How-to – Simple automated blackholing – Part 5

Upstream/RTBH blackholing

RFC 7999

A simple way to achieve blackholing is when your upstreams support RFC 7999 so you can tag a /32 eBGP announcement with community 666, the upstreams router picks it up and blackholes the prefix on their own network. That is a very simple solution, especially if you have only Tier1 Upstreams and no other eBGP/external Routing like peering IX’s etc.

Continue reading