Summary
- RFC 7606 replaces many session-reset responses to malformed BGP UPDATE attributes with treat-as-withdraw: remove the routes carried by the bad UPDATE from Adj-RIB-In while preserving the adjacency and unrelated valid routes.
- The response is deliberately bounded. If the receiver cannot parse the relevant NLRI reliably, or an attribute-specific rule requires a stronger action, it must still reset the session or disable the affected AFI/SAFI.
One bad update used to withdraw good routes too
BGP distributes reachability incrementally. A session may carry hundreds of thousands of valid paths accumulated over time. Yet RFC 4271's general response to a malformed attribute was a NOTIFICATION and a closed connection. The bad UPDATE vanished, but so did every sound route whose current copy depended on that session. Re-establishment and reconvergence then spread the cost to destinations unrelated to the original defect.
Optional transitive attributes made the asymmetry worse. A router that did not recognize an attribute could propagate it without checking its value. The defect might travel and fan out before reaching software that understood it. The recognizing receiver could then reset an innocent downstream adjacency rather than the session nearest the source. One malformed object could therefore multiply into many withdrawals.
RFC 7606 changes the unit of failure. Treat-as-withdraw handles the routes in the malformed UPDATE as if they had been explicitly withdrawn. They are removed from Adj-RIB-In, but the BGP session remains established and valid routes learned earlier remain available. The receiver exercises a narrower power: quarantine the identifiable route set rather than destroy the whole relationship.
The parser defines the limit of selective authority
Selective handling is safe only when the receiver knows what it is removing. RFC 7606 requires treat-as-withdraw for specified errors involving ORIGIN, AS_PATH, NEXT_HOP, MULTI_EXIT_DISC and LOCAL_PREF, and for missing well-known mandatory attributes, unless a more specific rule applies. Other cases can call for attribute discard, AFI/SAFI disable or session reset.
The crucial boundary is reachability parsing. If the NLRI, MP_REACH_NLRI or MP_UNREACH_NLRI cannot be decoded well enough to identify the routes, the receiver cannot honestly claim to have contained the error. The stronger RFC 4271 or multiprotocol response still applies. The standard does not turn resilience into permission to guess.
RFC 7607 supplies a concrete case. Routes containing AS 0 in specified path attributes are malformed and must be handled through the relevant revised procedures. That rule defines what is invalid; RFC 7606 defines how the receiving system limits the consequence when the affected routes can be identified.
Preservation moves cost rather than erasing it
Keeping the session protects unrelated reachability, but the affected destinations may become unreachable or take a worse path. On an IBGP session, different routers may react at different points and create inconsistent routing, including long-lived forwarding loops or black holes. The standard judges that risk generally less damaging than a session reset, not harmless.
Treat-as-withdraw is also not the same as ignoring the UPDATE. Silently discarding an incremental update could leave a previously announced invalid route installed. Withdrawal changes routing state explicitly. That difference makes the action visible in the control plane and limits stale authority.
The evidence obligation therefore grows as the blast radius narrows. RFC 7606 recommends diagnostic facilities and says their minimum capability should log the affected NLRI and retain the entire malformed UPDATE for analysis; this is operational guidance rather than an uppercase normative MUST. Operators should trace IBGP defects back to the ingress router and filter them there. A session that stays green while routes vanish is not an operational success unless the loss can be explained, attributed and reversed.
Evidence and limits
RFC 7606 supports the error-response hierarchy, parser boundary, operational risks and logging requirement. RFC 4271 provides the base session behavior; RFC 7607 demonstrates AS 0 handling; IANA confirms UPDATE Message Error code 3. The leadership framing is an inference from those rules. These sources do not prove deployment, a defect or an outage at any named operator, and they do not guarantee that selective withdrawal improves every incident.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
