Skip to main content
RunBook Academy

← All checklists in VyOS

Quarterlyvyos-route-policy

Route Policy Review Checklist

10 items ·5 critical ·1 warn ·4 info

Route Policy Review Checklist

Checklist discipline. Every item is meant to be answered yes / no with evidence. Items marked critical are non-negotiable; items marked warn are judgement calls; items marked info are baseline expectations.

Items

  • Every BGP peer has an explicit inbound filter (severity: critical)
  • Every BGP peer has an explicit outbound filter (severity: critical)
  • Outbound filter blocks internal / RFC1918 / unused prefixes (severity: critical)
  • Prefix-list names reflect intent (severity: info)
  • Route-map sequence numbering follows the design (severity: info)
  • Policy references verified (severity: info)
  • No overly broad matches (severity: critical)
  • Redistribution tagged / filtered to prevent loops (severity: critical)
  • Policy validated in a canary before production (severity: warn)
  • Quarterly review of every filter for staleness (severity: info)

Severity legend

  • info: baseline expectation
  • warn: judgement call; production-grade depends on context
  • critical: non-negotiable; a missed critical item is a release blocker

Evidence retention

The completed checklist is evidence for the change ticket, the audit, and the post-incident review. Store it where it can be recovered if the router is lost.

Critical5 items

Warning1 item

Info4 items