nanog mailing list archives
Re: Bogon filtering (don't ban me)
From: Cliff Albert <cliff () oisec net>
Date: Sun, 5 Dec 2004 22:06:08 +0100
On Sun, Dec 05, 2004 at 09:52:02PM +0100, Iljitsch van Beijnum wrote:
<http://www.cymru.com/Documents/secure-bgp-template.html>Note though that so far, nobody has tried to inject bogon routes into the global routing table just so packets from bogon sources wouldn't be filtered. The reason we want this is because of address space hijacking (such as done by spammers) and configuration mistakes. So filtering at the /8 level as in the document linked above isn't really going to buy you much in practice.
/8 le /32 still stands for /8 and more-specifics as I remember ? :) Secondly not everything is about security but also about keeping routing tables clean and useful, as more people noticed today. Filtering bogons away is just an extra step in making sure that you transport real traffic instead of bogus traffic of which you are 100% sure that it's *useless* traffic. uRPF will fix it for your own network, but filtering bogon routes away in BGP will also make your downstream a happier place. The only argument from you I have seen against bogon filtering is the fact that the lists aren't updated by certain parties. -- Cliff Albert <cliff () oisec net>
Current thread:
- Re: Bogon filtering (don't ban me), (continued)
- Re: Bogon filtering (don't ban me) william(at)elan.net (Dec 05)
- Re: Bogon filtering (don't ban me) Joe Abley (Dec 05)
- Re: Bogon filtering (don't ban me) Joe Maimon (Dec 05)
- Re: Bogon filtering (don't ban me) william(at)elan.net (Dec 05)
- Re: Bogon filtering (don't ban me) Iljitsch van Beijnum (Dec 05)
- Re: Bogon filtering (don't ban me) Rob Thomas (Dec 05)
- Re: Bogon filtering (don't ban me) Jørgen Hovland (Dec 05)
- Re: Bogon filtering (don't ban me) Mikael Abrahamsson (Dec 05)
- Re: Bogon filtering (don't ban me) Patrick W Gilmore (Dec 05)
- Re: Bogon filtering (don't ban me) Iljitsch van Beijnum (Dec 05)
- Re: Bogon filtering (don't ban me) Cliff Albert (Dec 05)
- Re: Bogon filtering (don't ban me) Iljitsch van Beijnum (Dec 05)
- Re: Bogon filtering (don't ban me) Sean Donelan (Dec 05)
- Re: Bogon filtering (don't ban me) Rob Thomas (Dec 05)
- Re: Bogon filtering (don't ban me) Michael . Dillon (Dec 06)
- Re: Bogon filtering (don't ban me) Patrick W Gilmore (Dec 06)
- Re: Bogon filtering (don't ban me) Rob Thomas (Dec 05)
- Re: Bogon filtering (don't ban me) Cliff Albert (Dec 05)
- Re: Bogon filtering (don't ban me) James (Dec 05)
- Re: Bogon filtering (don't ban me) Suresh Ramasubramanian (Dec 05)