BCP38 - Internet Death Penalty

Adam Vitkovsky adam.vitkovsky at swan.sk
Thu Mar 28 12:20:07 UTC 2013


> If you are doing strict BGP prefix-filter, it's either very easy to
generate ACL while at it
Yes and that is exactly what needs to become a habit for all the operators. 
We all do care what our neighbors advertise to us or what prefixes we accept
from them. 
But only a few really do care whether that's actually what is leaving our
neighbor's network. 

It's a pity that rpf is not "on" by default for interfaces over which the
ebgp session is configured. 

adam






More information about the NANOG mailing list