nanog mailing list archives
Re: Is it time to abandon bogon prefix filters?
From: Pekka Savola <pekkas () netcore fi>
Date: Wed, 20 Aug 2008 08:24:35 +0300 (EEST)
On Tue, 19 Aug 2008, Kevin Loch wrote:
While you're at it, you also placed the reachable-via rx on all your customer interfaces. If you're paranoid, start with the 'any' rpf and then move to the strict rpf. The strict rpf also helps with routing loops.Be careful not to enable strict rpf on multihomed customers. This includesany bgp customer unless you know for sure they are single homed to you and that will notchange.
Strict uRPF (feasible paths variant, RFC3704) works just fine with multihomed customers here.
But we don't allow TE more specifics either from the customer or from peers, so the longest prefix matching doesn't get messed up. And with certain kind of p2p link numbering, you may need to add a dummy static route. But it works.
For more see especially Section 3 of: http://tools.ietf.org/id/draft-savola-bcp84-urpf-experiences-03.txt (comments are also welcome.) -- Pekka Savola "You each name yourselves king, yet the Netcore Oy kingdom bleeds." Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings
Current thread:
- Re: Is it time to abandon bogon prefix filters?, (continued)
- Re: Is it time to abandon bogon prefix filters? Chris Adams (Aug 18)
- RE: Is it time to abandon bogon prefix filters? Tomas L. Byrnes (Aug 18)
- Re: Is it time to abandon bogon prefix filters? Danny McPherson (Aug 18)
- Re: Is it time to abandon bogon prefix filters? Sean Donelan (Aug 21)
- RE: Is it time to abandon bogon prefix filters? Tomas L. Byrnes (Aug 24)
- Re: Is it time to abandon bogon prefix filters? Valdis . Kletnieks (Aug 25)
- Re: Is it time to abandon bogon prefix filters? Chris Marlatt (Aug 25)
- Re: Is it time to abandon bogon prefix filters? Valdis . Kletnieks (Aug 25)
- RE: Is it time to abandon bogon prefix filters? Sean Donelan (Aug 26)
- Re: Is it time to abandon bogon prefix filters? Kevin Loch (Aug 19)
- Re: Is it time to abandon bogon prefix filters? Pekka Savola (Aug 19)
- Re: Is it time to abandon bogon prefix filters? Kevin Loch (Aug 20)
- Re: Is it time to abandon bogon prefix filters? Jo Rhett (Aug 21)
- Re: Is it time to abandon bogon prefix filters? Sean Donelan (Aug 21)
- Re: Is it time to abandon bogon prefix filters? Jared Mauch (Aug 25)
- Re: Is it time to abandon bogon prefix filters? Marshall Eubanks (Aug 25)
- Re: Is it time to abandon bogon prefix filters? Mark Andrews (Aug 25)
- Re: Is it time to abandon bogon prefix filters? Pete Templin (Aug 07)
- Re: Is it time to abandon bogon prefix filters? Patrick W. Gilmore (Aug 07)
- Re: Is it time to abandon bogon prefix filters? Robert E. Seastrom (Aug 07)
- Re: Is it time to abandon bogon prefix filters? Randy Bush (Aug 07)