nanog mailing list archives

Re: engineering --> ddos and flooding


From: "Christopher A. Woodfield" <rekoil () semihuman com>
Date: Fri, 1 Jun 2001 16:34:40 -0400


Easy...

ip route 127.254.254.254 255.255.255.255 null0

BGP sees this as a valid route, straight to the bit bucket.

-C

Even if they don't, who's to say what's unreachable?  If the NEXT_HOP is
truly unreachable, in that there is no route to it, the BGP path won't be
marked as valid and won't make it to the IP routing table (Loc-RIB.)

I've long felt that IP should have come with a provision for an address that
is never routed.  It would be great if we could get something like 127.0.0.2
for this very task.

Mark


-- 
---------------------------
Christopher A. Woodfield                rekoil () semihuman com

PGP Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xB887618B


Current thread: