Independent network architecture and cyber security consultancy London · Essex · Kent · UK & Europe
Network architecture service

BGP architecture and routing policy

Multi-homing, peering, traffic engineering, filtering, RPKI, communities and controlled migration of live routing platforms.

BGP sessions can remain established while commercial cost, resilience and routing risk quietly increase. Good routing architecture makes path selection, failover and route acceptance intentional.

What the service covers

  • Transit, peering and multi-homing architecture
  • Local preference, MED, communities and traffic engineering
  • Inbound and outbound prefix filtering
  • RPKI origin validation, IRR and as-set review
  • Prefix limits, max-prefix behaviour and route-leak controls
  • IPv4 and IPv6 policy parity
  • Migration planning, validation and rollback

Who it is for

This work is designed for ISPs, MSPs, datacentres, SaaS platforms and larger organisations operating their own ASN or depending on multiple carriers.

How an engagement works

The work begins with a current-state review of sessions, route tables, filters, communities, traffic patterns and failure history. The resulting design defines policy, acceptance criteria, implementation stages and tests. Matthew can remain involved through the change window and operational handover.

What should a BGP review deliver?

A useful review should leave you with a documented policy, explicit route acceptance rules, predictable backup behaviour, IPv6 parity, validation evidence and a migration plan that your engineers can operate.

Discuss the next step

Need senior input on a live network, planned migration or difficult design?

Book a £200 consultation