asymmetric routing
David Terrell
David Terrell <dbt@meat.net>
Tue, 29 Jan 2002 01:56:47 -0800
On Mon, Jan 28, 2002 at 08:50:38AM +0100, JOIN Project Team wrote:
> Am Sonntag, 27. Januar 2002 18:06 schrieb Francis Dupont:
> > Basically RFC 2827 / BCP 38 about Ingress Filtering should be used
> > for IPv6 too. There are two ways to do ingress filtering: access lists
> > and unicast RPF.
>
> I don't think it's that easy. Please keep in mind, that a site/customer
> might be multihomed. In that case he might use a different prefix from that
> assigned by the upstream provider as source address.
>
> Yes, one could filter all but those prefixes a customer holds, but then the
> customer has to name all his providers/prefixes. You can't force a customer
> to do so, because that information might be confidential.
If my customer doesn't want me to know what prefixes he owns, he
shouldn't send traffic from them to me, or I'll know.
--
David Terrell | "Anyone want to start a fund for students
Nebcorp Prime Minister | that vow not to work at MS?"
dbt@meat.net | - Libor Michalek
http://wwn.nebcorp.com/