netsec-sig - Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs....
Subject: Internet2 Network Security SIG
List archive
- From: Andrew Gallo <>
- To: Steven Wallace <>
- Cc:
- Subject: Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs....
- Date: Wed, 15 May 2019 11:42:12 -0400
Very true. I knew I was missing something.
I think it was Brad from Kansas that had the suggestion of having a ROA allow prefixes of multiple specific masks, such as /16 OR all /24s, but not in between. There isn't a standard to allow that, and it's only slightly better than the current mask length option, but it does prevent an attacker (or mistaker? if I can make up a word) from spoofing prefixes of intermediate length.
On Wed, May 15, 2019 at 11:24 AM <> wrote:
>
> What's the opinion of having the DDoS vendor advertise the prefix using the original networks ASN, in which case, the original ROA would cover? Is that bad form in terms of routing?
>
I’m not sure that fixes anything. The DDoS vendor will need to advertise a more specific, so you’re now stuck with creating many ROAs, or select an optional prefix length to cover the more specifics. Either will allow a hijacker to use spoof your origin and advertise more specific to effective divert traffic, all the while passing a validator test.
- [Security-WG] Seeking advice on BCP for ROAs...., ssw, 05/15/2019
- <Possible follow-up(s)>
- Re: [Security-WG] Seeking advice on BCP for ROAs...., John Kristoff, 05/15/2019
- Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs...., ssw, 05/15/2019
- Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs...., ssw, 05/15/2019
- Message not available
- Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs...., John Kristoff, 05/15/2019
- Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs...., Andrew Gallo, 05/15/2019
- Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs...., ssw, 05/15/2019
- Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs...., Andrew Gallo, 05/15/2019
- Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs...., Brad Fleming, 05/15/2019
- Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs...., ssw, 05/15/2019
- Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs...., Adair Thaxton, 05/15/2019
- Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs...., Andrew Gallo, 05/15/2019
- Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs...., John Kristoff, 05/15/2019
- Re: [Security-WG] [External] Re: Seeking advice on BCP for ROAs...., ssw, 05/15/2019
Archive powered by MHonArc 2.6.19.