-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
On 29/Mar/15 22:45, Gert Doering wrote: > > On the other hand, while you are still all picking on me for suggesting > an IGP - don't forget the havoc that you can do with BGP, like, "not > having proper incoming filters" and "not ensuring that prefixes you > do not want to send to other parties do not leak", and such :-) > (insert shameless plug for RFC 7454 here...) > > So whatever protocol you use (besides static+bfd), you MUST ensure that > a) you only accept what the customer is permitted to announce (typos and > other accidents happen), and b) you clearly understand how far you want > that information to propagate, and ensure that it happens that way. Agreed. Mark. -----BEGIN PGP SIGNATURE----- iQIcBAEBAgAGBQJVGGVHAAoJEGcZuYTeKm+GqsoP/RIBPzksRWUhVxualeWUxr+C ESLQ76XgvYIij0WOHRpF60YTFIPOJMaqLmy0wPrYpBqznScn9TD7vMze03IQbtde CK7oRKNRnDabVzO/PtRNwKtZOoTPWyiR+vun9qRcCEZ10UDpU+95utHlu0KUpnas N5cvBof54YN5LrLoRcQ3nweQ5pnZGwI+wO/FJfyIV4KMFpELIV6tT4KlmzEDC/d8 xMey0zOhpTC3r/yIjXDIoSBoob+MeZ5Qge3ztCIU4RsojMdIhgEM83Jpr3wuJ07N b1rxvLwRQuWmfoC6RVXShCeEZpCUkFaA9+A5hLeE8OD6pU0QXRsGlzHQ1ZC4xrVZ 8jqdQEnui9IceQr6RbLdLh8MtgWNJDHGuHSawhVEQ/1RmsJvf2KOsXxyBFz8fUV0 Q+D8rPVT3/OKBMeEj5TP7c4P33ieE4ggSSGQpt9xkWBmmVL15XHHqucA86mdAHXU Xu1JpYdhZqLBzrpnRUts3wYCbommMqZOKy7BjyK7sR3RXZpFFQKWK2RRiGXNxZBD DoFfmcotdM3L4Uh6BjLMLJwvpHDICcjG6JoRFgje7qnuBDNt0mPR2+lxe4dwpmT8 eLIa6BpmERcv2Go/VhCRtpIOEdigksRCZA+XPgbJobpUC1beVPObcHJuDn+uXAkf KkYZtkH9wVCYclSaPITk =8PIY -----END PGP SIGNATURE----- _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
