Got it

route filtering

Created: Sep 17, 2021 09:21:55Latest reply: Sep 25, 2021 17:36:00 363 4 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

What are the benefits of using route filtering?


Featured Answers

Best answer

Recommended answer

Vlada85
MVE Author Created Sep 17, 2021 09:26:54

Benefits of using route filtering:


Economic reasons

When a site is multihomed, announcing non-local routes to a neighbour different from the one it was learned from amounts to advertising the willingness to serve for transit, which is undesirable unless suitable agreements are in place. Applying output filtering on these routes avoids this issue.


Security reasons

An ISP will typically perform input filtering on routes learned from a customer to restrict them to the addresses actually assigned to that customer. Doing so makes address hijacking more difficult.

Similarly, an ISP will perform input filtering on routes learned from other ISPs to protect its customers from address hijacking.


Technical reasons

In some cases, routers have insufficient amounts of main memory to hold the full global BGP table. A simple work-around is to perform input filtering, thus limiting the local route database to a subset of the global table. This can be done by filtering on prefix length (eliminating all routes for prefixes longer than a given value), on AS count, or on some combination of the two; security is the most important point for this.

However, this practice is not recommended, as it can cause suboptimal routing or even communication failures with small networks[citation needed], and frustrate the traffic-engineering efforts of one's peers.

View more
  • x
  • convention:

All Answers
DDSN
DDSN Admin Created Sep 17, 2021 09:22:52

Hi hemin88,
Please wait patiently. Our engineers are looking for answers to your questions.
View more
  • x
  • convention:

Vlada85
Vlada85 MVE Author Created Sep 17, 2021 09:26:54

Benefits of using route filtering:


Economic reasons

When a site is multihomed, announcing non-local routes to a neighbour different from the one it was learned from amounts to advertising the willingness to serve for transit, which is undesirable unless suitable agreements are in place. Applying output filtering on these routes avoids this issue.


Security reasons

An ISP will typically perform input filtering on routes learned from a customer to restrict them to the addresses actually assigned to that customer. Doing so makes address hijacking more difficult.

Similarly, an ISP will perform input filtering on routes learned from other ISPs to protect its customers from address hijacking.


Technical reasons

In some cases, routers have insufficient amounts of main memory to hold the full global BGP table. A simple work-around is to perform input filtering, thus limiting the local route database to a subset of the global table. This can be done by filtering on prefix length (eliminating all routes for prefixes longer than a given value), on AS count, or on some combination of the two; security is the most important point for this.

However, this practice is not recommended, as it can cause suboptimal routing or even communication failures with small networks[citation needed], and frustrate the traffic-engineering efforts of one's peers.

View more
  • x
  • convention:

Good answer
View more
  • x
  • convention:

Great
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.