Re: BGP Roles: Transition to Transit Attribute
Robert Raszuk <[email protected]>
| Newsgroups | gmane.ietf.idr |
|---|---|
| Message-ID | <CAOj+MMFOUJNfFO-3gE_biJVBJ+owyOKrVCg4gbgRJiSDGhSP5A@mail.gmail.com> |
Hi Alexander, I am assuming you mean "transitive" not "transit". Still I have few main observations/questions: A) How do you prevent spoofing (on purpose or by accident) content of this attribute ? You you still need to validate by local policy check does it really make sense to send this from the peer ? B) Draft says: As opposed to communities, BGP attributes may not be generally modified or filtered by the operator. The router(s) enforce them. This is the desired property for the OTC marking. Hence, this document specifies OTC as an attribute. Well take any attribute .. you can modify most of them with fancy policy language. Even critical attributes like AS_PATH can be altered at will in transit by most popular BGP implementations. So I guess if you count on this one to be immutable make it clearly so as MUST in the draft. C) How do you plan to handle aggregation of prefixes with different OTCs ? Many thx, R. On Sun, Oct 6, 2019 at 10:40 PM Alexander Azimov <[email protected]> wrote: > Dear WG, > > As you might be aware, in the last version of the draft non-transit iOTC > attribute was transformed into transit OTC, which covers both inner leak > prevention and external leak detection. The authors believe that this way > it will provide a complete solution, which will supplement other works in > the field of securing BGP: ASPA and community-based leak detection. > > I want to believe that the draft is ready but there is an issue that > should be resolved before WGLC. The code point was reserved by IANA to iOTC > (Internal Only To Customer). I'd like to ask what is the proper process to > reuse this code point for OTC. At the moment there are already two > compatible implementations and another two are in progress. > > -- > Best regards, > Alexander Azimov > _______________________________________________ > Idr mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/idr > _______________________________________________ Idr mailing list [email protected] https://www.ietf.org/mailman/listinfo/idr