Is it time to abandon bogon prefix filters?

Pete Templin petelists at templin.org
Thu Aug 7 18:04:19 UTC 2008


Patrick W. Gilmore wrote:

> Filter your bogons.  But do it in an automated fashion, from a trusted 
> source.
> 
> Of course, I recommend Team Cymru, which has a most sterling record.  
> Nearly perfect (other than the fact they still recommend MD5 on BGP 
> sessions :).

How can you recommend Team Cymru, when their product is not in any way a 
filter?  It is merely an automated method of injecting aggregate null 
routes for bogons, but in no way prevents a network from accepting 
aggregate or specific bogon announcements (i.e. it does not _filter_).

pt





More information about the NANOG mailing list