Delta.BG · AS8860

BGP Community Support for AS8860 Customers

Delta.BG provides a set of BGP communities that let our BGP customers steer how their prefixes are announced by AS8860 — without opening a ticket and without manual intervention on our side. This page documents every community we accept from customers and every informational community we attach to the routes you receive from us.

1.Format and general rules

All traffic-engineering communities of AS8860 are BGP Large Communities (RFC 8092) in the provider-owned namespace:

8860:<function>:<target>

The <function> field selects the action; the <target> field selects which neighbor of AS8860 the action applies to. Unlike encoded schemes used by some carriers, the target is simply the neighbor's real AS number — no lookup tables. A small set of group values (below) covers "all transits", "all peers", and similar.

Rules that always apply:

  • Action communities are accepted on customer BGP sessions only. Communities in the 8860:* namespace arriving on transit, peering or IX sessions are deleted on ingress.
  • Action communities are consumed at our edge and are not propagated beyond AS8860.
  • Informational communities (section 6) are set by us and stripped from your announcements — you can read them, you cannot inject them.
  • The well-known communities NO_EXPORT (65535:65281) and NO_ADVERTISE (65535:65282) are honoured per RFC 1997. BLACKHOLE (65535:666, RFC 7999) is honoured per section 5.
  • Prefixes must be covered by your IRR route/route6 objects and must not be RPKI-invalid — see section 8.

2.Announcement control — suppression and prepending

Attach one or more of these to a prefix you announce to us:

Community Action toward <target>
Do not announce this prefix to the target
Announce prepended (8860)
Announce prepended (8860 8860)
Announce prepended (8860 8860 8860)

Target values

<target> is either the AS number of a specific AS8860 neighbor, or a group value:

Target Meaning
<ASN> That specific neighbor of AS8860 (see table below)
0 All external BGP neighbors of AS8860
64496 All transit providers
64497 All internet exchanges and peers
64498 All other BGP customers of AS8860

Current transit providers and exchanges of AS8860 (any direct neighbor ASN is a valid target, including bilateral peers not listed here):

ASN Neighbor Role
1299 Arelion transit
174 Cogent transit
3356 Lumen transit
3257 GTT transit
6762 Telecom Italia Sparkle transit
5405 Inter.link transit
31287 IPACCT transit / regional
15669 BIX.BG route servers internet exchange
57463 NetIX route servers internet exchange
  • Suppression and prepending toward an exchange (15669, 57463) applies to the route-server session, i.e. to all peers behind that route server. To control individual peers behind a route server, use the exchange's native communities — section 4.
  • Multiple communities combine: 8860:0:174 + 8860:102:1299 is a valid set.
  • If both a suppression and a prepend target the same neighbor, suppression wins.

3.Local preference control

Default local preference classes inside AS8860 (higher wins):

Class Local preference
Customer routes (default) 400
BIX.BG peering 320
NetIX peering 300
Customer routes marked secondary 250
Transit (all providers, equal) 120
Customer routes marked backup 90

Customers can lower the preference of their own announcements:

Community Result
Local preference 250secondary: loses to any peering path, still beats transit. Use this when you peer with us at an IX and want the IX path preferred over the customer session.
Local preference 90backup: below transit, used only when no other path to your prefix exists anywhere.

4.Per-peer control at internet exchanges

We announce customer routes to the BIX.BG and NetIX route servers. Both route servers support their own control communities (do-not-announce-to-peer, announce-only-to-peer). AS8860 relays these communities transparently — set them on your announcement to us and they survive our network untouched, letting you steer individual peers behind each route server:

Exchange Namespace to use Reference
BIX.BG (AS15669) 0:<peer-asn> and related RS communities BIX.BG route-server policy
NetIX (AS57463) 57463:… standard and large forms netix.net

Example: to stop your prefix from reaching AS15169 via the BIX.BG route servers while everything else stays announced, attach the BIX RS community 0:15169 to your announcement toward AS8860.

5.Blackholing (RTBH)

If one of your hosts is under a volumetric DDoS attack, you can ask the whole of AS8860 — and our upstream providers — to discard traffic to that host:

Community Meaning
Blackhole this prefix (Delta.BG trigger)
RFC 7999 BLACKHOLE — accepted as equivalent

Conditions, strictly enforced:

  • Exact host routes only: /32 for IPv4, /128 for IPv6.
  • Only inside address space you announce to us on that BGP session (your registered blocks). A blackhole request for any other address is silently rejected.
  • Effect: traffic is discarded at every AS8860 edge router, and the host route is propagated to our transit providers with RFC 7999 (and provider-specific RTBH communities), so the attack is dropped before it reaches our network.
  • The blackhole stays active for as long as you keep announcing the tagged host route. Withdraw the announcement to restore traffic.
  • The service is enabled per customer session — contact noc@delta.bg to activate it.
Misuse of blackholing may lead to termination of the service.

6.Informational communities — what you receive from us

Every route you learn from AS8860 carries tags describing where and how we learned it. Use them to build your own inbound policy (for example: accept only Bulgarian/IX routes, or de-prefer routes we learned from transit).

Community Meaning
8860:1010:1 Route entered AS8860 in datacenter SOF1
8860:1010:2 Route entered AS8860 in datacenter SOF2
8860:1020:<id> Ingress router (11 = mx1/SOF1, 12 = mx2/SOF1, 13 = mx3/SOF2, 14 = mx4/SOF2)
8860:1030:1 Learned from an AS8860 customer
8860:1030:2 Learned from an internet exchange peer
8860:1030:3 Learned from a private peer (PNI)
8860:1030:4 Learned from a transit provider
8860:1030:5 AS8860 own / internally originated prefix
8860:1040:<asn> Learned directly from neighbor <asn>
8860:1050:1 Learned at BIX.BG
8860:1050:2 Learned at NetIX

Example use: a "peering-only" view of our table is every route tagged 8860:1030:1 or 8860:1030:2.

7.Worked examples

1. Prefer your IX path over the customer link.

You peer with us at BIX.BG and also buy a BGP customer port. Announce your prefix on the customer session with 8860:200:1 — the BIX path (LP 320) now wins over the customer path (LP 250), and the customer session still beats transit if BIX fails.

2. Pure backup link.

Announce everything on the backup session with 8860:200:0. AS8860 uses it only when no other path to your prefix exists — including via our transits.

3. Steer traffic away from one upstream.

Your inbound via Cogent is congested; you want nothing announced there and a weaker announcement via Arelion: 8860:0:174 8860:102:1299.

4. Keep a prefix regional.

Announce with 8860:0:64496 — suppressed toward all transit providers, still announced to all exchanges, peers and customers of AS8860. The prefix stays reachable inside the Bulgarian/regional peering fabric only.

5. Blackhole one attacked host.

Your web server 198.51.100.7 is under attack: announce 198.51.100.7/32 with 8860:666:0. Traffic to that host is dropped at our edges and upstream; the rest of 198.51.100.0/24 keeps working. Withdraw the /32 when the attack ends.

6. Do not announce to a single peer behind an IX.

Attach the BIX RS community 0:15169 (see section 4) — everything stays as is, except peer AS15169 at BIX.BG no longer receives the prefix via the route servers.

8.Requirements and good-to-know

  • IRR: we generate prefix filters from your AS-SET (as registered in PeeringDB / on your session order). New prefixes become accepted automatically after you register the route/route6 objects; the filters refresh several times a day.
  • RPKI: AS8860 rejects RPKI-invalid announcements on all sessions, including customer sessions. Keep your ROAs correct — a prefix whose ROA does not match its origin AS will not be accepted. Check yours at rpki-validator.ripe.net or in your RIR portal.
  • Sanity limits: IPv4 prefixes longer than /24 and IPv6 prefixes longer than /48 are not accepted (blackhole host routes per section 5 are the only exception). Every session carries a maximum-prefix limit sized to your registered address space.
  • Communities not listed on this page — including any other value in the 8860:* namespace — are deleted on ingress and have no effect.
  • This page is versioned. Changes are announced to customer NOC contacts in advance.