[c-nsp] Sinkhole Routing

Per Carlson ml at carlson.homeunix.net
Wed Sep 29 09:44:52 EDT 2004


On 2004-09-29 15:04, Pete Templin wrote:
> I've also heard of scenarios where a customer will announce their entire 
> aggregate with the blackhole tag, and then generate more specific 
> announcements without.  The provider accepts the aggregate, processes it 
> internally as blackhole, and advertises it to their friends and 
> neighbors normally.  The provider also accepts the more specifics, 
> passes them throughout their network, and allows the more specific 
> announcement to override the "default" blackhole behavior.

IMHO, this is not the proper to do it. I wouldn't like to be the one who 
extracts a /32 host out of a /16 network.... Why denying *all* traffic, 
and then specifically permit almost every thing?

The opposite, as Wojtek proposes, do make sense. It's much easier to 
just deny a single host. To make it even more attractive to the NOC 
staff, set up a UNIX-host with Quagga (or Zebra) and build some easy to 
use web-interface.

Per






More information about the cisco-nsp mailing list