nanog mailing list archives
Re: "Defensive" BGP hijacking?
From: Jared Mauch <jared () puck nether net>
Date: Mon, 12 Sep 2016 14:11:36 -0400
On Sep 12, 2016, at 1:59 PM, Florian Weimer <fw () deneb enyo de> wrote: * Mel Beckman:If we can't police ourselves, someone we don't like will do it for us.That hasn't happened with with IP spoofing, has it? As far as I understand it, it is still a major contributing factor in denial-of-service attacks. Self-regulation has been mostly unsuccessful, and yet nothing has happened on the political level.
IP spoofing filtering is more of a technical issue than the social issue of BGP filtering. BGP filtering is feasible in hardware and software today. You can put a 600k line config on most devices without issues, and automate policy generation with a tool like bgpq3 or similar. Most hardware requires a recirculation of the packet to do a lookup on the source IP address. This means halving your NPU performance of something that hasn’t been in the 40 bytes per packet range for quite some time. - Jared
Current thread:
- "Defensive" BGP hijacking? Hugo Slabbert (Sep 11)
- Re: "Defensive" BGP hijacking? FHR (Sep 11)
- Re: "Defensive" BGP hijacking? Ca By (Sep 11)
- Re: "Defensive" BGP hijacking? Blake Hudson (Sep 12)
- Re: "Defensive" BGP hijacking? Ryan, Spencer (Sep 12)
- Re: "Defensive" BGP hijacking? Mel Beckman (Sep 12)
- Re: "Defensive" BGP hijacking? Florian Weimer (Sep 12)
- Re: "Defensive" BGP hijacking? Jared Mauch (Sep 12)
- Re: "Defensive" BGP hijacking? Ryan, Spencer (Sep 12)
- Re: "Defensive" BGP hijacking? Paras Jha (Sep 12)
- Re: "Defensive" BGP hijacking? Mel Beckman (Sep 12)
- Re: "Defensive" BGP hijacking? Hugo Slabbert (Sep 12)
- Re: "Defensive" BGP hijacking? Jean-Francois Mezei (Sep 12)
- Re: "Defensive" BGP hijacking? Valdis . Kletnieks (Sep 12)
- Re: "Defensive" BGP hijacking? Jean-Francois Mezei (Sep 12)
- <Possible follow-ups>
- Re: "Defensive" BGP hijacking? Scott Weeks (Sep 12)
