Request comment: list of IPs to block outbound

Vincent Bernat bernat at luffy.cx
Mon Oct 14 06:29:56 UTC 2019


 ❦ 14 octobre 2019 09:14 +03, Saku Ytti <saku at ytti.fi>:

>> I think you should seriously re-consider using rp_filter on a router.
>
> rp_filter is one of the most expensive features in modern routers, you
> should only use it, if PPS performance is not important. If PPS
> performance is important, ACL is much faster. ACL is also applicable
> to more scenarios, such as BGP customers.

How much performance impact should we expect with uRPF?

Thanks.
-- 
Make input easy to proofread.
            - The Elements of Programming Style (Kernighan & Plauger)



More information about the NANOG mailing list