[c-nsp] BGP MD5 DDOS ?

Chuck Church chuckchurch at gmail.com
Fri Sep 14 17:55:08 EDT 2012


It came up 2 or 3 years ago I seem to remember.  ACLs to verify the BGP
endpoints are a good first line of defense.   Cisco came up with a feature
that seems to help as well, see below.  Some people are for MD5, some feel
it has no value...

http://www.cisco.com/en/US/docs/ios/12_3t/12_3t7/feature/guide/gt_btsh.html

Chuck

-----Original Message-----
From: cisco-nsp-bounces at puck.nether.net
[mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of John Brown
Sent: Friday, September 14, 2012 4:00 PM
To: cisco-nsp at puck.nether.net
Subject: [c-nsp] BGP MD5 DDOS ?

Hi Folks,

I remember reading / hearing that using a BGP password could cause a DDOS
vulnerability with Cisco and other vendor devices.

Any words of wisdom here ??

Thanks


_______________________________________________
cisco-nsp mailing list  cisco-nsp at puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/



More information about the cisco-nsp mailing list