On Friday 04 December 2009 07:22:01 pm The Dark One wrote: > what is the general opinion from ISP out there about > using RPF on external peering interfaces? And which > variant: > -loose active-path > -loose feasible-path > -strict active-path > -strict feasible-path
In general, we've found it safer to run with loose mode + feasible paths on peering/edge routers that hold the full routing table. This works well. We've had issues when running uRPF on routers that don't hold the full table, e.g., public and private peering routers, because some of our peering partners end up leaking our routes to their other peering partners, when they shouldn't. Cheers, Mark.
signature.asc
Description: This is a digitally signed message part.
_______________________________________________ juniper-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/juniper-nsp

