[25256] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Martian list of IP's to block???

daemon@ATHENA.MIT.EDU (Andy McConnell)
Fri Oct 1 13:08:24 1999

Date: Fri, 1 Oct 1999 10:03:49 -0700 (PDT)
From: Andy McConnell <andym@ntt.net>
To: bmanning@vacation.karoshi.com
Cc: rfuller@3x.com, "John M. Brown" <jmbrown@ihighway.net>,
	nanog@merit.edu
In-Reply-To: <199910011549.IAA02509@vacation.karoshi.com>
Message-ID: <Pine.BSF.3.95LJ1.1b3.991001095814.68144D-100000@dukat.noc.cup.ndp.net>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=ISO-2022-JP
Errors-To: owner-nanog-outgoing@merit.edu


On Fri, 1 Oct 1999 bmanning@vacation.karoshi.com wrote:

}>     deny   ip 224.0.0.0 31.255.255.255 any log

...

}	I'm not convinced that blocking native multicast is a good idea.


I think it makes sense if you're using this list to block source
addresses, or if you are applying this list to unicast routes only.  We
also block 224.0.0.0/4, but not on MBGP-learned routes. 

-andy

--
Andy McConnell	IP Operations Manager 			andym@ntt.net
NTT America 	Network and IP Service Division		+1 408 873 3757
$B??8~N}(B $B0BEHN6(B 	NTT$B%"%a%j%+(BIP$B%*%Z%l!<%7%g%sC4Ev2]D9(B	

Always try to do things in chronological order; it's less
confusing that way.



home help back first fref pref prev next nref lref last post