[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Source address selection insufficient?
In your previous mail you wrote:
> => I disagree a little because Cisco policy-based routing and Juniper
> filter-based forwarding share the same problem: they are based on ACLs
> and lack of dynamic capabilities. In fact they are only useful in the
> ingress filtering context.
What kind of dynamic capabilities would you looking for? Reaction to
the routing table?
=> exactly. This can save existing connections on some limited but
important in some cases (after some previous arrangements with your
ISPs).
But this is out of scope, so maybe you should follow up off-list.
=> I agree..
The point is that you can match against the source prefix, which is
what is required here.
=> my concern is that it is very hard or impossible to get more :-(
Regards
Francis.Dupont@enst-bretagne.fr