[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [lisp-interest] LISP-ALT and security



bensons@riot.queuefull.net wrote:
Though, the replying eTR may not represent the whole RIR-assigned prefix. Perhaps you're saying that the RIR would sign a statement indicating how the LIR may/will allocate subnets (I.e. /24 nets) from the supernet? And these would be distributed to iTR nodes beforehand or looked up against a directory or table on the fly? That doesn't sound practical, but maybe I don't understand correctly.

From a security perspective there isn't an issue with allowing an ETR who has authority to speak for /22 EID prefix to provide separate information (priorities, weights, even RLOCs) for different sub-sets of that /22.

(It might have an impact on scaling, but that is a different matter.)

   Erik