On Thu, 14 Aug 2008, Hank Nussbacher wrote:

On Thu, 14 Aug 2008, Jon Lewis wrote:

That's basically what I ended up with yesterday in the simulator. My problem with it is, without inside knowledge of my upstream networks, how do I know which routes will never go away or never even just change mask? To be safer, if I end up doing this, I'll probably put half a dozen or so networks from each upstream in the access-list.

I suggest tracking one block and not a few. Finding the right one takes about 30 minutes of traceroutes from various LGs.

Since the access-list only needs to match any single listed route to work, why wouldn't you track several routes to be safer?

You can look at a few looking glasses and know that ProviderX will always announce some CIDR with the same netmask? That sounds like a neat trick.
Nobody ever deaggregates, right? :)

----------------------------------------------------------------------
 Jon Lewis                   |  I route
 Senior Network Engineer     |  therefore you are
 Atlantic Net                |
_________ http://www.lewis.org/~jlewis/pgp for PGP public key_________
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to