nanog mailing list archives

Re: How to validate blackhole routes? (Was: trouble letting go of IRR)


From: Saku Ytti via NANOG <nanog () lists nanog org>
Date: Mon, 2 Mar 2026 15:15:25 +0200

On Mon, 2 Mar 2026 at 15:09, Job Snijders via NANOG
<nanog () lists nanog org> wrote:

I would benefit from a few more words on what exactly you mean with the
above. Do you mean to say that if the customer AS is 65535, you'd only
permit blackholes if they are contained within the prefixes for which
AS65535 is an authorized origin, according to RPKI ROAs? Sure, that
seems a reasonable precaution.

Yes. Sort of pretending ROA allowed to /32 or whatever the specific
may be, IFF there is a blackhole community attached.

Ignoring active path.

-- 
  ++ytti
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/TK6KESEBPS7HUPKSJTAWV235LI4FWZO7/


Current thread: