{"id":4510,"date":"2026-09-28T17:09:31","date_gmt":"2026-09-28T11:39:31","guid":{"rendered":"https:\/\/cybx.in\/blog\/?p=4510"},"modified":"2026-09-28T17:09:32","modified_gmt":"2026-09-28T11:39:32","slug":"how-to-secure-bgp","status":"publish","type":"post","link":"https:\/\/cybx.in\/blog\/how-to-secure-bgp\/","title":{"rendered":"How to Secure BGP?"},"content":{"rendered":"\n<meta name=\"description\" content=\"BGP sits quietly in the background until something goes wrong. Then everyone notices. The Border Gateway Protocol decides how traffic moves between autonomou\">\n<meta property=\"og:title\" content=\"How to Secure BGP\">\n<meta property=\"og:description\" content=\"BGP sits quietly in the background until something goes wrong. Then everyone notices. The Border Gateway Protocol decides how traffic moves between autonomou\">\n<meta name=\"twitter:card\" content=\"summary_large_image\">\n<meta name=\"twitter:title\" content=\"How to Secure BGP\">\n<meta name=\"twitter:description\" content=\"BGP sits quietly in the background until something goes wrong. Then everyone notices. The Border Gateway Protocol decides how traffic moves between autonomou\">\n\n\n<p>BGP sits quietly in the background until something goes wrong. Then everyone notices. The Border Gateway Protocol decides how traffic moves between autonomous systems, so a bad route announcement can send traffic somewhere it shouldn&#8217;t go. Securing BGP means making those route decisions harder to abuse and easier to spot when something looks wrong.<\/p>\n<h2>Start With BGP Session Security<\/h2>\n<p>A good first step is controlling who can even establish a BGP session with your router. Don&#8217;t leave that door open wider than it needs to be.<\/p>\n<p>Use authentication between BGP peers, especially with external peers. TCP MD5 has been widely used for this purpose, while TCP Authentication Option, or TCP-AO, provides a newer approach where supported. The exact option depends on your network equipment and software.<\/p>\n<p>Access control matters too. Your edge router should only accept BGP connections from known peer addresses. If a random system can reach the BGP service, you&#8217;re already making life easier for an attacker.<\/p>\n<h3>Protect the Routing Process<\/h3>\n<p>\u2022 An explicit prefix filter is boring, which is exactly why I like it. Boring security controls tend to stay useful.<\/p>\n<p>\u2022 RPKI validation adds another check by verifying whether a network is authorised to originate a prefix, although it doesn&#8217;t solve every BGP security problem.<\/p>\n<p>\u2022 Maximum-prefix limits put a ceiling on what a peer can announce, so one bad session doesn&#8217;t suddenly fill your routing table.<\/p>\n<h2>Stop Route Leaks Before They Spread<\/h2>\n<p>A route leak happens when routing information travels somewhere it shouldn&#8217;t. The result can be traffic taking an unexpected path, sometimes across networks that were never meant to carry it.<\/p>\n<p>Strong import and export policies reduce this risk. Don&#8217;t treat a provider, customer, and peer as if they all have the same routing relationship. They don&#8217;t.<\/p>\n<p>AS path filters are useful here because they let you check the autonomous systems appearing in a route&#8217;s path. Community-based policies can add another layer of control, provided they&#8217;re designed carefully.<\/p>\n<h3>RPKI Deserves a Place Here<\/h3>\n<p>RPKI is one of the better tools available for dealing with route origin problems. A network operator creates a Route Origin Authorisation that says which autonomous system is permitted to originate a prefix. Routers that perform RPKI validation can then classify received routes based on that information.<\/p>\n<p>It isn&#8217;t magic. A valid RPKI result doesn&#8217;t prove that the entire path is trustworthy. Still, ignoring it when your equipment supports it feels like leaving a useful lock sitting on the table.<\/p>\n<h2>Monitor BGP Like Something Important<\/h2>\n<p>Security doesn&#8217;t end after the filters are configured. Watch the routing table and look for changes that don&#8217;t fit normal behaviour.<\/p>\n<p>\u2022 Unexpected origin changes should get a second look, especially for important prefixes.<\/p>\n<p>\u2022 Route count suddenly jumps? That&#8217;s worth investigating before users start reporting strange connectivity.<\/p>\n<h2>Keep BGP Configuration Tight<\/h2>\n<p>Finally, protect the routers themselves. Limit management access and keep network operating systems updated. Remove old peer configurations instead of letting them sit around forever.<\/p>\n<p>Also review filters after network changes. A policy that made perfect sense two years ago can become a hole after one provider changes its setup.<\/p>","protected":false},"excerpt":{"rendered":"<p>BGP sits quietly in the background until something goes wrong. Then everyone notices. The Border Gateway Protocol decides how traffic&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-4510","post","type-post","status-publish","format-standard","hentry","category-learn"],"_links":{"self":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts\/4510","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/comments?post=4510"}],"version-history":[{"count":1,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts\/4510\/revisions"}],"predecessor-version":[{"id":4560,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/posts\/4510\/revisions\/4560"}],"wp:attachment":[{"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/media?parent=4510"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/categories?post=4510"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybx.in\/blog\/wp-json\/wp\/v2\/tags?post=4510"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}