Re: [nsp] Open BGP conection passively

From: Nobumichi Atobe (nobu@atobe.net)
Date: Tue Jun 11 2002 - 11:02:55 EDT


Thanks for your reply, Sean

When start peering with another ISP, the passive command would be nice.

Suppose ISP-A & ISP-B are going to peer with and ISP-B is filtering BGP
packets from not-peered source address to their bgp router, like ACL185 on
http://www.cymru.com/~robt/Docs/Articles/secure-bgp-template.html .
And if ISP-A configure before even ISP-B's configuration schedule is not fixed,
ACL violation logs would be shown continuously on ISP-B router,and this might
bother ISP-B ops.

If such passive configuration is implemented on cisco devices, I could say
"OK we have configured passively, you can start peering anytime you like" etc.

Am I too concerned about new neighbor? :)

Atobe

On Tue, 11 Jun 2002 08:46:52 -0500
"Sean Crocker" <crockers@mail.trinicom.com> wrote:

> Atobe,
>
> >I would like to know if cisco devices can configure opening BGP
> >connection passively or not, like Juniper's do like below.
> >http://www.juniper.net/techpubs/software/junos50/swconfig50-routing/html/bgp-config18.html
>
> No, it's all a matter of timing and which side opens the
> connection, although a misconfiguration of something like
> update source could effectively cause one side to never be
> the one to successfully start the peering, although it'll
> try to :-) I suppose it would be a neat knob, but what would
> you use it for?
>
> Sean
>
>



This archive was generated by hypermail 2b29 : Sun Aug 04 2002 - 04:13:46 EDT