Re: BGP Roles: Transition to Transit Attribute

Robert Raszuk <[email protected]>
Newsgroups gmane.ietf.idr
Message-ID <CAOj+MMFOUJNfFO-3gE_biJVBJ+owyOKrVCg4gbgRJiSDGhSP5A@mail.gmail.com>
Hi Alexander,

I am assuming you mean "transitive" not "transit".

Still I have few main observations/questions:

A) How do you prevent spoofing (on purpose or by accident) content of this
attribute ? You you still need to validate by local policy check does it
really make sense to send this from the peer ?

B) Draft says:

   As opposed to communities, BGP attributes may not be generally
   modified or filtered by the operator.  The router(s) enforce them.
   This is the desired property for the OTC marking.  Hence, this
   document specifies OTC as an attribute.


Well take any attribute .. you can modify most of them with fancy policy
language. Even critical attributes like AS_PATH can be altered at will in
transit by most popular BGP implementations. So I guess if you count on
this one to be immutable make it clearly so as MUST in the draft.

C) How do you plan to handle aggregation of prefixes with different OTCs ?

Many thx,
R.


On Sun, Oct 6, 2019 at 10:40 PM Alexander Azimov <[email protected]>
wrote:

> Dear WG,
>
> As you might be aware, in the last version of the draft non-transit iOTC
> attribute was transformed into transit OTC, which covers both inner leak
> prevention and external leak detection. The authors believe that this way
> it will provide a complete solution, which will supplement other works in
> the field of securing BGP: ASPA and community-based leak detection.
>
> I want to believe that the draft is ready but there is an issue that
> should be resolved before WGLC. The code point was reserved by IANA to iOTC
> (Internal Only To Customer). I'd like to ask what is the proper process to
> reuse this code point for OTC. At the moment there are already two
> compatible implementations and another two are in progress.
>
> --
> Best regards,
> Alexander Azimov
> _______________________________________________
> Idr mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/idr
>

_______________________________________________
Idr mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/idr
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.