On Tue, 4 Aug 2026 at 18:20, Michael Hare via NANOG <nanog@lists.nanog.org> wrote:
+1. Was going to follow up to Saku's message about how/if folks are doing that in JunOS [or other OS] natively without outside automation. Our backbone has scavenger style plp in BE, I control admission via prefix-list in ingress fwfilter on untrusted interfaces. Haven't personally tested but looks like DCU + forwarding-table export policy + output firewall filter, maybe this is possible today but requires output fwfilter to family mpls. I don't currently have a fwfilter there so ideally another option exists.
Something to this note, nothing really specific to any AFI: https://raw.githubusercontent.com/job/draft-downgrade-bgp-community/refs/hea... For context, remainder of QoS config would look something to: https://p.ip.fi/Nott.txt -- ++ytti