nanog mailing list archives
Re: Newbie Questions: How-to remove spurious IRR records (and keep them out for good)?
From: Brandon Martin <lists.nanog () monmotha net>
Date: Mon, 2 Nov 2020 13:28:29 -0500
On 10/30/20 9:26 PM, Rubens Kuhl wrote:
1 - You should worry a little, but not much. Filters allowing unwanted announcements might be created using these erroneous IRR records, but they won't do any damage by themselves. An actual wrong BGP announcement is required for any damage to happen, and even without those IRR records, a wrong announcement will cause some havoc since not everyone builds filters based on IRR and not everyone runs RPKI validation.
I've had problems where people who build filters on IRR will build their filters SOLELY based on IRR. That is, they are not permissive and will assume that, if there is an IRR object present for a prefix, that ONLY the announcements matching that object should be accepted. This can lead to severe reachability issues if not corrected. -- Brandon Martin
Current thread:
- Re: Newbie Questions: How-to remove spurious IRR records (and keep them out for good)? Brandon Martin (Nov 02)
- <Possible follow-ups>
- Re: Newbie Questions: How-to remove spurious IRR records (and keep them out for good)? Job Snijders (Nov 02)