Best practices inquiry: filtering 128/1

John Kristoff jtk at ultradns.net
Tue Jul 11 03:22:49 UTC 2006


On Mon, 10 Jul 2006 21:56:27 -0500
Jerry Pasker <jerry at jerry.org> wrote:

> Because you fear that their routers that distribute the feed could 
> become own3d and used to cause a massive DoS by filtering out some 
> networks?

Someone in the NANOG community, I forget who now, had the sensible
suggestion that you create a filter list based on the bogon list at
the time you setup your feed.  You use that to limit what you will
accept from Cymru.  Since bogon blocks will only get allocated, the
worst that could happen is the breaking of a recently allocated bogon
network.  Even if you don't update your filter list for the next 5
years the damage is likely to be minimal.

John



More information about the NANOG mailing list