Hi Thomas,

we have seen similar effects in the past. I remember a case, where a
router with Trident cards and 4.3.1 (and newer routers around it) got
stuck in a situation similar to yours. It even tried to forward packets
to a port that was admin-down.

> Do you drop BGP updates on ingress with "as-path length ge 51" please? -not 
> only it's a good practice, but apparently long as-paths caused RIB-FIB 
> clogging in the past.

This fixed our problem. After a whole night of debugging, I found this
mail thread, "[c-nsp] CEF issues this weekend".

Some AS announced a prefix and prepended >500 times.

Since then, we filter for as-path-length on ingress everywhere and
haven't seen this behavior again.

Best regards,
Sebastian
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to