gives a late-position tag a critical action has created a dependency on the capacity of every relevant transition.
The legacy external-route field sharpens the point. For an AS-external or NSSA prefix, the old encoding must carry the first tag; further values may use the new sub-TLV. That helps an older implementation retain a stable first value. It does not promote the first value into a universal primary policy or certify that later values were optional.
An ABR should propagate administrative tags when it originates inter-area summaries, unless local policy inhibits propagation. The same qualified rule applies when an NSSA border router translates routes; RFC 3101 supplies the wider NSSA translation context. A receiving system therefore needs to distinguish absence caused by original configuration, an implementation maximum, unsupported extension, local suppression, summary construction or path selection. One null field cannot carry those explanations.
A summary is a new statement, not a sack of component labels
RFC 9825 says component-route tags should not be propagated into configured area ranges, NSSA ranges or configured aggregates of redistributed routes. Implementations should instead let operators configure multiple tags on the summary.
This is not a minor exception. A summary prefix speaks about a larger set than any one component. Copying a component's label upward may assign its administrative treatment to destinations for which that treatment was never approved. Taking the union of every component can create an equally misleading composite. The standard chooses a cleaner control boundary: the summary receives its own deliberate tag statement.
The resulting audit must show two events. First, component tags were not inherited. Second, an authorized principal assigned the summary's replacement list. If a system records only the final values, an intentional reclassification, a default, a stale configuration and an operator omission can look identical.
The older IS-IS mechanism in RFC 5130 provides the predecessor context for policy control using administrative tags. RFC 9825 draws from that model, but neither document turns an opaque identifier into a self-executing policy. The carrier remains deliberately thin.
Equal cost does not produce equal tag provenance
Equal-cost multipath creates a different compression. Several LSAs can contribute paths to one OSPF route while carrying different tag lists. An ABR must associate the propagated route with tags from one contributing LSA. If it supports multiple tags, it may associate values from several contributors up to its maximum. RFC 9825 recommends adding contributors in ascending order of the LSA originator Router-ID.
The final list therefore cannot be read as “all equal-cost paths share these attributes”. It may mean “these were taken from the selected contributor”, or “these were accumulated from contributors until a limit was reached”. The receipt needs the contributing LSA identities, the selection order, the implementation maximum and the emitted list. Without those fields, two conforming routers can expose different administrative evidence while offering the same route cost.
The distinction matters whenever a tag activates protection, prioritization or redistribution. A control plane can keep equal cost while the action set changes with the chosen contributor. A data-plane check then remains necessary: neither equal cost nor tag presence proves which next hop carried a packet.
BGP-LS makes the label more visible, not more authoritative
RFC 9825 allows OSPF administrative tags to be advertised through the IGP Route Tag TLV defined by RFC 9552. That makes the information available to BGP-LS consumers such as controllers and analytic systems. It also adds another projection.
A BGP-LS consumer may receive exactly what its producer exported and still lack facts about what an intermediate ABR discarded, which ECMP contributor supplied the tags, which summary configuration replaced component labels or which local dictionary gives the numbers meaning. Visibility expands; authority does not. A controller should not infer a completed route-policy action merely because the identifier reached its topology database.
This is the same separation emphasized by Heng Lu's Reality Layers: configured intent, advertised symbol, received state, executed rule and observed effect belong to different records. Running-Code Primacy demands evidence from the systems that actually interpreted and acted, while Minimum Initial Specification explains the value of a thin common carrier that does not annex every future policy choice.
The management plane can change the dictionary's carrier
RFC 9825 includes a YANG model for interface-local prefix tags, area-range tags, local-RIB next hops and LSA database state. It requires secure management transports and mutual authentication, and points to RFC 8341 for restricting NETCONF and RESTCONF operations and content.
That access boundary is operationally important. Authorization to edit a tag node is not authorization for every business or service consequence associated with the route. Conversely, read access can disclose link-state information useful to an attacker. The model therefore needs separate records for who changed configuration, what list the routing process originated, what neighbours received and what policy later executed.
The security section provides a concrete mechanism without claiming an incident. If tags drive redistribution and an attacker changes them, required routes may be withheld from another domain, producing subtle denial of service, or routes may be advertised where they should not be, creating a routing vulnerability. The causal path contains several verbs: obtain management or protocol influence, alter a label, make a policy match or miss, change an advertisement, change forwarding and affect service. Evidence for the first verb cannot stand in for the last.
The useful receipt is a sequence, not a green badge
For each policy-bearing prefix, the operator needs a versioned tag dictionary with owner, scope and expiry; the authorized configuration change; the exact LSA and ordered values at origin; every ABR's input, supported maximum, propagation policy and output; ECMP contributor selection; summary non-inheritance plus replacement configuration; BGP-LS export; policy rule version and match; resulting advertisements, RIB and FIB state; and a data-plane and application observation.
The list is long because “tag preserved” compresses too much. RFC 9825 solves a coordination problem: several implementations can carry interoperable identifiers, and constrained implementations can retain a consistent subset. It does not solve the organization's authority problem. Only a reconciled chain can show that the intended principal defined a meaning, the running network retained enough of it, the proper policy consumed it and the claimed outcome actually followed.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
