Tuesday, January 19, 2010

New network allocations from IANA - Update your BOGON Filters

For all you network administrators and network engineers out there, it is time to update your Bogon filters to allow for IANA's recent IP address allocations. IANA allocated blocks 1.0.0.0/8 and 27.0.0.0/8 and placed in reservation 198.51.100.0/24 and 203.0.113.0/24. For those of you who don't know what I am talking about, a BOGON is an IP packet that "claims" to be from a portion of the IP address space that has not been allocated by IANA for public use. Such packets are often the result of misconfigurations of network equipment, or sometimes even used intentionally in various types of internet based attacks. There are a couple ways to filter for bogon traffic entering and leaving your network. The first way involves the creation of ACLs applied on your border router's ingress and egress interfaces. The second way is a bit more elaborate and automated but requires a little more technical skill and trust and this is by establishing a BGP session with organizations such as Team Cymru such that you receive routes from them that black hole bogon traffic. For more information visit Team Cymru and protect your network from this illegitimate traffic.