nanog mailing list archives

Re: Request comment: list of IPs to block outbound


From: Enno Rey <erey () ernw de>
Date: Sun, 13 Oct 2019 18:40:09 +0200

Hi,

On Sun, Oct 13, 2019 at 08:58:17AM -0700, Stephen Satchell wrote:
The following list is what I'm thinking of using for blocking traffic
between an edge router acting as a firewall and an ISP/upstream.  This

fe80::/10           Link            Link-local address.

most people allow that range as blocking it will drop NA/NS packets with the upstream router which in turn can delay 
the establishment of the BGP session (provided there is one over IPv6).

best

Enno


-- 
Enno Rey

https://theinternetprotocol.blog
Twitter: @Enno_Insinuator


Current thread: