nanog mailing list archives

Re: Prefix hijacking, how to prevent and fix currently


From: Saku Ytti <saku () ytti fi>
Date: Fri, 29 Aug 2014 14:47:29 +0300

On (2014-08-29 14:37 +0300), Saku Ytti wrote:

clearly i am missing something.  got a write-up?

Loose mode RPKI:
 - verified or unknown less-specific route is preferable to failing more-specific

Or said otherwise when choosing route from Adj-RIBs-In to Loc-RIB longest
match is not done to whole population, population is first divided to
'verified', 'unknown' and 'failed' routes, and longest match is done for each
sub-population in order, until match is found.

-- 
  ++ytti


Current thread: