AW: AW: Prefix-Hijack by AS7514
Mark Tinka
mark.tinka at seacom.mu
Fri Jul 17 10:03:04 UTC 2015
On 17/Jul/15 11:46, Matsuzaki Yoshinobu wrote:
> Yes, I agree, and we have done that. How about peering partners -
> which is our case this time. Is it feasible to maintain strict
> inbound prefix filters for all peering relationships?
To be honest, not really.
Some countries I know do this for their exchange points. But
by-and-large, it is not scalable. Same goes for AS_PATH lists for peering.
One can be liberal at peering points but have max-prefix as a basic
protection mechanism (which is what we do).
Of course, IRR's are the other way to go.
Mark.
More information about the NANOG
mailing list