Re: How to validate blackhole routes? (Was: trouble letting go of IRR)
Saku Ytti via NANOG <[email protected]>
| Newsgroups | gmane.org.operators.nanog |
|---|---|
| Message-ID | <CAAeewD__7tsCN01xQr2abMyxLrovOkcFBsk=+cqVd30EHUW0=w@mail.gmail.com> |
On Mon, 2 Mar 2026 at 15:09, Job Snijders via NANOG <[email protected]> wrote: > I would benefit from a few more words on what exactly you mean with the > above. Do you mean to say that if the customer AS is 65535, you'd only > permit blackholes if they are contained within the prefixes for which > AS65535 is an authorized origin, according to RPKI ROAs? Sure, that > seems a reasonable precaution. Yes. Sort of pretending ROA allowed to /32 or whatever the specific may be, IFF there is a blackhole community attached. Ignoring active path. -- ++ytti _______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/[email protected]/message/TK6KESEBPS7HUPKSJTAWV235LI4FWZO7/