BGP FlowSpec
Danny McPherson
danny at tcb.net
Mon May 2 13:54:12 UTC 2016
On 2016-05-02 09:48 AM, Martin Bacher wrote:
>
> So filtering as precise as possible and as close as possible to the
> attack source is maybe the best option we have at the moment.
That was precisely my point! If an upstream isn't filtering at their
ingress (or their egress) the optimal place for me to filter is at my
ingress. Of course I'd rather have something akin to inter-domain
pushback or FlowSpec, etc.. But you can't control how, or assume others
will act on that.
-danny
More information about the NANOG
mailing list