asymmetric routing

David Terrell David Terrell <dbt@meat.net>
Tue, 29 Jan 2002 01:56:47 -0800


On Mon, Jan 28, 2002 at 08:50:38AM +0100, JOIN Project Team wrote:
> Am Sonntag, 27. Januar 2002 18:06 schrieb Francis Dupont:
> > Basically RFC 2827 / BCP 38 about Ingress Filtering should be used
> > for IPv6 too. There are two ways to do ingress filtering: access lists
> > and unicast RPF.
> 
> I don't think it's that easy. Please keep in mind, that a site/customer
> might be multihomed. In that case he might use a different prefix from that 
> assigned by the upstream provider as source address. 
> 
> Yes, one could filter all but those prefixes a customer holds, but then the
> customer has to name all his providers/prefixes. You can't force a customer
> to do so, because that information might be confidential.

If my customer doesn't want me to know what prefixes he owns, he
shouldn't send traffic from them to me, or I'll know.

-- 
David Terrell           | "Anyone want to start a fund for students
Nebcorp Prime Minister  | that vow not to work at MS?"
dbt@meat.net            |  - Libor Michalek
http://wwn.nebcorp.com/