Alexander Vainshtein wrote on 04/09/2026 08:12:
E.g., a compromised Route Reflector could modify (or simply discard) the BGP Prefix SID Attribute in routes of such families as VPN-IP or EVPN - with a devastating effect on the services., while such an attack would not have any impact on IP-VPN and EVPN services over MPLS underlay.

What, if anything, do I miss?

In practice, if you have a compromised RR, your entire network is fully compromised.

In regard to a standards specification, a compromised RR would be out of scope for the security section. It doesn't represent a failure or security weakness specific to srv6.

Nick

_______________________________________________
spring mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to