Montgomery,

Let me try to clarify.

As per my understanding the proposed solution suggests to filter
incoming traffic by applying uRPF at the edges.
That is a very good approach, everyone should perform at least loose
uRPF in their networks.

But it also goes further and suggest to amend the usual behavior by
advertising via BGP the source addresses of the traffic you want to
drop so that the routers can null route and trigger uRPF.
This is where i see problems.

Carriers cannot do that as they cannot drop ALL the traffic from a
certain source if the request is not coming from the owner.
And i can't see why the owner should ask to do that to their upstreams.
It would be easier/cheaper to do that in-house.

Contents are usually targets, not sources and it's easier/cheaper for
them to halt the VM or shut the port on the switch that signaling null
route via BGP.
(I am not an expert, so please correct me if i am wrong)

Then we have eyeballs.
I can't see why an eyeball would decide to completely null-route
packets coming from their customers.
Yet again it would probably be easier/cheaper to disconnect the port.

Last we have IXPs.
Which, to me, should have the very same concerns carriers have.

So, even if this may be a good solution on paper, i can't find a
scenario where you can apply it.

Regards

On Thu, Nov 10, 2016 at 4:08 PM, Montgomery, Douglas (Fed)
<[email protected]> wrote:
> Marco,
>
> Also might we distinguish if you are referring to spoofed packets, which
> is what uRPF is about?  Non-spoofed DDoS, both in-bound and out-bound is
> not something that BCP-84 addresses.  That problem still exists and still
> must be dealt with by other means.
>
> Given the prelevence of reflection DDoS attacks in the Internet today,
> focusing on mitigating those attacks that rely on IP-spoofing seems worth
> while.
>
> dougm
> —
> Doug Montgomery, Mgr Internet & Scalable Systems Research at  NIST/ITL/ANTD
>
>
>
>
>
> On 11/9/16, 1:17 PM, "GROW on behalf of Sriram, Kotikalapudi (Fed)"
> <[email protected] on behalf of [email protected]> wrote:
>
>>>I am not sure if anyone would ever deploy such mechanism.
>>>For contents it's useless as they have to filter DDoSes before they
>>>reach their network.
>>>For carriers is poorly scalable as they'd have to configure thousands of
>>>prefixes.
>>>It could make sense for eyeballs but they hardly would drop all the
>>>traffic
>>>from their customers even if they're participating in a DDoS
>>>(also note that inbound customer traffic is rarely an issue for eyeballs)
>>
>>Marco,
>>
>>Can you please clarify for me the following?
>>1. Are your comments directed at uRPF (BCP-84) in general?
>>2. If not, are they directed specifically at strict or feasible-path uRPF?
>>
>>Once I get clarity into that I think I can better address your concerns.
>>
>>Thanks.
>>Sriram
>>
>>
>>_______________________________________________
>>GROW mailing list
>>[email protected]
>>https://www.ietf.org/mailman/listinfo/grow
>



-- 
Marco

_______________________________________________
GROW mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/grow

Reply via email to