nanog mailing list archives

Re: Request comment: list of IPs to block outbound


From: Vincent Bernat <bernat () luffy cx>
Date: Mon, 14 Oct 2019 08:29:56 +0200

 ❦ 14 octobre 2019 09:14 +03, Saku Ytti <saku () ytti fi>:

I think you should seriously re-consider using rp_filter on a router.

rp_filter is one of the most expensive features in modern routers, you
should only use it, if PPS performance is not important. If PPS
performance is important, ACL is much faster. ACL is also applicable
to more scenarios, such as BGP customers.

How much performance impact should we expect with uRPF?

Thanks.
-- 
Make input easy to proofread.
            - The Elements of Programming Style (Kernighan & Plauger)


Current thread: