[Babel-users] [RFC] Replace WireGuard AllowedIPs with IP route attribute

Erin Shepherd bird-users at erinshepherd.net
Sat Nov 18 11:21:57 CET 2023


On Sat, 18 Nov 2023, at 03:19, Daniel Gröber wrote:
> Hi Alexander,
> 
> On Thu, Nov 09, 2023 at 12:57:26PM +0100, Alexander Zubkov wrote:
> > But as I understood the technology, it works only in one way (for
> > outgoing packets) and the decapsulation should be processed separately,
> > for example in case of VXLAN and MPLS they have their own tables.
> 
> That would be a problem as I specifically want to tie the source address
> filtering to this too. I'll have a look at the internals (if and) when I
> get around to starting work on this.

Is tying source address filtering to the routing table the right thing to do here? It seems to me that it would cause issues similar to those we see more generally with Unicast Reverse Path Filtering
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://trubka.network.cz/pipermail/bird-users/attachments/20231118/bddc33ef/attachment.htm>


More information about the Bird-users mailing list