ntacpeering - Re: Today's BGP incidents
Subject: NTAC Peering Working Group
List archive
- From: Chris Robb <>
- To: Steven Wallace <>
- Cc: "" <>
- Subject: Re: Today's BGP incidents
- Date: Sat, 5 Jan 2013 14:25:21 -0500
Hi Steve. We have a few safeguards that would prevent this on our International and Federal peelings. Before I describe those, it's important for everyone to recognize that domestically, all of our connectors have explicit prefix lists, so anything beyond the approved set of participant routes would be rejected immediately. On our R&E peer connections to international and federal networks, we don't have the luxury of having an explicit prefix list available to us. So, each peer is configured with a default limit of 3,000 routes. There was some NTAC discussion (2008?), about creating different tiers to that number so that our smaller peers get a more tightened limit and the larger ones might get something higher. As it stands, we might place an exception in place for a network like GEANT, but the limits are very close to what they advertise today. The second safeguard is a commercial AS number sanity filter. It contains most of the large commercial networks. Anything with that appearing in the BGP advertisement AS path will be rejected before hitting the routing table. We've talked at times about implementing AS-path filtering for our peers and using the routing registries to harden this up a bit. We might revisit that as part of this. -Chris -- Chris Robb, Internet2 Director of Operations and Engineering O: 812.855.8604 C: 812.345.3188 **************** Visit our website: www.internet2.edu Follow us on Twitter: www.twitter.com/internet2 Become a Fan on Facebook: www.internet2.edu/facebook On Jan 5, 2013, at 12:20 PM, Steven Wallace <> wrote:
|
- Today's BGP incidents, Bill Owens, 01/04/2013
- Re: Today's BGP incidents, John Hernandez, 01/04/2013
- Re: Today's BGP incidents, Bill Owens, 01/04/2013
- Re: Today's BGP incidents, Hans Addleman, 01/04/2013
- Re: Today's BGP incidents, Buraglio, Nicholas D, 01/04/2013
- <Possible follow-up(s)>
- Fwd: Today's BGP incidents, Steven Wallace, 01/05/2013
- Re: Today's BGP incidents, Chris Robb, 01/05/2013
Archive powered by MHonArc 2.6.16.