Release of portable version OpenBGPD 8.2

The release of the portable edition of the OpenBGPD routing package 8.2 has been announced, developed by the OpenBSD project developers and adapted for use on FreeBSD and Linux (support for Alpine, Debian, Fedora, RHEL/CentOS, Ubuntu is claimed). To ensure portability, parts of the code from the OpenNTPD, OpenSSH, and LibreSSL projects have been used. The project supports most of the BGP 4 specifications and meets the requirements of RFC8212 but does not attempt to cover all aspects, primarily providing support for the most demanded and widespread functions.

The development of OpenBGPD is supported by the regional internet registrar RIPE NCC, which is interested in enhancing the functionality of OpenBGPD for use in servers traffic routing at Internet Exchange Points (IXP) and in creating a full-fledged alternative to the BIRD package (among the open alternatives implementing the BGP protocol, projects such as FRRouting, GoBGP, ExaBGP, and Bio-Routing can be noted).

The project focuses on ensuring the highest level of security and reliability. It employs strict checks on the correctness of all parameters, tools to enforce buffer boundaries, privilege separation, and access restriction to system calls. Advantages also include an easy-to-use configuration definition language syntax, high performance, and efficiency in memory usage (for example, OpenBGPD can work with routing tables containing hundreds of thousands of entries).

Key changes in the new version:

  • The implementation of the ASPA (Autonomous System Provider Authorization) mechanism, used in BGP to verify AS_PATH paths, authorize provider autonomous systems, and protect against the leakage of incorrect routes, has been updated. The ASPA implementation has been brought in line with the specifications draft-ietf-sidrops-aspa-verification-16 and draft-ietf-sidrops-aspa-profile-16 and has been transitioned to the use of search tables that are independent of AFI (Address Family Indicator).
  • A bug in the netlink message parser related to the incorrect size definition of messages, which leads to crashes on the Linux platform, has been fixed.
  • The code for generating UPDATE messages has been transitioned to use the new ibuf API.
  • Error messages output in bgpctl when attempting to use features not supported in the portable version of OpenBGPD have been improved.
  • An example of GRACEFUL_SHUTDOWN filtering rules has been redesigned to handle only ebgp sessions.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster