18.04.2011 15:43, Andrew Miehs пишет:
On Mon, Apr 18, 2011 at 11:27 AM, Artyom Viklenko<[email protected]>wrote:

I NEED to annouce these networks to Customer. But Customer should not
annouce them to another upstream.

Ah, missunderstood who was leaking.

The other service provider your customer was peering with obviously didn't
filter the customers announcements.
Your customer would add an additional prefix hop, thus increasing the length
so that hopefully the effects are too bad.

Even with setting no export etc, should your customer want to break things
he can.

I would speak with his service provider, and ask him why he accepted your
addresses.


This is what was done. His another upstream was informed and fixed filters.

I'm trying to think about possible protection against such things.
But it seems that we need new BGP version 5+ protocol... :)

Thanks to all for discussion!


--
           Sincerely yours,
                            Artyom Viklenko.
-------------------------------------------------------
[email protected] | http://www.aws-net.org.ua/~artem
[email protected]   | JID: [email protected]
FreeBSD: The Power to Serve   -  http://www.freebsd.org
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to