Revised Validation Procedure for BGP Flow Specifications

Document Type Replaced Internet-Draft (individual)
Authors Jim Uttaro  , Clarence Filsfils  , Prodosh Mohapatra  , David Smith 
Last updated 2012-11-05 (latest revision 2012-05-15)
Replaced by RFC 9117
Stream (None)
Intended RFC status (None)
Expired & archived
plain text pdf htmlized bibtex
Stream Stream state (No stream defined)
Consensus Boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Replaced by draft-ietf-idr-bgp-flowspec-oid
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


This document describes a modification to the validation procedure defined in RFC 5575 for the dissemination of BGP flow specifications. RFC 5575 requires that the originator of the flow specification matches the originator of the best-match unicast route for the destination prefix embedded in the flow specification. This allows only BGP speakers within the data forwarding path (such as autonomous system border routers) to originate BGP flow specifications. Though it is possible to disseminate such flow specifications directly from border routers, it may be operationally cumbersome in an autonomous system with a large number of border routers having complex BGP policies. The modification proposed herein enables flow specifications to be originated from a centralized BGP route controller.


Jim Uttaro (
Clarence Filsfils (
Prodosh Mohapatra (
David Smith (

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)