On Fri, Aug 17, 2012 at 12:43:32PM +0100, Nick Hilliard wrote:
> - put in an implicit deny for all bgp sessions without an explicit filter
> on them

XR does that for EBGP:

"External BGP (eBGP) neighbors must have an inbound and an outbound
policy configured. If no policy is configured, no routes will be
accepted from the neighbor, nor will any routes be advertised to it.
This added security measure ensures that routes cannot accidentally be
accepted or advertised in the case where a configuration error results
in the intended policy being rejected.

This enforcement affects only eBGP neighbors (neighbors in a different
autonomous system than this networking device). For internal BGP (iBGP)
neighbors (neighbors in the same autonomous system), all routes will be
accepted or advertised if there is no policy."

