Skip to Content.
Sympa Menu

netsec-sig - Re: [Security-WG] Junos min-ttl and as regex backref feature

Subject: Internet2 Network Security SIG

List archive

Re: [Security-WG] Junos min-ttl and as regex backref feature


Chronological Thread 
  • From: Andrew Gallo <>
  • To:
  • Cc:
  • Subject: Re: [Security-WG] Junos min-ttl and as regex backref feature
  • Date: Sun, 20 May 2018 13:53:33 -0700
  • Ironport-phdr: 9a23:ZtO0Xx1R4NWUW3TfsmDT+DRfVm0co7zxezQtwd8Zse0QLvad9pjvdHbS+e9qxAeQG9mDsLQc06L/iOPJYSQ4+5GPsXQPItRndiQuroEopTEmG9OPEkbhLfTnPGQQFcVGU0J5rTngaRAGUMnxaEfPrXKs8DUcBgvwNRZvJuTyB4Xek9m72/q99pHPbQhEniaxba9vJxiqsAvdsdUbj5F/Iagr0BvJpXVIe+VSxWx2IF+Yggjx6MSt8pN96ipco/0u+dJOXqX8ZKQ4UKdXDC86PGAv5c3krgfMQA2S7XYBSGoWkx5IAw/Y7BHmW5r6ryX3uvZh1CScIMb7S60/Vza/4KdxUBLniikHOT43/m/Ul8J+kr5UrQm7qBBj2YPZep2ZOOZ8c67bYNgURXBBXsFUVyFZHo68aZYAD/AfMudWsoLzpkEBrR+6BQmrGejizSVHhnDs0q0+1+QhFhrL3AMuHtITqnjbssj6NLoLXO2z0aLGzi3DYutI1Tr89ITFcBUsof+PUL1rbcbczEYiGx/ZglmNrIHqIy+Z2+UIvmWe8eZsS/mghmg6oA9ruDev3N0jiozRi4IV1F/E8SJ5zZ4wJdKiSU57ZceoEJpXty2GLod3Td0uT39ztyogxb0Gvpm7fCcOyJs53RLQd/uHc42Q7hLiUuaePyt4iWp7dL++mxq/802tyuP/W8avzFpHqyVInsXQunwQ0hHc9tSLR/p480qkxzqDyRvc5vlBIU8ulKrbL5AhwqQ3lpoWqUnMBCD2l1/yjK+ScUUp4fan6+H9bbXnop+QLYB0iw/jMqg0hMOwHPk4PhAUX2eH4eS8yKHj/UrhTbVRkPI5jrTZsIrbJcQHpq+1GgFU0ok45ha7Djemy8gYnWIZIF5feRKHiZTpNE/UIPD+E/i/n0qgnC11yP/bI72ySqnKe3rfk5/ofb9n8whdzxA4i9xS/5tJDvcMLO+gYELpsM3kCUowPAWwx+HPB8pgkI4SRDGhGKicZYrUvUWF+aoAKu2IY8dBsTn0L/wiz/HxkDk0lUJLLvrh5ocedH3tRqcuGE6ee3e52to=

I would like to see the GTSM enhancement.  Other UIs place this config in the BGP section, but not Junos.  There are some commit scripts around to allow you to use an 'apply-macro' tag in a BGP group.  I've brought this up with someone from Juniper and his reaction was a bit cool- security things go in firewall filter lists, not elsewhere.  I'm not discouraging pursuit of this enhancement, but I wouldn't be surprised if Junos purists reject the idea.



On Fri, May 18, 2018 at 9:47 AM, John Kristoff <> wrote:
Friends,

You may remember last year I solicited support for an enhancement
request to harden the NTP daemon on Junos.  This request has been filed
with Juniper.

I'm thinking of two more I'd like to submit and am wondering if there
would again be support from this community.  These are:

* enhanced GTSM support for BGP sessions

  Utilizing GTSM for BGP peering sessions is not often used, because it
  it is not enabled by default and it requires non-trivial firewall
  filters to actually enforce.

  Perhaps add a min-ttl setting under protocols bgp?  Should the value
  of 255 be the default so future generations can use a min-ttl setting?

* backreferences in AS path regular expressions

  Cisco provides this feature and I have at least one use-case for it.
  I'd like to be able to match an as-path that contains some number of
  repeated ASNs (prepending) in order to apply a particular policy
  (e.g. adjust LOCAL_PREF or reject the announcement altogether).

I'm curious if anyone here would find these two enhancements desirable
and if you'd be willing to sign on to a request to Juniper in support.

John




Archive powered by MHonArc 2.6.19.

Top of Page