Re: [j-nsp] CVE-2023-4481
Gert Doering via juniper-nsp <[email protected]>
| Newsgroups | gmane.network.nsp.juniper |
|---|---|
| Message-ID | <[email protected]> |
Hi,
On Sun, Sep 17, 2023 at 03:07:26PM +0200, Tobias Heister via juniper-nsp wrote:
> So, like with all features and knobs, you might want to consider whether it
> brings you any benefit to keep the prefixes in hidden state or "minimize"
> processing of things you will maybe never look at.
From an operational perspective, knowing that a given prefix *did* arrive
at the local router, and was then dropped (= hidden) for a specific reason
is very valuable. Without that information, you can only guess "did my
peer send it at all?" and troubleshooting *this* means "talk to people
outside your organization" which is way more time consuming than just
looking at hidden prefixes.
gert
--
"If was one thing all people took for granted, was conviction that if you
feed honest figures into a computer, honest figures come out. Never doubted
it myself till I met a computer with a sense of humor."
Robert A. Heinlein, The Moon is a Harsh Mistress
Gert Doering - Munich, Germany [email protected]
_______________________________________________
juniper-nsp mailing list [email protected]
https://puck.nether.net/mailman/listinfo/juniper-nsp
signature.asc
(application/pgp-signature, 630 B)
-----BEGIN PGP SIGNATURE----- iQGcBAEBAgAGBQJlBwSfAAoJEB2Cnv7KVigSBgcL/juNwvLNGoxtFldfIKIY4/6p SBnzBlO+5EMfStn5RK2yk+YRFLulHeG5s1P3EOi6z5zCcbn5dqS5s3BmhcgR0L+9 2+bVgLFY6bmXD6o0/wEKoNs1kYYQ9KlclaJ9VEuGnLtef97AEZ5Sx6kVY8yVGBOW N6QWFHJyJ8eDeiCKX0kOEJaqgnlsM+ZeN+weHDdePLQM7MryQ082oVm+EXJIBusM MsAgjPYURsGGx6T+I0zJExpUJfjX6g391DBfZ+8JsC7cUeSBNj9z3MY1DJFHjO5J +DI8ufjNe5gvN0k28kf9FmLWyzthTOh48zmw40Av2E/yuhIq2/NHrXocahiWp6Tt SkbQXiOwbaOcFPwCUZKGYOTbReysRskh5qksYOINy6h/QauvghgsIqZiicS8NT6K QCl7MOKxf4e5gbarUnedAA7pkzQY2PHXqN2Us0y8jBw8MNyKFnWvS/b25QyxbXFF zw4xN7IyyRe72pp2ylbEdydpu0kBcXjTMLeD/ZYupQ== =bsdC -----END PGP SIGNATURE-----