Peering

A direct interconnection between two networks so they can exchange traffic with each other, rather than sending it through a third-party transit provider.

Peering is an arrangement in which two independent networks, such as internet service providers, content providers or large organisations, connect directly and exchange traffic destined for each other. The link may be private or run across an internet exchange point. Peering between providers is commonly settlement-free, in contrast to transit, where one network pays another to carry its traffic to the rest of the internet. Cloud platforms use the same word for connecting two virtual private clouds.

Peering sits at the network edge, and its security issue is trust in routing information. Peers exchange routes, usually with the Border Gateway Protocol, and the routes a peer announces are accepted as input unless they are filtered or validated. A false or mistaken announcement can therefore redirect traffic for someone else’s addresses. The controls are prefix filtering, which accepts only the ranges a peer is entitled to announce, and route origin validation (RFC 6811), which checks announcements against the Resource Public Key Infrastructure. Ingress and egress filtering handle traffic, not routes.

Exam relevance: a scenario in which traffic for an organisation’s addresses is suddenly routed elsewhere is likely to point to an unfiltered route announcement at a peering or transit point. Candidates are expected to see that route filtering, not encryption, is the matching control.