Re: BGP38 egress filter on Ubuntu Server

2021-06-02 Thread Grant Taylor via NANOG
On 6/2/21 12:39 AM, William Herrin wrote: I think you may be misunderstanding BCP 38. BCP 38 is about limiting -source- addresses. What you've described is bogon filtering on destination IP addresses. As far as I know, there's no BCP on bogon filtering although BCP 84 offers some relevant advic

Re: BGP38 egress filter on Ubuntu Server

2021-06-01 Thread William Herrin
On Tue, Jun 1, 2021 at 1:47 PM Stephen Satchell wrote: > Before I re-invent the wheel, has anyone come up with blackhole route > specifications for netplan in Ubuntu servers? Such a capability would > perform the egress blocking for an edge server. > > The table of blackhole routes I would set up

Re: BGP38 egress filter on Ubuntu Server

2021-06-01 Thread Chriztoffer Hansen
On Tue, 1 Jun 2021 at 22:58, Chriztoffer Hansen wrote: > https://team-cymru.com/community-services/bogon-reference/bogon-reference-http/ I have found that pfSense uses this feed to filter traffic if 'Block bogon networks' is enabled on the WAN interface(s). I.e. the pfSense bogons + bogonsv6 tab

Re: BGP38 egress filter on Ubuntu Server

2021-06-01 Thread Chriztoffer Hansen
On Tue, 1 Jun 2021 at 22:43, Stephen Satchell wrote: > Before I re-invent the wheel, has anyone come up with blackhole route > specifications for netplan in Ubuntu servers? Such a capability would > perform the egress blocking for an edge server. https://team-cymru.com/community-services/bogon-r