Re: Securing EBGP while getting rid of big IRR-based prefix-list-filters (Was: How long AS-PATH policies have you used)

Saku Ytti via NANOG <[email protected]>
Newsgroups gmane.org.operators.nanog
Message-ID <CAAeewD_AzUQp2isgQuC-4btjeBsVpqyxZoLoOO4gu5R468oDKQ@mail.gmail.com>
On Fri, 27 Feb 2026 at 11:29, Job Snijders via NANOG
<[email protected]> wrote:

> What exactly is 'secure' about an AS-SET? How can those two words be
> used in the same sentence? As I understand it AS-SETs are plain-text
> blobs of unknown provenance which contain entirely arbitrary data for
> unknown purposes that can change at a moments notice.

With AS-SET in practice most ports will have explicit prefix-lists
ensuring they can only send very small subset of all prefixes
possible.

Some are trash, but most are pretty good. For most ports, we offer in
practice very high guarantees on what they could possibly break by
UPDATE.

We can say that they can add anything to AS-SET, and we can say RPKI
does nothing, as they can set any origin. But we're not talking about
what it could be, we are talking about what it is, and it is doing a
lot and there is nothing else to reach anything close to its coverage
today.

If we are comfortable giving that away, because AS-SET could be
anything. I am all for it, less work for me. If my customers tell me
that it is not important to them, then I'm all for it.
-- 
  ++ytti
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/[email protected]/message/CVPC5BSDOZW7RACUGA33ZXFCAWH3KKPY/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.