[100849] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: RIR filtering & Level3

daemon@ATHENA.MIT.EDU (Kevin Epperson)
Thu Nov 15 10:18:25 2007

Date: Thu, 15 Nov 2007 08:16:27 -0700 (MST)
From: Kevin Epperson <Epperson@Colorado.EDU>
To: Jon Lewis <jlewis@lewis.org>
cc: Pete Templin <petelists@templin.org>,
        Justin Shore <justin@justinshore.com>, NANOG <nanog@nanog.org>
In-Reply-To: <Pine.LNX.4.61.0711150945380.3306@soloth.lewis.org>
Errors-To: owner-nanog@merit.edu


This was an isolated error which has been fixed and safeguards added to 
prevent it from happening again.  Normally we do not announce anything 
larger than /24 to any eBGP neighbor and we accept down to /32 from 
customers assuming the prefix is registered.

 	-Kevin (Level3)

On Thu, 15 Nov 2007, Jon Lewis wrote:

>
> On Thu, 15 Nov 2007, Pete Templin wrote:
>
>> 1) ProviderX (L3 in this case) is allowing you to see some of their 
>> internal routing information.  If by chance those more-specifics come with 
>> MED and you have multiple connections to them, you can choose to make 
>> intelligent routing decisions via MED.  You could have circuitous routing 
>> though, should you not get the more-specifics over a subset of your 
>> connections
>> 
>> 2) ProviderX is demonstrating their incompetence in routing and filtering. 
>> This is just an inkling of the goofy stuff and potential landmines lurking 
>> within their network.  You should open tickets, escalate to management, and 
>> abandon this provider ASAP.
>
> I don't think it's option 1.  We've been a direct Level3 customer for several 
> years and though we're not filtering on RIR minimums yet (ask me again in 
> January :) we do have some basic sanity filtering in place. Level3 isn't 
> sending us anything longer than /24 and hasn't at least in recent history 
> (according to my distribute-list).
>
> ----------------------------------------------------------------------
> Jon Lewis                   |  I route
> Senior Network Engineer     |  therefore you are
> Atlantic Net                |
> _________ http://www.lewis.org/~jlewis/pgp for PGP public key_________
>

home help back first fref pref prev next nref lref last post