RIPE-555 fundamentaly changes the way how we can filter IPv6 & IPv4 martians?

Chris Welti chris.welti at switch.ch
Thu Jul 12 10:05:44 CEST 2012


Hi Mikael.

Am 7/11/12 7:21 PM, schrieb Mikael Abrahamsson:
> On Wed, 11 Jul 2012, Chris Welti wrote:
> 
>> Since I can not rely on the fact that longer prefix lengths just
>> happen in certain well defined ranges (minimum allocation per
>> address range) anymore, I see only three possibilites:
> 
> Why can't you rely on that?
> 
> https://www.ripe.net/ripe/docs/ripe-555
> 
> "The IPv6 PI assignments smaller than a /32 are taken from
> 2001:678::/29."
> 
> So if you don't care about IXP networks in DFZ, then you just allow
> /32s and larger from all of RIPE space, and /48 and larger from this
> /29 and you're golden.
> 

Two reasons:
1) As you say, this only applies to IPv6 PI assignments. But I also care about 
IXP networks, Root Name servers and Anycast TLDs.

2) I'm a bit worried that people will get the impression from RIPE-555 that they can just
get away with announcing several /48 out of their /32 without the covering /32 itself.
That would break connectivity to "normal" networks when relying on such filtering in the DFZ.

Apart from that there is the issue of filtering IPv4 prefixes, which is a lot worse now.

Regards,
Chris


More information about the ipv6-ops mailing list