tcp md5 bgp attacks?
Randy Bush
randy at psg.com
Tue Aug 14 21:38:35 UTC 2018
so we started to wonder if, since we started protecting our bgp
sessions with md5 (in the 1990s), are there still folk trying to
attack?
we were unable to find bgp mib counters. there are igp interface
counters, but that was not our immediate interest. we did find
that md5 failures are logged.
looking at my logs for a few years, i find essentially nothing;
two 'attackers,' one my own ibgp peer, and one that noted evildoer
rob thomas, bgprs01.ord08.cymru.com.
we would be interested in data from others.
note that we are neither contemplating nor suggesting removing md5
from [y]our bgp sessions.
randy
More information about the NANOG
mailing list