Subject: Re: question about ipf "fastroute"
To: der Mouse <mouse@Rodents.Montreal.QC.CA>
From: Michael Richardson <>
List: tech-net
Date: 02/14/2003 00:33:59

>>>>> "der" == der Mouse <mouse@Rodents.Montreal.QC.CA> writes:
    >> I want to do source address based routing for some particular IPs.

    der> I have a pseudo-interface driver that does exactly this:

    der> [Truly-Delicious - root] 75> netstat -rn -f inet | egrep srt0
    der> default UGS 3 468844 1500 srt0 UH 1 0
    der> 1500 srt0

  Thanks for the heads up. This sounds useful in other contexts.

  In this context we actually have three transit ISPs connected, plus
peering at an interchange. We have both provider independent addresses
and provider dependant addresses. We have a full routing table.

  We actually want to always route the provider dependant addresses back
to the provider. This is mostly due to emergency access and bandwidth issues
for certain services. We actually want even finer control... some things
should just respect the routing table and go out to the IX.
  There is some issue that we are tracking, somewhere between 50K and
118K routes, something weird happens, and the IPF stuff doesn't work
for one set of addresses, but does for another.
]       ON HUMILITY: to err is human. To moo, bovine.           |  firewalls  [
]   Michael Richardson, Sandelman Software Works, Ottawa, ON    |net architect[
] |device driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [
Version: GnuPG v1.0.7 (GNU/Linux)
Comment: Finger me for keys