netsec-sig - Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange
Subject: Internet2 Network Security SIG
List archive
Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange
Chronological Thread
- From: "Montgomery, Douglas (Fed)" <>
- To: "" <>, Karl Newell <>
- Cc: Michael H Lambert <>, "" <>
- Subject: Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange
- Date: Mon, 6 Nov 2017 22:25:40 +0000
- Accept-language: en-US
- Authentication-results: spf=none (sender IP is ) ;
- Ironport-phdr: 9a23:THQHGROPexjrNMog/TQl6mtUPXoX/o7sNwtQ0KIMzox0K/38o8bcNUDSrc9gkEXOFd2CrakV26yO6+jJYi8p2d65qncMcZhBBVcuqP49uEgeOvODElDxN/XwbiY3T4xoXV5h+GynYwAOQJ6tL1LdrWev4jEMBx7xKRR6JvjvGo7Vks+7y/2+94fdbghMhzexe69+IAmrpgjNq8cahpdvJLwswRXTuHtIfOpWxWJsJV2Nmhv3+9m98p1+/SlOovwt78FPX7n0cKQ+VrxYES8pM3sp683xtBnMVhWA630BWWgLiBVIAgzF7BbnXpfttybxq+Rw1DWGMcDwULs5Qiqp4bt1RxD0iScHLz85/3/Risxsl6JQvRatqwViz4LIfI2ZMfxzca3HfdMeWGFPQMBfWSJcCY+4docCDu8NMOBFpIf/ulQOtwOzCwmyCu3y1j9GiHz43aM43OsvEAHJwAMvEskUv3jIqdX4LrseXPq3waTO0D7Nb+lW2TD46IXQfBwvpvaMXbRsccrezkkvEh3Kjk+QqID9Ijib2OMNs3WU7+pkT+2vkHMspwVxrDex28ggj4fFjZ8Sx1/Z8iV53Yk1JdijRU59YN6kC4dQuzuVN4txXMMvWmdlszs0xL0BvJ60ZikKyJI/yh7edfOHb4aI7gjkVOaLLjd1gm9udrGnhxuq70StxPfwWtSo3FtEtCZJjMXAum0X2xDO9sSKReNx8lq/1TuLzQze6/tILV40mKfVMZIt3KA8moYLvUTNACD7m1n6gaqTe0o+5uel7+fqb7D8qZCHNIJ4lATzPbg0lcyxDuk1NwkDUmuZ9OSy0rDo4Ff3T69QjvIsl6nUqJDaKtofpq6+GwJV3Zos5AqjAzu7ydgXgHwHIExcdBKAlIfmJUvCIPflDfejmFuslyprx/bbMbH7GpXNNH/DkKv/crlh905cyQ0zzdZF65JTF7EBPPbzWkj2tNzbFBM2Lwu0w+P/BNV80IMRR36PD7eHPK7cq1OE+/4jLueWaIMLpDrxNuIp6+PygXI2gVMdeLOm3ZoTaHC2BPRmJECZbGLxjdcGDGcKsQ8+QffsiF2DSj5Te2y+X6075jElEI6mF5vMRpixgLyd2ye2BoZWaX5aBVCRC3fodpmEWvcVZCOcLc9siTgEVbm6S489zhGiqhX2y7thLurI5CIYr5Tj28Zp5+HNjx096yF7D9mF2WGXU250hn8IRyMx3K1nokx9zEmM0KZmjPxcEdxe/PJJUgEmNZHC1ex6Dc79Wh7fctuTVlmpX8imCykrTt0t298Of1p9G9K6gxDFwyqlGaMal6SVC5Mq6KLc3n7xJ8lmxnbC1akhlEUmQtBROWG8h65/8RTTCJDTk0WfiamqaboQ0DTT+2ie0Grd9H1fBURrXK7YR3EDdw7Jovz44F/PVbmjFe5hPwdcg4bWMaZBd8fokUQDW/jLOdLCbni3lnvqQxuE2+XIJKnjYWFV+ijCBUwA21QQ+3uZOAw6Lianv2/ECjFyTxTib166osdkr3buBGozyR2FaEhszavxsjISmPOYQuhbnpwJtGZr42F4G0uy2vrQCsGc4QVmYvMPMpsG/F5b2DeB5ERGNZu6IvUn3wZAfg==
- Spamdiagnosticmetadata: NSPM
- Spamdiagnosticoutput: 1:99
This group might be interested in some work we are trying to develop in the IETF to improve the usefulness of uRPF beyond the edge. https://datatracker.ietf.org/doc/draft-sriram-opsec-urpf-improvements/ I you have comments or feedback let us know, dougm --dougm @ NIST / ITL / ANTD From: <> on behalf of David Farmer <> I agree BCP38/uRPF is probably best focused on connectors. However, I'm not sure the goal is to get all connecters to do BCP38/uRPF, at least yet. I believe the current goal is to better understand the need, the efficacy, and issues of
deploying BCP38/uRPF in our community. Blindly deploying BCP38/uRPF doesn't answer those questions.
As for RPKI; In our community RPKI is just as much a campus issue, as most campuses are the BGP route origin. Exclusively focusing on connectors for RPKI won't work. Connectors could be the focus for RPKI route validation, but without ROAs from campuses,
RPKI route validation won't have much effect as there won't me much to validate. This is a classic chicken or the egg problem. we need to incrementally make progress on both sides. Without regionals validating there isn't a good reason for campuses to create
ROA. And, without ROAs from campuses there isn't a good reason for regionals to validate. Thanks. On Mon, Nov 6, 2017 at 10:41 AM, Karl Newell <> wrote:
-- =============================================== |
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, (continued)
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, David Farmer, 11/06/2017
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, Michael H Lambert, 11/06/2017
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, Karl Newell, 11/06/2017
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, David Farmer, 11/06/2017
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, John Hernandez, 11/06/2017
- RE: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, Michael Hare, 11/07/2017
- RE: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, Garrett, Seth B, 11/07/2017
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, Pete Siemsen, 11/07/2017
- Message not available
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, John Kristoff, 11/08/2017
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, Pete Siemsen, 11/27/2017
- RE: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, Michael Hare, 11/07/2017
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, John Hernandez, 11/06/2017
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, David Farmer, 11/06/2017
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, Karl Newell, 11/06/2017
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, Montgomery, Douglas (Fed), 11/06/2017
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, Michael H Lambert, 11/06/2017
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, David Farmer, 11/06/2017
- Re: [Security-WG] I2 - Anti-Spoofing/uRPF discussion summary from Technology Exchange, Steven Wallace, 11/06/2017
Archive powered by MHonArc 2.6.19.