nanog mailing list archives
Re: Stupid Question maybe?
From: Saku Ytti <saku () ytti fi>
Date: Wed, 19 Dec 2018 09:32:29 +0200
On Wed, 19 Dec 2018 at 02:55, Philip Loenneker <Philip.Loenneker () tasmanet com au> wrote:
I had a heck of a time a few years back trying to troubleshoot an issue where an upstream provider had an ACL with an incorrect mask along the lines of 255.252.255.0. That was really interesting to talk about once we discovered it, though it caused some loss of hair beforehand...
Juniper originally didn't support them even in ACL use-case but were forced to add later due to customer demand, so people do have use-cases for them. If we'd still support them in forwarding, I'm sure someone would come up with solution which depends on it. I am not advocating we should, I'll rather take my extra PPS out of the HW. However there is one quite interesting use-case for discontinuous mask in ACL. If you have, like you should have, specific block for customer linknetworks, you can in iACL drop all packets to your side of the links while still allowing packets to customer side of the links, making attack surface against your network minimal. -- ++ytti
Current thread:
- Re: Stupid Question maybe?, (continued)
- Re: Stupid Question maybe? Justin M. Streiner (Dec 18)
- Re: Stupid Question maybe? Tom Beecher (Dec 18)
- Re: Stupid Question maybe? George William Herbert (Dec 18)
- Re: Stupid Question maybe? William Herrin (Dec 18)
- Re: Stupid Question maybe? Brian Kantor (Dec 18)
- Re: Stupid Question maybe? Saku Ytti (Dec 18)
- RE: Stupid Question maybe? Naslund, Steve (Dec 18)
- RE: Stupid Question maybe? David Edelman (Dec 18)
- Re: Stupid Question maybe? Grant Taylor via NANOG (Dec 18)
- RE: Stupid Question maybe? Philip Loenneker (Dec 18)
- Re: Stupid Question maybe? Saku Ytti (Dec 18)
- Re: Stupid Question maybe? Christian Meutes (Dec 20)
- Re: Stupid Question maybe? Saku Ytti (Dec 20)
- Re: Stupid Question maybe? Grant Taylor via NANOG (Dec 20)
- Re: Stupid Question maybe? Saku Ytti (Dec 20)
- Re: Stupid Question maybe? Grant Taylor via NANOG (Dec 20)
- Re: Stupid Question maybe? Saku Ytti (Dec 20)
- Re: Stupid Question maybe? Brian Kantor (Dec 18)
- Re: Stupid Question maybe? Justin M. Streiner (Dec 18)
- RE: Stupid Question maybe? Naslund, Steve (Dec 19)
- Re: Stupid Question maybe? Patrick W. Gilmore (Dec 19)
- RE: Stupid Question maybe? Naslund, Steve (Dec 19)
- Re: Stupid Question maybe? Adam Atkinson (Dec 20)