On 2016-08-04 07:34, heasley wrote:
Wed, Aug 03, 2016 at 10:11:46PM -0400, Christopher Morrow:
So, back to your discuss though:
"BGP speakers SHOULD only accept and honor BGP announcements
carrying
the BLACKHOLE community if the announced prefix is covered by a
shorter prefix for which the neighboring network is authorized to
advertise."
(note that 'shorter' is used here...again making the above bit more
confiusing with smaller/larger)
MUST vs SHOULD for this, I do think the MUST would be easy to handle.
Is
this a problem in an RS situation? Probbaly not... on the RS, but on
the
distant peer, it likely is hard(er) to deal with. I don't imagine many
folk
prefix filter the RS session very tightly only because memberships
come/go
and you may not always get timely notice (I have no idea when people
come/go at the IX's I connect to).
So, SHOULD makes some sense to me, at least in the RS
peer/distant-peer
world. Surely for direct BGP peerings MUST is a better idea, I think.
or strike the language altogether. it is unnecessary. if it is their
prefix and they want to blackhole it - whatever, their prerogative.
Yhe weirdest things happen in the DFZ and I can see corner cases in
which one network may desire to advertise the RTBH host only.
For instance: network "A" is peering with networks "B" and "C" and wants
to receive legit traffic from the first (because he has more capacity)
but wants to stop the attack closer to the source which is in "C" .
--
Marco
_______________________________________________
GROW mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/grow