nanog mailing list archives

Re: JunOS/FRR/Nokia et al BGP critical issue


From: Nick Hilliard <nick () foobar org>
Date: Fri, 1 Sep 2023 10:39:43 +0100

Bjørn Mork wrote on 01/09/2023 08:17:
Sounds familiar.

https://supportportal.juniper.net/s/article/BGP-Malformed-AS-4-Byte-Transitive-Attributes-Drop-BGP-Sessions?language=en_US

You'd think a lot of thought has gone into error handling for optional
transitive attributes since then, but...

A good deal of thought has gone into the problem, and this is where rfc7606 came from. Treat-as-withdraw for the NLRI in question is the default option with this approach, and should be deployed universally.

Nick


Current thread: