nanog mailing list archives
Re: nLayer IP transit
From: Saku Ytti <saku () ytti fi>
Date: Thu, 1 Aug 2013 09:13:59 +0300
On (2013-08-01 10:00 +1000), Mark Tees wrote:
I remember reading a while back that customers of nLayer IP transit services could send in Flowspec rules to nLayer. Anyone know if that is true/current?
Anyone planning to do this might want to be aware that the validation process of flowspec does not limit actions. In practice this means, if you do run flowspec to your customers, your customers likely can inject traffic to arbitrary VRFs. I feel RFC should have explicitly stated valid actions for validation process, which operator MAY change, and any other action MUST cause validation process to fail. -- ++ytti
Current thread:
- nLayer IP transit Mark Tees (Jul 31)
- Re: nLayer IP transit Patrick W. Gilmore (Jul 31)
- Re: nLayer IP transit Saku Ytti (Jul 31)
- Re: nLayer IP transit Alexandre Snarskii (Aug 01)
- Re: nLayer IP transit Saku Ytti (Aug 01)
- Re: nLayer IP transit Alexandre Snarskii (Aug 01)
- Re: nLayer IP transit Richard A Steenbergen (Aug 01)
- Re: nLayer IP transit Mark Tees (Aug 01)
- Re: nLayer IP transit Richard A Steenbergen (Aug 02)
- Re: nLayer IP transit Mark Tees (Aug 01)