Dear Windstream engineers

Saku Ytti saku at ytti.fi
Mon Feb 1 09:08:51 UTC 2016


On 1 February 2016 at 08:17, joel jaeggli <joelja at bogus.com> wrote:

Hey,

> source based RTBH requires urpf, which while generally available may
> have practical limitations on implementation.

I'd say uRPF/loose is one way to do it on some platforms. In JunOS for
longest time it was not possible, and in default config it still is
not, as source route pointing to null does not fail uRPF/loose check.
However JunOS has had ~always SCU (I compare it to QPPB in CSCO) which
can be used to implement source based RTBH, without use of uRPF. It
likely out-performs uRPF/loose massively, as you don't have to do two
LPM lookups.

-- 
  ++ytti



More information about the NANOG mailing list