> Send Randy text about *why* you should drop invalid

i actually understand this.  it's the jgs paris aha.  thanks!

if you have a roa
   10.0.0.0/16-24  42
and you get announcements
   10.0.0.0/16     42
   10.0.666.0/24  666
if you do not drop the invalid 10.0.666.0/24, then longest match will
send packets to 666

>         Origin ops/ BGP Sec ops
>         Text - Deploy (upgrade code),
>         apply policy just to tag with a community,
>         then do analysis to ensure it's doing what you expect,
>         then deploy policy to actually do things like drop invalid,
>         prefer valid over unknown, etc." 

this i do not follow.

> The latter looks to me like a deployment guideline to address the
> concerns that I think Brian brought up about OV/BGPSec potentially
> creating non-trivial changes to routing during deployment. I can flesh
> that text out a bit if people agree that it's useful to add.

i think i covered that with the new traffic paragraph.

thanks!!!

randy
_______________________________________________
sidr mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/sidr

Reply via email to