Implementing BGP Edge Hygiene with IRR and RPKI at a PCI-Regulated Fintech
This technical article outlines the Border Gateway Protocol (BGP) security measures implemented by a national fintech company to protect payment traffic and maintain PCI DSS compliance. The author emphasizes that BGP edge hygiene is a critical perimeter control, not just a routing function, involving collaboration between security, compliance, and network teams. The piece details a threat model comprising five key risks: route hijacks, route leaks, sub-prefix hijacks, BGP optimizer leaks, and operational errors. To mitigate these, the organization deployed five layers of filters on external eBGP sessions. The text specifically describes Layer 1 (max-prefix limits to prevent table crashes during leaks) and Layer 2 (AS-path filters to reject routes containing the company's own ASN or private ASNs). Configuration examples for Cisco IOS-XR and Junos are provided. The approach successfully reduced routing-related incidents to near zero over a year, highlighting the importance of automated filtering and strict validation in preventing regulatory events and data exposure.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection