Bogon filtering (don't ban me)

Hank Nussbacher hank at mail.iucc.ac.il
Fri Dec 3 07:23:01 UTC 2004


In Ciscoland its called Autosecure (IOS 12.3):
http://www.cisco.com/warp/public/cc/pd/iosw/prodlit/cas11_ds.htm

"Blocks all IANA reserved IP address blocks"

The actual doc:
<http://niatec.info/mediacontent/cisco/media/targets/resources_mod07/7_1_2_AutoSecure.pdf>

Problem is, I still do not see that Cisco has a way of auto-updating a
router that has used autosec_complete_bogon or
autosec_iana_reserved_block.

-Hank

> We've proposed what vendors need to better support bogon filtering, even
> wrote a draft:
>   http://arneill-py.sacramento.ca.us/draft-py-idr-redisfilter-01.txt
> but last time I talked to cisco ios person (which was just two weeks ago
> at IPv6 Summit), it still has not been done. Perhaps couple more people
> who buy their hardware asking them about it will make a difference ...




More information about the NANOG mailing list