Prefix hijacking, how to prevent and fix currently

Saku Ytti saku at ytti.fi
Fri Aug 29 11:47:29 UTC 2014


On (2014-08-29 14:37 +0300), Saku Ytti wrote:

> > clearly i am missing something.  got a write-up?
> 
> Loose mode RPKI:
>  - verified or unknown less-specific route is preferable to failing more-specific

Or said otherwise when choosing route from Adj-RIBs-In to Loc-RIB longest
match is not done to whole population, population is first divided to
'verified', 'unknown' and 'failed' routes, and longest match is done for each
sub-population in order, until match is found.

-- 
  ++ytti



More information about the NANOG mailing list