nanog mailing list archives
Re: Bogon filtering (don't ban me)
From: Ian Dickinson <ian.dickinson () pipex net>
Date: Sun, 05 Dec 2004 18:42:27 +0000
Cliff Albert wrote:
On Sun, Dec 05, 2004 at 12:41:32PM -0500, Joe Abley wrote:
>>
I have one question regarding the CYMRU bogon route-server. What good is it if more-specific bogons are going around in the BGP table ?With OpenBSD 3.6 running pf and bgpd, you can apply a filter rule to BGP updates received from individual peers which updates a pf radix table with the network received:
Nice - anyone know of anything equivalent for ipf/pfil on Solaris?
Interesting, but no option on Juniper/IOS boxes/foundry boxen.
Since 12.0(29)S and 12.2(25)S, this feature: BGP Support for IP Prefix Import from Global Table into a VRF Table http://www.cisco.com/univercd/cc/td/doc/product/software/ios120/120newft/120limit/120s/120s29/cs_bgivt.htm does the trick nicely, as long as you trust builds that new, and your linecards are new enough. Worked fine in my testing. This is effectively a way of populating a VRF and then pointing uRPF at it. I think it was aimed at feasible path uRPF, but can do the bogon stuff as well. -- Ian Dickinson Development Engineer PIPEX ian.dickinson () pipex net http://www.pipex.net This e-mail is subject to: http://www.pipex.net/disclaimer.html
Current thread:
- Re: Bogon filtering, (continued)
- Re: Bogon filtering Rob Thomas (Dec 03)
- Re: Bogon filtering Patrick W Gilmore (Dec 03)
- Re: Bogon filtering (don't ban me) David Barak (Dec 03)
- RE: Bogon filtering (don't ban me) Mark Segal (Dec 03)
- IBM --- Bogon filtering Majid Farid (Dec 03)
- RE: Bogon filtering (don't ban me) Hank Nussbacher (Dec 04)
- RE: Bogon filtering (don't ban me) Rob Thomas (Dec 04)
- Re: Bogon filtering (don't ban me) Cliff Albert (Dec 05)
- Re: Bogon filtering (don't ban me) Joe Abley (Dec 05)
- Re: Bogon filtering (don't ban me) Cliff Albert (Dec 05)
- Re: Bogon filtering (don't ban me) Ian Dickinson (Dec 05)
- Re: Bogon filtering (don't ban me) william(at)elan.net (Dec 05)
- Re: Bogon filtering (don't ban me) william(at)elan.net (Dec 05)
- Re: Bogon filtering (don't ban me) Joe Abley (Dec 05)
- Re: Bogon filtering (don't ban me) Joe Maimon (Dec 05)
- Re: Bogon filtering (don't ban me) william(at)elan.net (Dec 05)
- Re: Bogon filtering (don't ban me) Iljitsch van Beijnum (Dec 05)
- Re: Bogon filtering (don't ban me) Rob Thomas (Dec 05)
- Re: Bogon filtering (don't ban me) Jørgen Hovland (Dec 05)
- Re: Bogon filtering (don't ban me) Mikael Abrahamsson (Dec 05)
- Re: Bogon filtering (don't ban me) Patrick W Gilmore (Dec 05)