Print

Print


Everyone should not be sending that range but if they are can the import filters for each bgp neighbor to ignore drop for that routes if one is received.  Just like the private IP list and AS list.



[log in to unmask] <[log in to unmask]>
2900 W. 10th St. | Sioux Falls, SD 57104
(w) 605.978.3558  | (c) 605.359-3737 | (tf) 800.247.1442
SDN NOC 877.287.8023
NOC Support email: [log in to unmask] <[log in to unmask]>

“Be Excellent to Each Other”

From: MICE Discuss [mailto:[log in to unmask]] On Behalf Of David Farmer
Sent: Thursday, December 1, 2016 10:12 PM
To: [log in to unmask]
Subject: Re: [MICE-DISCUSS] Participants leaking BGP routes for the MICE IXP Block

I didn't think of that variant, but that's why we discuss these kind of things.  I'm willing to give that a try.  Heck, I might even give people two or three strikes, especially if the actually respond to my email rather than ignore me. :)

However, I thought of one advantage of #4 after sending the email.  In the case on non-nuisance incidents, like an actual hijack event, everyone is notified immediately.  Otherwise, it has to wait for me to forward the email in the case of an actual event. BGPmon pages me, because the University has the paid service, but I'm only human and therefore fallible.

Any other comments?


On Thu, Dec 1, 2016 at 8:02 PM, Russell Berg <[log in to unmask]> wrote:
I agree... first strike private, second strike public.  Automatic if you don't want to be the transgressor tracker.

Russ

-----Original Message-----
From: MICE Discuss [mailto:[log in to unmask]] On Behalf Of Richard Laager
Sent: Thursday, December 01, 2016 8:00 PM
To: [log in to unmask]
Subject: Re: [MICE-DISCUSS] Participants leaking BGP routes for the MICE IXP Block

On 12/01/2016 06:56 PM, David Farmer wrote:
> 2. Notify transgressors PRIVATELY
> 3. Manually, Name and Shame transgressors 4. Automated, Name and Shame
> of transgressors (setup a BGPmon account to mail to MICE-DISCUSS)

If you are willing to do the work, I like 2, followed by 3. If you don't want to do the work, then 4.

--
Richard



--
===============================================
David Farmer               Email:[log in to unmask]
Networking & Telecommunication Services
Office of Information Technology
University of Minnesota
2218 University Ave SE        Phone: 612-626-0815
Minneapolis, MN 55414-3029   Cell: 612-812-9952
===============================================

________________________________

To unsubscribe from the MICE-DISCUSS list, click the following link:
http://lists.iphouse.net/cgi-bin/wa?SUBED1=MICE-DISCUSS&A=1

________________________________

***This message and any attachments are solely for the intended recipient. If you are not the intended recipient, disclosure, copying, use or distribution of the information included in this message is prohibited -- Please immediately and permanently delete.***