[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
BGP FlowSpec
On 2016-05-02 09:48 AM, Martin Bacher wrote:
>
> So filtering as precise as possible and as close as possible to the
> attack source is maybe the best option we have at the moment.
That was precisely my point! If an upstream isn't filtering at their
ingress (or their egress) the optimal place for me to filter is at my
ingress. Of course I'd rather have something akin to inter-domain
pushback or FlowSpec, etc.. But you can't control how, or assume others
will act on that.
-danny
- References:
- BGP FlowSpec
- From: danny at tcb.net (Danny McPherson)
- BGP FlowSpec
- From: outsider at scarynet.org (Alexander Maassen)
- BGP FlowSpec
- From: ti14m028 at technikum-wien.at (Martin Bacher)