Destination-IP-Origin-AS Filter for BGP Flow Specification
Robert Raszuk <[email protected]> Mon, 4 Nov 2019 18:50:29 +0100
| Newsgroups | gmane.ietf.idr |
|---|---|
| Message-ID | <CAOj+MMHLFxe94chd1woN74KeJy3UQa2mfSjXjrE7uudPBDw6KQ@mail.gmail.com> |
Dear Authors of draft-wang-idr-flowspec-dip-origin-as-filter
After reading this document with interest I am scared !
*You have constructed a fantastic tool to hijack traffic to any AS or for
that matter balckhole it completely with surgical precision. *
Yet the draft does not say a word about validation of such filters. In fact
it describes use cases where validation would not be done as no destination
IP address would be present at all. Section 4 just illustrates DST ASN +
SRC IP.
Technically you highlight the value of the proposal by stating that R1
needs to install only one rule in the data plane:
Using the method defining in this draft, the ISP AS64597 needs to
setup only *one "Destination Origin AS + Source Prefix" rule in Router
R1 as following:
*
+--------------+--------------+-------------------------+
| Destination | Source Prefix| Redirect to IP Nexthop |
| IP Origin AS | | |
+--------------+--------------+-------------------------+
| 64598 | IP Prefix 61 | R3 |
+--------------+--------------+-------------------------+
Figure 3: Steering the Traffic Using Origin AS and Source Prefix
Well packets do not carry ASNs so that may be a bit tricky for the data
plane.
I assume you mean that router will explode given Dst ASN into all atomic
BGP destination announcements either by BGP AS_PATH match or by RIR/RPKI
lookup. So effectively one such control plane rule may result in 100s of
not 1000s of data plane match rules.
And at the end you state:
*5. Security Considerations No new security issues are introduced to the
BGP protocol by this specification.*
IMHO this proposal both on security and technical grounds should not
proceed any further.
Many Thx,
Robert.
_______________________________________________
Idr mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/idr