[106887] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Is it time to abandon bogon prefix filters?

daemon@ATHENA.MIT.EDU (Randy Bush)
Fri Aug 15 11:18:24 2008

Date: Fri, 15 Aug 2008 08:18:14 -0700
From: Randy Bush <randy@psg.com>
To: "Robert E. Seastrom" <rs@seastrom.com>
In-Reply-To: <86fxp6tird.fsf@seastrom.com>
Cc: NANOG list <nanog@nanog.org>
Errors-To: nanog-bounces@nanog.org

>> Again, I think bogon filters are a bad idea for unmanaged or
>> semi-managed routers (or inclusion as a "default" in anything,
>> i.e. Cisco's auto-secure).
> 
> You make a very good point about the difference between routers that
> are being routinely maintained by highly clueful people and routers
> that are in the field and untouched/unloved for months to years at a
> time.

in the field != untouched/unloved

i contend that all one's routers should be rigorously configured as
programmatically as possible.

randy


home help back first fref pref prev next nref lref last post