We want to block Bogon networks sent or received via BGP. It seems like you can get this done by using a blackhole or by using a route-map with a prefix-list. However which of these is the "proper" way to do it?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I would use a prefix-list and any routes that match the public listed bogons you just flat out drop them. This is an rfc1918 or rfc6598 or unallocated networks. Build the prefix-list once and use it where required
http://socpuppet.blogspot.com/2014/01/how-to-verify-or-build-bogon-list.html
Ken Felix
PCNSE
NSE
StrongSwan
What I thought as well, I just saw a few other threads on here where people were using blackholes vs the prefix lists
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.