ietf-wg-idr / draft-ietf-idr-5g-edge-service-metadata

Editing for the 5G Service Metadata
0 stars 2 forks source link

The Security Consideration addition to ensure boundary nodes not leaking Metadata on accident #10

Closed lindadunbar closed 8 months ago

lindadunbar commented 8 months ago

Jeff Haas suggested that RR attaching NO-ADVERTISE well-known community to the UPDATE when sending the UPDATE to the ingress routers.

lindadunbar commented 8 months ago

The following paragraphs have been added to the Security Consideration of -v15:

To prevent the BGP UPDATE receivers (a.k.a. ingress routers in this document) from leaking the Metadata Path Attribute by accident to nodes outside the trusted domain [ATTRIBUTE-ESCAPE], the following practice should be enforced: