Better visibility into packet-dropping decisions
Better visibility into packet-dropping decisions
Posted Feb 27, 2022 23:43 UTC (Sun) by amarao (guest, #87073)Parent article: Better visibility into packet-dropping decisions
Posted Mar 2, 2022 3:25 UTC (Wed)
by MaZe (subscriber, #53908)
[Link] (2 responses)
Posted Mar 2, 2022 9:58 UTC (Wed)
by amarao (guest, #87073)
[Link]
Posted Jul 7, 2022 6:48 UTC (Thu)
by gdt (subscriber, #6284)
[Link]
Linux counting failed MD5 packets is excellent, as network operators investigating BGP connection issues can check that the counter is the expected zero.
For the longest time vendors were promoting IPsec as the replacement for the TCP MD5 option, but operationally the overhead of configuration and customer education was too high. More recently TCP-AO (Authentication Option) offers a similar mechanism to the MD5 option, but with modern cyrptographic algorithms.
For external BGP connections the TTL security check also offers good protection from network abuse. Customers generally seem to be able to configure that without much difficulty.
Better visibility into packet-dropping decisions
Better visibility into packet-dropping decisions
Better visibility into packet-dropping decisions
Cynically, if the BGP connection isn't using a long, random, unique key prior to that outage, then it will be afterwards :-)
