[RPKI] Accepting smaller routes than RPKI object allows (blackholing)

Chriztoffer Hansen chriztoffer at netravnen.de
Thu Aug 29 11:12:06 UTC 2019

On 29 August 2019 at 09:43:30 -00:00, Klimek, Denis <DKlimek at stadtwerke-norderstedt.de> wrote:

> Today I played around with RPKI against our customer BGP sessions and noticed that if a customer wants to send a /32 or /128 route to blackhole his traffic that this is not accepted due invalid rpki state.
> Why not re-configure your route-map to accept host routes. Before the RPKI state validation is done later in the route-map?



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.nlnetlabs.nl/pipermail/rpki/attachments/20190829/2a193bc0/attachment.htm>

More information about the RPKI mailing list