do not filter your customers

Christopher Morrow morrowc.lists at gmail.com
Fri Feb 24 19:29:57 UTC 2012


On Fri, Feb 24, 2012 at 2:26 PM, Danny McPherson <danny at tcb.net> wrote:

> happens by accident all the time.  How we can justify putting all
> that BGPSEC and RPKI machinery in place and not address this
> "leak" issue somewhere in the mix is, err.., telling.

I think if we asked telstra why they didn't filter their customer some
answer like:
 1) we did, we goofed, oops!
 2) we don't it's too hard
 3) filters? what?

I suspect in the case of 1 it's a software problem that needs more
belts/suspenders
I suspect in the case of 2 it's a problem that could be shown to be
simpler with some resource-certification in place
I suspect 3 is not likely... (or I hope so).

So, even without defining what a leak is, providing a tool to better
create/verify filtering would be a boon.




More information about the NANOG mailing list