Request for comment -- BCP38

Elmar K. Bins elmi at 4ever.de
Mon Sep 26 14:55:35 UTC 2016


Re Stephen,

> So, to beat that horse to a fare-thee-well, to be BCP38 compliant I need, on
> every interface sending packets out to the internet, to block any source
> address matching a subnet in the BOGON list OR not matching any of my
> routeable network subnets?  Plus add null-route entries for all the BOGONs
> in my routing table so I don't send a bad destination packet to my upstream?

The correct way to implement this is
  - outgoing permit my allocated address blocks as source addresses
  - outgoing deny EVERYTHING (else)

Elmar.





More information about the NANOG mailing list