nanog mailing list archives
Re: [doable?] peer filtering (was Re: Trusting BGP sessions)
From: Ran Atkinson <rja () extremenetworks com>
Date: Wed, 15 Nov 2000 16:51:44 -0500
At 15:02 15/11/00, Kevin Oberman wrote:
Since Sprint and UUnet don't seem to be willing to provide information in the IRR to allow us to generate access-lists/policies, and not peering with these folks would be a Bad Idea(tm), so we can't quite filter everyone. (If I could figure out a way to get them to register, I'd have fun trying, though.)
Excellent point.
The main deployment limitation of any of the schemes
proposed for enhanced authentication of prefix advertisements
appears to be the unwillingness of certain major ISPs to
provide authenticated information about which prefixes
that service provider claims to be providing service for.
The Routing Registries would be one way to make
that data available, however the folks who don't want to
participate in the RRs also seem uncomfortable providing
the same data via some other method that can be authenticated.
Offhand, I don't know which service providers have
this reluctance. Its clear that at least some major service
providers do have such a reluctance. Until resolved, this
will be a significant deployment hindrance for better methods
(e.g. S-BGP or the other proposed approaches) of protecting
against inaccurate/false/accidental prefix advertisements.
Sigh.
Ran
rja () extremenetworks com
DISCLAIMER: Speaking for myself here, not my employer.
Flames to /dev/null please.
Current thread:
- RE: Trusting BGP sessions, (continued)
- RE: Trusting BGP sessions Mark Borchers (Nov 14)
- Re: Trusting BGP sessions Steven M. Bellovin (Nov 14)
- Re: Trusting BGP sessions Sean Donelan (Nov 14)
- Re: Trusting BGP sessions Sean Donelan (Nov 14)
- Re: Trusting BGP sessions Adrian Chadd (Nov 15)
- [doable?] peer filtering (was Re: Trusting BGP sessions) john heasley (Nov 15)
- Re: [doable?] peer filtering (was Re: Trusting BGP sessions) Kevin Oberman (Nov 15)
- Re: [doable?] peer filtering (was Re: Trusting BGP sessions) john heasley (Nov 15)
- Re: [doable?] peer filtering (was Re: Trusting BGP sessions) gerald (Nov 15)
- Re: [doable?] peer filtering (was Re: Trusting BGP sessions) john heasley (Nov 15)
- Re: [doable?] peer filtering (was Re: Trusting BGP sessions) Ran Atkinson (Nov 15)
- Re: [doable?] peer filtering (was Re: Trusting BGP sessions) Howard C. Berkowitz (Nov 20)
- Re: [doable?] peer filtering (was Re: Trusting BGP sessions) john heasley (Nov 20)
