Alexander Vainshtein wrote on 04/09/2026 08:12:
E.g., a compromised Route Reflector could modify (or simply discard) the
BGP Prefix SID Attribute in routes of such families as VPN-IP or EVPN -
with a devastating effect on the services., while such an attack would
not have any impact on IP-VPN and EVPN services over MPLS underlay.
What, if anything, do I miss?
In practice, if you have a compromised RR, your entire network is fully
compromised.
In regard to a standards specification, a compromised RR would be out of
scope for the security section. It doesn't represent a failure or
security weakness specific to srv6.
Nick
_______________________________________________
spring mailing list -- [email protected]
To unsubscribe send an email to [email protected]