On 19 May 2016 at 14:40, Adam Vitkovsky <[email protected]> wrote:
Hey, > I'm sorry I wasn't necessarily commenting on your worries, where if i > understand it correctly you mentioned that if customer advertises a rule with > set next hop to other VRF the rule gets installed allowing him to inject > traffic to that VRF -and thus this type of action should be rejected when > received via CP-PE eBGP session. > -did I get it right? Yes. Incoming traffic to your network could be diverted to arbitrary VRF or arbitrary next-hop, and what ever actions flow-spec will get in future. > In my question I was trying to ask whether the below shortcoming of current > flowspec implementations are being addressed. They are not, but diverting someone elses traffic is addressed by RFC. -- ++ytti _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
