nanog mailing list archives

Re: AT&T/as7018 now drops invalid prefixes from peers


From: Job Snijders <job () instituut net>
Date: Tue, 12 Feb 2019 18:48:01 +0000

On Tue, Feb 12, 2019 at 6:40 PM Owen DeLong <owen () delong com> wrote:

To be clear, I don’t believe they are dropping all routes which don’t validate (have no ROAs), only routes where the 
prefix matches an existing ROA and the origin AS in the AS PATH does not match.

Small addition: routes are not only rejected when the BGP Origin ASN
doesn't match with any of the ROAs, but also if the Prefix Length
doesn't match up. RFC 6811 describes the procedure.

Kind regards,

Job


Current thread: