Discussion:
[j-nsp] Which BOGON filter strategy you would recommend IPv4 and IPv6
Alexander Marhold
2016-02-16 07:49:07 UTC
Permalink
Hi !



My customer is a bigger company with customers around the world, which
recently connected directly to 4 upstream providers and 1 IX via MX router
and BGP



Now by searching the internet and googling I do not know which method to
use to have up-to date BOGON filtering for IPv4 AND IPV6 (yes IPv6 is
necessary)



I found things like spamhaus, team-cymru.org .



It seems that IPv6 is still less treated than IPv4



What do you recommend, and which way to get the lists and how often is an
update needed

Or is it better to try a dynamic solution via bgp-peering ?



With best regards



alexander





_______________________________________________
juniper-nsp mailing list juniper-***@puck.nether.net
https://puck.nether.net/mailman/listinfo/juniper-nsp
Tomasz Mikołajek
2016-02-16 07:59:57 UTC
Permalink
Help.
I use in my network feed from team cymru. Rasy way to get bogom prefixes.
It is free so don't requier 100% uptime. ;-) Moste of the time BGP session
is establish.
Post by Alexander Marhold
Hi !
My customer is a bigger company with customers around the world, which
recently connected directly to 4 upstream providers and 1 IX via MX router
and BGP
Now by searching the internet and googling I do not know which method to
use to have up-to date BOGON filtering for IPv4 AND IPV6 (yes IPv6 is
necessary)
I found things like spamhaus, team-cymru.org .
It seems that IPv6 is still less treated than IPv4
What do you recommend, and which way to get the lists and how often is an
update needed
Or is it better to try a dynamic solution via bgp-peering ?
With best regards
alexander
_______________________________________________
https://puck.nether.net/mailman/listinfo/juniper-nsp
_______________________________________________
juniper-nsp mailing list juniper-***@puck.nether.net
https://puck.nether.net/mailman/listinfo/junip
Saku Ytti
2016-02-16 11:37:05 UTC
Permalink
On 16 February 2016 at 09:49, Alexander Marhold
<***@gmx.at> wrote:

Hey,
Post by Alexander Marhold
What do you recommend, and which way to get the lists and how often is an
update needed
I recommend bogonising only statically bogons, which never change. No
unallocated bogonising (calling those bogons is false anyhow), it has
brought lot more harm than good.
--
++ytti
_______________________________________________
juniper-nsp mailing list juniper-***@puck.nether.net
https://puck.nether.net/mailman/listinfo/juniper-nsp
Dave Bell
2016-02-16 11:48:46 UTC
Permalink
Hi,

I would follow RFC 6890 when creating my bogon list. I would be a bit
nervous about taking a BGP feed of bogons from a 3rd party in case
they were compromised, and valid address space was introduced into, or
invalid address space was removed from their feed.

Regards,
Dave
Post by Saku Ytti
On 16 February 2016 at 09:49, Alexander Marhold
Hey,
Post by Alexander Marhold
What do you recommend, and which way to get the lists and how often is an
update needed
I recommend bogonising only statically bogons, which never change. No
unallocated bogonising (calling those bogons is false anyhow), it has
brought lot more harm than good.
--
++ytti
_______________________________________________
https://puck.nether.net/mailman/listinfo/juniper-nsp
_______________________________________________
juniper-nsp mailing list juniper-***@puck.nether.net
https://puck.nether.net/mailman/listinfo/juniper-nsp
Jackson, William
2016-02-16 14:15:57 UTC
Permalink
Bogons still do a BGP feed with many deaggregated prefixes.

http://www.team-cymru.org/bogon-reference.html ( FULLBOGONS )

William Jackson

-----Original Message-----
From: juniper-nsp [mailto:juniper-nsp-***@puck.nether.net] On Behalf Of Alexander Marhold
Sent: 16 February 2016 08:50
To: juniper-***@puck.nether.net
Subject: [j-nsp] Which BOGON filter strategy you would recommend IPv4 and IPv6

Hi !



My customer is a bigger company with customers around the world, which recently connected directly to 4 upstream providers and 1 IX via MX router and BGP



Now by searching the internet and googling I do not know which method to use to have up-to date BOGON filtering for IPv4 AND IPV6 (yes IPv6 is
necessary)



I found things like spamhaus, team-cymru.org .



It seems that IPv6 is still less treated than IPv4



What do you recommend, and which way to get the lists and how often is an update needed

Or is it better to try a dynamic solution via bgp-peering ?



With best regards



alexander

Loading...