# Negotiate each BGP address family before exchanging reachability

> Use RFC 4760 — Multiprotocol Extensions for BGP-4 to review this narrow operational decision without extending the source beyond its stated scope.

- Canonical URL: https://update.dsesecurity.com/updates/negotiate-each-bgp-address-family-before-exchanging-reachability/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-08-27T12:16:21+00:00
- Modified: 2026-08-27T12:53:57+00:00
- Last reviewed by DSE: 2026-08-26
- Resource type: Playbook
- DSE priority: Advisory
- Topics: IT, Networks & Infrastructure
- Reading time: 3 minutes

## What you need to know

Use RFC 4760 — Multiprotocol Extensions for BGP-4 to review this narrow operational decision without extending the source beyond its stated scope.

## Potentially affected

Teams, systems, services, or facilities within the stated scope of RFC 4760 — Multiprotocol Extensions for BGP-4

## DSE recommendation

Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.

## Article

Keep this document to one review outcome: Negotiate each BGP address family before exchanging reachability. Only the official source and traced locations below supply facts. Confirm applicability before acting.

## Source fact:

The official [RFC 4760 — Multiprotocol Extensions for BGP-4](https://www.rfc-editor.org/rfc/rfc4760.html) from RFC Editor / Internet Engineering Task Force supports the following bounded statements:

- MP_REACH_NLRI advertises reachable prefixes and their next hop, with AFI and SAFI identifying the address-family semantics. The research record locates this support at Section 3 (Multiprotocol Reachable NLRI – MP_REACH_NLRI).

- MP_UNREACH_NLRI withdraws multiple routes for the AFI and SAFI carried in that attribute. The research record locates this support at Section 4 (Multiprotocol Unreachable NLRI – MP_UNREACH_NLRI).

- Bidirectional route exchange for an AFI/SAFI requires both peers to advertise support for that exact tuple through BGP Capability Advertisement. The research record locates this support at Section 8 (Use of BGP Capability Advertisement).

These statements are the factual basis for this document. Do not extend them into a broader assurance. Review address plans, interfaces, routes, peers, protocol roles, timers, middleboxes, and intended failure domains only where the source and recorded environment align.

## What the source does not establish

This RFC evidence supports only the named network-protocol decision; it does not select vendor settings, topology, capacity, or an acceptable failure mode. A correct source interpretation can still be inapplicable to a particular design. Confirm DNS, Active Directory authentication, PKI, time, routing policy, transport reachability, and monitoring, ownership, and change authority instead of treating documented behavior as a deployment guarantee.

## Applicability questions

- For source statement 1 at Section 3 (Multiprotocol Reachable NLRI – MP_REACH_NLRI), which observable configuration, record, or test can confirm applicability here?

- For source statement 2 at Section 4 (Multiprotocol Unreachable NLRI – MP_UNREACH_NLRI), which observable configuration, record, or test can confirm applicability here?

- For source statement 3 at Section 8 (Use of BGP Capability Advertisement), which observable configuration, record, or test can confirm applicability here?

- Within address plans, interfaces, routes, peers, protocol roles, timers, middleboxes, and intended failure domains, which versions, roles, and configuration states define the review population?

- Could DNS, Active Directory authentication, PKI, time, routing policy, transport reachability, and monitoring invalidate the test, hide a failure, or change applicability?

- Who owns the decision, and which observation requires stopping, escalation, or rollback?

## DSE recommendation:

DSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of address plans, interfaces, routes, peers, protocol roles, timers, middleboxes, and intended failure domains, observed and expected states, owner, and reason for deviation.

An implementation decision needs an owner, approved window, prechecks, observable outcome, stop authority, and rollback path. Validate DNS, Active Directory authentication, PKI, time, routing policy, transport reachability, and monitoring before and after the test, and store only sanitized operational evidence.

## Verification and evidence

Evidence should let another reviewer reproduce this decision. Retain observations beside the traced locations Section 3 (Multiprotocol Reachable NLRI – MP_REACH_NLRI); Section 4 (Multiprotocol Unreachable NLRI – MP_UNREACH_NLRI); Section 8 (Use of BGP Capability Advertisement). Favor configuration snapshots, route or neighbor state, packet captures, counters, topology records, and controlled failover results, linked to stable identifiers, time, and operator.

Close the review only when the evidence, exception handling, resulting action, and after-state are linked. Schedule a new review after material technical, organizational, incident, or source changes; today’s observation is not a continuing guarantee.

## Official references

- [RFC 4760 — Multiprotocol Extensions for BGP-4](https://www.rfc-editor.org/rfc/rfc4760.html) — RFC Editor / Internet Engineering Task Force

## Primary reference

- Name: RFC 4760 — Multiprotocol Extensions for BGP-4
- Authority: www.rfc-editor.org
- URL: https://www.rfc-editor.org/rfc/rfc4760.html
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Negotiate each BGP address family before exchanging reachability,” DSE Security, https://update.dsesecurity.com/updates/negotiate-each-bgp-address-family-before-exchanging-reachability/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
