nanog mailing list archives

Re: Blackholing traffic by ASN


From: Chris Adams <cmadams () hiwaay net>
Date: Thu, 31 Jan 2008 08:07:55 -0600


Once upon a time, Christopher Morrow <morrowc.lists () gmail com> said:
Nowadays, most equipment can blackhole internally (to null0 say) at full
speed, so it isn't an issue. Just set your next hop to a good null0
style location on route import and you are done for traffic destined to
those locations.

...do uRPF-loose-mode and you kill FROM these locations as well...

On Cisco, but not Juniper.

-- 
Chris Adams <cmadams () hiwaay net>
Systems and Network Administrator - HiWAAY Internet Services
I don't speak for anybody but myself - that's enough trouble.


Current thread: