BCP38 - Internet Death Penalty
Adam Vitkovsky
adam.vitkovsky at swan.sk
Thu Mar 28 12:20:07 UTC 2013
> If you are doing strict BGP prefix-filter, it's either very easy to
generate ACL while at it
Yes and that is exactly what needs to become a habit for all the operators.
We all do care what our neighbors advertise to us or what prefixes we accept
from them.
But only a few really do care whether that's actually what is leaving our
neighbor's network.
It's a pity that rpf is not "on" by default for interfaces over which the
ebgp session is configured.
adam
More information about the NANOG
mailing list