|
|
<- Previous Message | Next Message -> Thread Index
RE: Application Note: Securing BGP on Juniper Routers
Correction... remove-private will remove the leftmost private ASNs.
-- steve
-----Original Message-----
From: Stephen Gill [mailto:gillsr@...Sent: Monday, June 24, 2002 12:46 AM
To: 'ISP-BGP Discussion List'; 'fscalzo-isp@...'
Subject: Re: Application Note: Securing BGP on Juniper Routers
In reference to your comments...
1. The static discard routes are there to remove all ambiguity when a
0/0 route exists. If your network does not have a default route and you
have all Internet routes, then yes you can join the two. In this case,
we use a 0/0 route and thus would like to make sure that nothing squeaks
by.
2. Actually, Juniper does not install all equal cost paths into the
forwarding table by default. It selects one at random.
http://www.juniper.net/techpubs/software/junos53/swconfig53-routing/html
/routing-generic-config10.html
Flow based load balancing is definitely a good thing.
3. There are benefits and drawbacks to out-delay. If your network is
configured in a way that avoids oscillation, then this is not necessary.
Out delay may delay convergence or delay oscillation depending on your
network :).
4. The remove-private command in the template takes care of this.
Routes will not get advertised w/o having them removed.
Cheers,
-- steve
<- Previous Message | Next Message -> Thread Index
|
|