Index | Thread | Search

From:
Job Snijders <job@bsd.nl>
Subject:
etc/examples/bgpd.conf: add ASPA
To:
tech@openbsd.org
Date:
Thu, 11 Jun 2026 19:42:25 +0000

Download raw body.

Thread
  • Job Snijders:

    etc/examples/bgpd.conf: add ASPA

Now that the novelty has worn off, let's add ASPA filtering to the
bgpd.conf example. Perhaps like so?


Index: bgpd.conf
===================================================================
RCS file: /cvs/src/etc/examples/bgpd.conf,v
diff -u -p -r1.26 bgpd.conf
--- bgpd.conf	18 Dec 2024 16:00:26 -0000	1.26
+++ bgpd.conf	11 Jun 2026 19:40:18 -0000
@@ -118,7 +118,8 @@ match from ebgp community GRACEFUL_SHUTD
 deny quick from any prefix-set bogons
 
 # deny RPKI invalid, built by rpki-client(8), see root crontab
-deny quick from ebgp ovs invalid
+deny quick from ebgp ovs invalid	# deny ROA-invalids
+deny quick from ebgp avs invalid	# deny ASPA-invalids
 
 # filter bogon AS numbers
 # AS_TRANS (23456) is not supposed to show up in any path and indicates a