Skip to main content
RunBook Academy

← All checklists in VyOS

Quarterlyvyos-route-leak-prevention

BGP Route Leak Prevention Checklist

9 items ·3 critical ·3 warn ·3 info

BGP Route Leak Prevention Checklist

Checklist discipline. Every item is meant to be answered yes / no with evidence. Items marked critical are non-negotiable; items marked warn are judgement calls; items marked info are baseline expectations.

Items

  • Outbound filter on every eBGP peer (severity: critical)
  • Outbound filter blocks RFC1918 and other internal prefixes (severity: critical)
  • Outbound filter is default-deny with explicit allows (severity: critical)
  • IRR / RPKI data consulted when building filters (severity: warn)
  • max-prefix on every peer limits blast radius (severity: warn)
  • Route-leak detection monitoring configured (severity: info)
  • Route-leak response runbook ready (severity: info)
  • Quarterly outbound filter review (severity: info)
  • Outbound filter validated in canary for every change (severity: warn)

Severity legend

  • info: baseline expectation
  • warn: judgement call; production-grade depends on context
  • critical: non-negotiable; a missed critical item is a release blocker

Evidence retention

The completed checklist is evidence for the change ticket, the audit, and the post-incident review. Store it where it can be recovered if the router is lost.

Critical3 items

Warning3 items

Info3 items