nanog mailing list archives
RE: Ingress filtering on transits, peers, and IX ports
From: <adamv0025 () netconsultings com>
Date: Thu, 15 Oct 2020 15:46:23 +0100
From: Saku Ytti <saku () ytti fi> Sent: Thursday, October 15, 2020 3:30 PM On Thu, 15 Oct 2020 at 17:22, Tim Durack <tdurack () gmail com> wrote:We deploy urpf strict on all customer end-host and broadband circuits. Inthis scenario urpf = ingress acl I don't have to think about. But you have to think about what prefixes a customer has. If BGP you need to generate prefix-list, if static you need to generate a static route. As you already have to know and manage this information, what is the incremental cost to also emit an ACL?
Actually ideally there would be a feature/knob to automatically sync BGP (and static routes) with packet filters. adam
Current thread:
- Re: Ingress filtering on transits, peers, and IX ports, (continued)
- Re: Ingress filtering on transits, peers, and IX ports Eric Kuhnke (Oct 14)
- Re: Ingress filtering on transits, peers, and IX ports Casey Deccio (Oct 19)
- Re: Ingress filtering on transits, peers, and IX ports Baldur Norddahl (Oct 15)
- RE: Ingress filtering on transits, peers, and IX ports adamv0025 (Oct 15)
- Re: Ingress filtering on transits, peers, and IX ports Saku Ytti (Oct 15)
- RE: Ingress filtering on transits, peers, and IX ports adamv0025 (Oct 15)
- Re: Ingress filtering on transits, peers, and IX ports Saku Ytti (Oct 15)
- Re: Ingress filtering on transits, peers, and IX ports Tim Durack (Oct 15)
- Re: Ingress filtering on transits, peers, and IX ports Saku Ytti (Oct 15)
- Re: Ingress filtering on transits, peers, and IX ports Nick Hilliard (Oct 15)
- RE: Ingress filtering on transits, peers, and IX ports adamv0025 (Oct 15)
- Re: Ingress filtering on transits, peers, and IX ports Chris Adams (Oct 15)
- RE: Ingress filtering on transits, peers, and IX ports adamv0025 (Oct 15)
- Re: Ingress filtering on transits, peers, and IX ports Tim Durack (Oct 15)
- Re: Ingress filtering on transits, peers, and IX ports Baldur Norddahl (Oct 15)