nanog mailing list archives

Re: Any way to P-T-P Distribute the RBL lists?


From: "Eric A. Hall" <ehall () ehsco com>
Date: Thu, 25 Sep 2003 14:31:23 -0500



on 9/24/2003 9:30 PM Drew Weaver wrote:

            I know you all have probably already thought of this, but
can anyone think of a feasible way to run a RBL list that does not have
a single point of failure? Or any attackable entry?

Easy. Have the master server only be reachable by replication partners
through a VPN connection, and have dozens of secondaries advertising
through multiple anycast addresses.

-- 
Eric A. Hall                                        http://www.ehsco.com/
Internet Core Protocols          http://www.oreilly.com/catalog/coreprot/


Current thread: