nanog mailing list archives

Re: IP DSCP across the Internet


From: Randy Bush <randy () psg com>
Date: Wed, 06 May 2015 14:48:40 +0900

We don't honor DSCP values that comes in via best-effort circuits
(i.e., the Internet). Although not a very strong reason, this
particular experience is one reason why.

trusting markings of any sort which you do not need is an increase in
attack, game playing, and/or bug surface.  the only thing i would pass
is ecn.

randy


Current thread: