nanog mailing list archives
Re: 69/8...this sucks -- Centralizing filtering..
From: "Jack Bates" <jbates () brightok net>
Date: Tue, 11 Mar 2003 19:39:50 -0600
From: "Iljitsch van Beijnum"
I don't see your point. Packets with bogon sources are just one class of spoofed packets. As I've explained earlier S-BGP or soBGP with uRPF will get rid of bogons. Neither this or bogon filters on the host will do anything against non-bogon spoofed packets.
You're thinking technical. The problem isn't bogon filters per say. The problem is that someone got it in their head that if you filter packets using a bogon list, you'll limit the number of possible spoofed packets allowed into your network. Given than many bots use randomizers, and bogon networks do cover a large amount of the netspace, this may be true. Then again, perhaps not. It doesn't matter in the end. The fact remains that while people may protect the routes from being advertised, many large providers do not drop packets that do not have valid routes. Because of this, many firewalls (which don't run BGP) filter based on bogon lists. Only 1 of the last 6 people I contacted for blocking 69/8 actually had BGP. -Jack
Current thread:
- Re: 69/8...this sucks -- Centralizing filtering.., (continued)
- Re: 69/8...this sucks -- Centralizing filtering.. Ray Bellis (Mar 10)
- Re: 69/8...this sucks -- Centralizing filtering.. Jack Bates (Mar 10)
- Re: 69/8...this sucks -- Centralizing filtering.. Stephen Sprunk (Mar 11)
- Re: 69/8...this sucks -- Centralizing filtering.. jlewis (Mar 11)
- Re: 69/8...this sucks -- Centralizing filtering.. Shane Kerr (Mar 14)
- RE: 69/8...this sucks -- Centralizing filtering.. Iljitsch van Beijnum (Mar 11)
- Re: 69/8...this sucks -- Centralizing filtering.. Jack Bates (Mar 11)
- Re: 69/8...this sucks -- Centralizing filtering.. Iljitsch van Beijnum (Mar 11)
- Re: 69/8...this sucks -- Centralizing filtering.. Peter Galbavy (Mar 11)
- Re: 69/8...this sucks -- Centralizing filtering.. Iljitsch van Beijnum (Mar 11)
- Re: 69/8...this sucks -- Centralizing filtering.. Jack Bates (Mar 11)
- RE: 69/8...this sucks -- Centralizing filtering.. Owen DeLong (Mar 11)