[c-nsp] Peering + Transit Circuits

Lukas Tribus luky-37 at hotmail.com
Tue Aug 18 17:31:42 EDT 2015


> On 18/08/2015 21:56, Gert Doering wrote:
>> So how's that stopping one of your bilateral peers from sending you
>> traffic destined elsewhere?
> 
> it doesn't: you detect it and depeer them.  If they force the situation
> with static routes, the traffic will be dropped.

But thats kind of the point of this whole thing: avoiding abuse without
having the rely on complex detection mechanisms, isn't it?

If you need to detect anyway, than you may us well just use a blacklist
approach instead of whitelisting your peers.


Lukas


 		 	   		  


More information about the cisco-nsp mailing list