nanog mailing list archives

Re: Tier 2 ingress filtering


From: Alejandro Acosta <alejandroacostaalamo () gmail com>
Date: Fri, 29 Mar 2013 22:51:58 -0430

Hi,

On 3/29/13, Patrick <nanog () haller ws> wrote:
On 2013-03-29 14:49, William Herrin wrote:
I've long thought router vendors should introduce a configuration
option to specify the IP address from which ICMP errors are emitted
rather than taking the interface address from which the packet causing
the error was received.

Concur. An 'ip(v6)? icmp source-interface loop0' sure beats running 'ip
unnumbered loop0' everywhere. ;)

Why do you think it will be better?, can you explain?
So far I can only think in a more difficult troubleshooting if this
idea/feature gets spread.

I guess based in the scenario where the output interface can not reach
Internet sounds as a practical solution however for sure the output
interface is reachable inside the provider network.

Thks,

Alejandro,





Current thread: