nanog mailing list archives

Re: JunOS/FRR/Nokia et al BGP critical issue


From: Eugeniu Patrascu <eugen () imacandi net>
Date: Wed, 30 Aug 2023 16:59:22 +0300

On Wed, Aug 30, 2023 at 4:04 PM William Herrin <bill () herrin us> wrote:

On Wed, Aug 30, 2023 at 4:50 AM Mike Lyon <mike.lyon () gmail com> wrote:
Ran across this article today and haven't seen posts about it so i
figured I would share:

https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling

Can you imagine, as the origin of a route, troubleshooting a
connectivity issue in which Internet BGP routers far from your control
have trouble with attributes attached by their peers and then "did
their best" with your route instead of dropping the session and
essentially demanding intervention by the network operator?

Dumping the session may seem extreme, but there's a good reason for it.


Or do the sensible thing and just drop the announcement and log the
problem.
This might be a problem in a DFZ environment, but albeit a small one.
Or, drop the invalid attribute and treat the announcement as a regular one.

Current thread: