Re: AS8584 taking over the internet
Wait, the horse is dead and partially dismembered, but we're still whacking away. Hopefully this will target the blows at the parts that are still not jelly. 1) Filtering is a good idea. If everyone did it, it would be a great idea. Getting everyone in the Internet to do anything is impossible, so maybe it's not the most useful solution. 2) there are groups working on ways to do announcement AS verification. there are two efforts in the IETF right now, in the RPS and IDR working groups. These will allow people to do distant source verification. These solutions look far more promising to me that saying everyone should filter. There is work beyond either of these proposals that gets harder, but both of these look to do a big chunk of problem for accidents like this. Harping just a little more, unless the IP registries take the lead and push their hierarchical allocation tree data out and ISPs pick it up and do useful filtering with it, this problem will continue to occur regularly. Talk to your registry and your router vendors to start getting the pieces in place to get a global solution. I think it is safe to say that more mail on NANOG saying people should neighbor filter will not solve this problem. Lets work on things that will. jerry
I think it is safe to say that more mail on NANOG saying people should neighbor filter will not solve this problem. Lets work on things that will.
Not in itself as there are people who don't care, don't read NANOG, and/or don't listen, and/or are hard of understanding. But people insisting that peers filter their customers, using whether or not they filter as a selection criterion (i.e. how vulnerable they are to one of their own customers), and insisting their downstreams filter, would be a good start. Without pointing specific fingers there are some quite large AS's, who have peering with some large networks with no or little peer to peer filtering, who also demonstrably have no customer filtering. This means the peer gets polluted. Obviously either peer to peer or customer filtering solves this one. But filtering *is* a good thing, and it is important people exert pressure to make it happen. I don't think you can replace *filtering* by origin verification. Sure, the more belts and braces the better. -- Alex Bligh GX Networks (formerly Xara Networks)
participants (2)
-
Alex Bligh
-
Jerry Scharf