nanog mailing list archives

Re: IGP protocol


From: Saku Ytti <saku () ytti fi>
Date: Tue, 13 Nov 2018 17:30:41 +0200

On Tue, 13 Nov 2018 at 16:27, Alain Hebert <ahebert () pubnix net> wrote:

    For those that got involved in fixing a network that goes down due to OSPF spoofed packets...  (Before OSPFv2|3)
    + Security for IS-IS

Do you know connected host can't talk ISIS to you?

ISIS is false security. In modern platforms OSPF almost always can be
protected (iACL), ISIS in many times cannot. I'd run MD5 in either
case.

-- 
  ++ytti


Current thread: