Saku- Thanks for link. This is what I had in mind, but I presumed if output interface was into an LSP maybe I'd need output filter in family MPLS. At this point, I'll just try this out in the lab. -Michael
-----Original Message----- From: Saku Ytti <saku@ytti.fi> Sent: Tuesday, August 4, 2026 11:30 AM To: North American Network Operators Group <nanog@lists.nanog.org> Cc: Michael Hare <michael.hare@wisc.edu> Subject: Re: how about a well-known DOWNGRADE BGP Community? (Was: RTBH Support Across the Industry)
On Tue, 4 Aug 2026 at 18:20, Michael Hare via NANOG <nanog@lists.nanog.org> wrote:
+1. Was going to follow up to Saku's message about how/if folks are doing that in JunOS [or other OS] natively without outside automation. Our backbone has scavenger style plp in BE, I control admission via prefix-list in ingress fwfilter on untrusted interfaces. Haven't personally tested but looks like DCU + forwarding-table export policy + output firewall filter, maybe this is possible today but requires output fwfilter to family mpls. I don't currently have a fwfilter there so ideally another option exists.
Something to this note, nothing really specific to any AFI: https://urldefense.com/v3/__https://raw.githubusercontent.com/job/draft- downgrade-bgp- community/refs/heads/main/nos/junos.txt__;!!Mak6IKo!IOVZQT4Lf7E7zL5MWS bICpNXJnyzuaVs2NnLxqdQJftUH3NI3k00Ws0VNddwQDb250bo4F95RdUFgnqM$
For context, remainder of QoS config would look something to: https://urldefense.com/v3/__https://p.ip.fi/Nott.txt__;!!Mak6IKo!IOVZQT4Lf7E... zL5MWSbICpNXJnyzuaVs2NnLxqdQJftUH3NI3k00Ws0VNddwQDb250bo4F95Rb4 m1HQV$
-- ++ytti