[GROW] Re: A well-known DOWNGRADE BGP Community
James Bensley <lists+ietfgrow@bensley.me> Tue, 25 August 2026 15:58 UTC
Return-Path: <lists+ietfgrow@bensley.me>
X-Original-To: grow@mail2.ietf.org
Delivered-To: grow@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 125C712F23876 for <grow@mail2.ietf.org>; Tue, 25 Aug 2026 08:58:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787673511; bh=kN0/Dd4/iNdnu4Zm4/GuC+opqtsm7Qmnn/dOgLSCF30=; h=Date:To:From:Subject:In-Reply-To:References; b=LTeFvIRYvoAdmHsZTzZyJS3rEOlw3e8/WPmoqod9MJpvTIg9xOs6bn4bx9VDYthFF ENtvp+UtVx+WGgTMc9+G5YdmxiyanhuQY5szaLxGrI6HH+PePweblGpOlX6wWhq754 Q96JKc2PPO3eLw0m2D0jeNwDvdkPmNH/hkEzpZ6A=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.797
X-Spam-Level:
X-Spam-Status: No, score=-2.797 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=bensley.me
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XD2c2hE7h1rg for <grow@mail2.ietf.org>; Tue, 25 Aug 2026 08:58:29 -0700 (PDT)
Received: from mail-4318.protonmail.ch (mail-4318.protonmail.ch [185.70.43.18]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 74B0B12F237EB for <grow@ietf.org>; Tue, 25 Aug 2026 08:58:28 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bensley.me; s=protonmail2; t=1787673505; x=1787932705; bh=DDrDUleg1SYvd/fz2SrOt/dGw5vi5DcFnztH6Q8iPVw=; h=Date:To:From:Subject:Message-ID:In-Reply-To:References: Feedback-ID:From:To:Cc:Date:Subject:Reply-To:Feedback-ID: Message-ID:BIMI-Selector; b=EV5L4rpUMmK5X5PEjoUIHY42J+v8NGnSd+Yg4YOeMOa/rwjNp4By5Bzm74/NrQIKO /FhssPeMz+3xUr+5gzq3rGXKfZI1VKUujl/+amWr+VmDnntp8iJ3CFI7IjgfrN0DKu KnOXOTghqm5pof0tiUOyMXaSgoNXBie1OevOV42Cr1lGNG6NMYeb+Cb0G46ZwnSzLI Gu9GiIhDsFuqp8Se+rhooir9di9IENZSdcsrsepDjX9wJCmRnop2WRFwYtg12StWxH dTCzj9tYLKQrNAn6YG0gKdy2WZo8c6DziIoh1JjL8uMv2e5Ssc3xLGbr7Cjsa0sy8K c01pEt3OMlt1Q==
Date: Tue, 25 Aug 2026 15:58:19 +0000
To: grow@ietf.org, ytti@ntt.net, Job Snijders <job=40bsd.nl@dmarc.ietf.org>
From: James Bensley <lists+ietfgrow@bensley.me>
Message-ID: <2BmnqtDBH_j7ddkDCQImH_-4UrGJjNoCMR31gDmy3D-DvI6OL3JkBT988Xp97xd4LRXgUDct6wxwG0otBTQ-4a9Jxoaw6GcMZm1cMly1-TU=@bensley.me>
In-Reply-To: <anHsf6n-7jHvppuN@feather.sobornost.net>
References: <anHsf6n-7jHvppuN@feather.sobornost.net>
Feedback-ID: 49756985:user:proton
X-Pm-Message-ID: 001551ab6b53126002869747915563fbad16ee69
MIME-Version: 1.0
Content-Type: multipart/signed; protocol="application/pgp-signature"; micalg="pgp-sha512"; boundary="------3052bc4f2384cfda47055e327c739240f1248989efe1e6aa0282b97e4492897a"; charset="utf-8"
Message-ID-Hash: ZF4H76BN5Z2A7TXI7WH63CMDQ7A22F3I
X-Message-ID-Hash: ZF4H76BN5Z2A7TXI7WH63CMDQ7A22F3I
X-MailFrom: lists+ietfgrow@bensley.me
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-grow.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [GROW] Re: A well-known DOWNGRADE BGP Community
List-Id: Grow Working Group Mailing List <grow.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/grow/2XtoQmm_JTrdzvns7na1PbbF4xg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/grow>
List-Help: <mailto:grow-request@ietf.org?subject=help>
List-Owner: <mailto:grow-owner@ietf.org>
List-Post: <mailto:grow@ietf.org>
List-Subscribe: <mailto:grow-join@ietf.org>
List-Unsubscribe: <mailto:grow-leave@ietf.org>
Hi Job, Saku, I like the draft, it solves a few problems with the existing RTBH based approach to tackling DDoS attacks: * It doesn’t complete the DDoS attack so some genuine traffic may still get through. * Visibility isn’t lost of the attack (is it still on going, how big is it, what kind of attack pattern is being used, etc.). * It could de-risk / remove the validation issues we have today with trying to validate host routes for RTBH because I could just downgrade a /24 or /48, so we can stick to our existing route filtering practices and not have to do anything weird to try and validate host routes. But I also see several problems that would need to be solved before I could implement this. Do either of you already have ideas on these (maybe you’ve thought of these already?): * If I downgrade a /24 rather than a host route, then other customers could be affected by the DDoS, so that might not be that helpful actually. Then I’m back to downgrading host routes, and the major problem with RTBH is the validation part, not dropping the traffic. And this draft doesn’t change anything about the validation of host routes. * With RTBH, we can auto detect the DDoS and inject an RTBH route. No need to wake up my on-call engineer. If I downgrade a prefix, I’m receiving all the attack traffic still, meaning I will have congested core links. But this would be fine because only the low priority attack traffic is being dropped due to the congestion, not genuine traffic. However, in order not to wake my on-call engineer due to “packet loss on core link” alerts, I need my NMS to alert when any of QoS queues 0,2-7 have packet loss (but not for packet loss in queue 1). This level of detail is not available from all devices via gNMI and not supported by all NMS. This could be tricky. * The barrier to entry for this is quite a bit higher than RTBH. RTBH requires a bit of BGP policy and off you go. Technically, you could say that DOWNGRADE also only requires a bit of BGP policy too, to set the QoS class, but actually, I’ll bet you a round of drinks many networks haven’t got QoS deployed and/or it doesn’t work very well on their devices (we’ve opened 3 separate bug cases with Arista trying to get basic QoS to work). So if you don’t already have QoS working on your network, I’d say the barrier to entry is quite a bit higher. * The main reason for using RTBH is when the attack bandwidth is simply too high (there is collateral damage to other customers because I’m out of capacity, so I need to drop traffic to this prefix to protect my other customers). Because DOWNGRADE doesn’t stop the traffic, the congestion is still present across multiple ASNs. I can de-prioritise the traffic in my network, but my direct peer who doesn’t support DOWNGRADE, their link to me still congests, which affects all customers relying on that link. With RTBH, I can send the RTBH route to my direct peer, they don’t support RTBH, they forward it on to their peer, who does support RTBH, and they drop the traffic, which saves the link capacity between me and my direct peer. With DOWNGRADE, my direct peer doesn’t support it, they forward the DOWNGRADE route to their peer, they de-prioritise the traffic, but the capacity of their physical link to my direct peer is bigger than the capacity of the physical link between me and my direct peer, so the amount of traffic received at the link with my direct peer still causes it to congest and my other customers are still suffering. I would need to fall back to RTBH. Maybe DOWNGRADE becomes an option before RTBH? One could try to use DOWNGRADE, if this doesn’t improve the situation enough we can RTBH. Any thoughts/feedback are appreciated. Cheers, James.
- [GROW] A well-known DOWNGRADE BGP Community Job Snijders
- [GROW] Re: A well-known DOWNGRADE BGP Community Bryton Herdes
- [GROW] Re: A well-known DOWNGRADE BGP Community Job Snijders
- [GROW] Re: A well-known DOWNGRADE BGP Community Saku Ytti [C]
- [GROW] Re: A well-known DOWNGRADE BGP Community Paolo Lucente
- [GROW] Re: A well-known DOWNGRADE BGP Community James Bensley