[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: New Version Notification for draft-ietf-v6ops-v6inixp-02



Hi,

On Mon, 5 Oct 2009 12:07:50 +0100
Roque Gagliano <roque@lacnic.net> wrote:

> [...] When considering the
>     routing of the IXP LANs two options are identified:
> 
>     o  IXPs may decide that LANs should not to be globally routed in
>        order to limit the possible origins of a Distributed Denial of
>        Service (DDoS) attack to its particpant' AS boundries.  In this
>        configuration participants may route these prefixes inside
> their networks (e. g. using BGP no-export communities or routing the  
> IXP
>        LANs within the participants' IGP) to perform fault management.
>        Using this configuration, the monitoring of the IXP LANs from
>        outside of its participants' AS boundaries is not possible.
> 
>     o  IXP may decide that LAN should be globally routed.  In this
> case, IXP LANs monitoring from outside its participants' AS
> boundries is
>        possible but the IXP LANs will be vulnerable to DDoS from  
> outside of
>        those boundaries.
> 

Although I have no problems with the content of this text, we should be
careful to limit this document to options and recommendations for IPv6
deployment in specific.

Since the above options are no different than those for IPv4 I believe
this piece of text does not need to be added.

Kind regards,
Martin