[j-nsp] Juniper BGP invalid attributes

Andy Vance avance at hq.speakeasy.net
Tue Mar 17 23:46:06 EDT 2009


Richard,

Appears these are the releases that it has been fixed in.

8-1-4p0-4, 8-2-4p0-7, 9-0-2p0-1, 9-1-2p0-1, 9-2-1p0-1, 9-3-0p0-1, 10-0-0

This caused us problems this evening as well and some issues we continue to work on with JTAC at this time.

Andy

-----Original Message-----
From: juniper-nsp-bounces at puck.nether.net [mailto:juniper-nsp-bounces at puck.nether.net] On Behalf Of Richard A Steenbergen
Sent: Tuesday, March 17, 2009 6:23 PM
To: Richard A Steenbergen
Cc: juniper-nsp at puck.nether.net
Subject: Re: [j-nsp] Juniper BGP invalid attributes

On Tue, Mar 17, 2009 at 07:54:37PM -0500, Richard A Steenbergen wrote:
> Who else just noticed Juniper bgp sessions all over the place flapping
> with:
> 
> code 3 (Update Message Error) subcode 1 (invalid attribute list) code 
> 3 (Update Message Error) subcode 11 (AS path attribute problem) 
> Received BAD update for family inet-unicast(1), prefix 193.5.68.0/23

Ok got some packet captures of the invalid update, it looks like
193.5.68.0/23 was being announced and propagated globally with the leaked confederations in AS4_PATH issue described in PSN-2009-01-200.

What code has the fix for this issue? The PSN doesn't say. Since these invalid attributes are now leaking out globally, it might be worth an update. :)

-- 
Richard A Steenbergen <ras at e-gerbil.net>       http://www.e-gerbil.net/ras
GPG Key ID: 0xF8B12CBC (7535 7F59 8204 ED1F CC1C 53AF 4C41 5ECA F8B1 2CBC) _______________________________________________
juniper-nsp mailing list juniper-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp


More information about the juniper-nsp mailing list