Re: [j-nsp] CVE-2023-4481

2023-08-29 Thread David Sinn via juniper-nsp
A network I operate is going with: bgp-error-tolerance { malformed-route-limit 0; } The thoughts being that there is no real reason to retain the malformed route and the default of 1000 is arbitrary. We haven't really seen a rash of them, so adjusting the logging

[j-nsp] CVE-2023-4481

2023-08-29 Thread Randy Bush via juniper-nsp
do we have a recommended `bgp-error-tolerance {}` config to deal with CVE-2023-4481? and what does one do on antique hardwhere with. e.g., junos 14? randy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net