On 19 May 2016 at 14:40, Adam Vitkovsky <[email protected]> wrote:

Hey,

> I'm sorry I wasn't necessarily commenting on your worries, where if i 
> understand it correctly you mentioned that if customer advertises a rule with 
> set next hop to other VRF the rule gets installed allowing him to inject 
> traffic to that VRF -and thus this type of action should be rejected when 
> received via CP-PE eBGP session.
> -did I get it right?

Yes. Incoming traffic to your network could be diverted to arbitrary
VRF or arbitrary next-hop, and what ever actions flow-spec will get in
future.

> In my question I was trying to ask whether the below shortcoming of current 
> flowspec implementations are being addressed.

They are not, but diverting someone elses traffic is addressed by RFC.

-- 
  ++ytti
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to