69/8...this sucks -- Centralizing filtering..

Jack Bates jbates at brightok.net
Tue Mar 11 14:34:10 UTC 2003



From: "Iljitsch van Beijnum"

> Fortunately, in this particular case there is a solution on the horizon:
> S-BGP or soBGP. These BGP extensions authenticate all prefix
> announcements, so there is no longer any need to perform bogon filtering
> on routing information. uRPF can then be used to filter packets based on
> the contents of the routing table.
>
A majority of the filters in place are not BGP filters. They are firewall
rulesets designed to filter out hijacked and spoofed IP addresses to limit
DOS and illegitimate connections. S-BGP and soBGP will not solve the problem
for these people.

-Jack




More information about the NANOG mailing list