gtsm by default

This commit is contained in:
Randy Bush 2022-02-13 17:34:12 -08:00
parent 762c824df5
commit 2d3d6dc7c9

View file

@ -502,7 +502,8 @@ Flags (bit):
<t>By default, GTSM, <xref target="RFC5082"/>, SHOULD be enabled to <t>By default, GTSM, <xref target="RFC5082"/>, SHOULD be enabled to
test that a received HELLO MUST be on the local link. It MAY be test that a received HELLO MUST be on the local link. It MAY be
disabled by configuration.</t> disabled by configuration. GTSM check failures SHOULD be logged,
though with rate limiting to keep from overwhelming logs.</t>
<t>If more than one device responds, one adjacency is formed for <t>If more than one device responds, one adjacency is formed for
each unique source IP address. L3ND treats each adjacency as a each unique source IP address. L3ND treats each adjacency as a
@ -539,7 +540,9 @@ Flags (bit):
<t>By default, GTSM, <xref target="RFC5082"/>, SHOULD be enabled to <t>By default, GTSM, <xref target="RFC5082"/>, SHOULD be enabled to
ensure that a SYN received in response to a HELLO is on the local ensure that a SYN received in response to a HELLO is on the local
link. It MAY be disabled by configuration.</t> link. It MAY be disabled by configuration. GTSM check failures
SHOULD be logged, though with rate limiting to keep from
overwhelming logs.</t>
<t>If the receiver of a HELLO agrees with the sender's choice of <t>If the receiver of a HELLO agrees with the sender's choice of
TLS/TCP and authentication, both sides have agreed on an AFI for the TLS/TCP and authentication, both sides have agreed on an AFI for the