HI Folks, One of our colleagues from AUSNOG mentioned this, and I thought it'd be worth reposting here as I'd imagine it's required reading for many of you (which I'm sure you have of course!). Cheers jamie RFC7454 - "BGP Operations and Security" https://tools.ietf.org/html/rfc7454 "Abstract The Border Gateway Protocol (BGP) is the protocol almost exclusively used in the Internet to exchange routing information between network domains. Due to this central nature, it is important to understand the security measures that can and should be deployed to prevent accidental or intentional routing disturbances. This document describes measures to protect the BGP sessions itself such as Time to Live (TTL), the TCP Authentication Option (TCP-AO), and control-plane filtering. It also describes measures to better control the flow of routing information, using prefix filtering and automation of prefix filters, max-prefix filtering, Autonomous System (AS) path filtering, route flap dampening, and BGP community scrubbing."
In a similar vein, You all might like the Routing Resilience Manifesto https://www.routingmanifesto.org/manrs/
On 16 Apr 2015, at 15:27, Jamie Baddeley wrote:
I really need to rev this, but it may be of interest, as well:
https://app.box.com/s/osk4po8ietn1zrjjmn8b
-----------------------------------
Roland Dobbins
participants (3)
-
Andy Linton
-
Jamie Baddeley
-
Roland Dobbins