[c-nsp] BGP Filtering Policy with regular expressions

Michalis Palis security at cytanet.com.cy
Mon Jan 21 04:34:03 EST 2008


Hello all

I am trying to write a BGP policy using regular expressions for outgoing filtering. I need to allow customer AS numbers to be announced by our network as well as any prepends they send or any AS behind  our customer's AS.

e.g allow 

12345 678 9123
12345 12345 

etc....

I did try the follwing which seems to work but I am not sure if I will have any security problems.

^12345_      for AS12345 and anything behind AS12345


Any suggestions will be appreciated



More information about the cisco-nsp mailing list