[68159] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: UUNet Offer New Protection Against DDoS

daemon@ATHENA.MIT.EDU (Patrick W.Gilmore)
Wed Mar 3 18:26:30 2004

In-Reply-To: <0A6515AF81DFD84582280B1E2666FEAE024BDFB6@ILCHICVEXC006.mail.inthosts.net>
Cc: Patrick W.Gilmore <patrick@ianai.net>
From: Patrick W.Gilmore <patrick@ianai.net>
Date: Wed, 3 Mar 2004 18:17:55 -0500
To: nanog@merit.edu
Errors-To: owner-nanog-outgoing@merit.edu


On Mar 3, 2004, at 5:51 PM, Lumenello, Jason wrote:

> I struggled with this, and came up with the following.
>
> We basically use a standard route-map for all customers where the first
> term looks for the community. The customer also has a prefix-list on
> their neighbor statement allowing their blocks le /32. The following
> terms (term 2 and above) in the route-map which do NOT look for the
> customer discard community, have a different standard/generic
> prefix-list evaluation which blocks cruft and permits 0.0.0.0/0 ge 8 le
> 24.
>
> By doing this, I only accept a customer /32 from his dedicated
> prefix-list when it has the DOS discard community, otherwise I catch
> them with the ge 8 le 24 in the following terms.

A lot of people seem to be doing this.

Mind if I ask what's the harm of letting customers announce /32 or /29s 
into your core as long as you filter at your borders?

The additional prefixes are not going to kill your routers, and it 
allows the customer more finely tuned traffic controls.  IOW: Seems 
there is some utility and no harm.

-- 
TTFN,
patrick


home help back first fref pref prev next nref lref last post