nanog mailing list archives
Re: BGP FlowSpec
From: Danny McPherson <danny () tcb net>
Date: Mon, 02 May 2016 09:54:12 -0400
On 2016-05-02 09:48 AM, Martin Bacher wrote:
So filtering as precise as possible and as close as possible to the attack source is maybe the best option we have at the moment.
That was precisely my point! If an upstream isn't filtering at their ingress (or their egress) the optimal place for me to filter is at my ingress. Of course I'd rather have something akin to inter-domain pushback or FlowSpec, etc.. But you can't control how, or assume others will act on that.
-danny
Current thread:
- Re: BGP FlowSpec Danny McPherson (May 02)
- Re: BGP FlowSpec Alexander Maassen (May 02)
- Re: BGP FlowSpec Martin Bacher (May 02)
- Re: BGP FlowSpec Danny McPherson (May 02)
- Re: BGP FlowSpec Martin Bacher (May 02)
- Re: BGP FlowSpec Martin Bacher (May 02)
- Re: BGP FlowSpec Danny McPherson (May 02)
- Re: BGP FlowSpec Roland Dobbins (May 02)
- Re: BGP FlowSpec jim deleskie (May 02)
- Re: BGP FlowSpec Roland Dobbins (May 02)
- Re: BGP FlowSpec Martin Bacher (May 02)
- Re: BGP FlowSpec Roland Dobbins (May 02)
- Re: BGP FlowSpec Martin Bacher (May 02)
- Re: BGP FlowSpec Alexander Maassen (May 02)
- Re: BGP FlowSpec Martin Bacher (May 02)
- <Possible follow-ups>
- Re: BGP FlowSpec Shane Short (May 02)