Ah ah ah, it's very complex to common mortals as
me :)
Perhaps it is mature the time to adopt, after many
years, the *SIMPLE* implementation created by Maiko
VE4KLM for JNOS2, applying it to our systems:
------------
3) Configuration
-------------
When adding a 44 route, typically one uses something
like this :
route add 44.0/8 encap a.b.c.d
But does that automatically add the two levels of firewalling that we are
discussing here? If not, it does not seem very relevant. It is quite easy
to make a configuration that basically works (especially when using RIP which
makes route statements like the above unnecessary), but the point is that it
is not secure against abuse by malicious people. That is why additional
work is needed.
Rob