Abstract
Unknown unicast on shared peering LANs is widely assumed to be transient. This case study presents the opposite: a self-perpetuating mechanism via RFC 4861 §7.3.1 forward-progress confirmation, where a single MAC change can leave a stale neighbour entry REACHABLE indefinitely while customer traffic — HTTPS SNI, signalling, residential 999 calls — is flooded to hundreds of member ports. A reproducible demonstration was published in November 2024. The talk presents the mechanism at the kernel and protocol level, a five-year timeline of reports and partial remediations at one IXP, the categories of disclosure and safety-of-life exposure at stake, and operational lessons for IXP operators and members. It closes on the speaker's open self-examination: did I do enough on behalf of my customers?
Recording
Speaker
James Rice
Rate this talk
You must be logged-in to rate talks