• One of the biggest takeaways from the RIPE NCC course is that there is no single feature that makes BGP secure. Even though technologies like RPKI have significantly improved routing security, they don’t solve every problem. RPKI only validates the origin of a route. It doesn’t verify whether the advertised AS Path is correct, nor…

  • One thing I really liked about the RIPE NCC course is that it doesn’t present a single “magic solution.” Instead, it explains that BGP security is built from multiple layers. Every mechanism addresses a different type of problem, and together they significantly reduce the chances of routing incidents. Prefix Filtering The first and probably most…

  • BGP is one of those protocols that quietly keeps the Internet running. As network engineers, we usually spend most of our time configuring neighbors, advertising prefixes, or troubleshooting routing issues. Security, however, is often something we don’t think much about until something goes wrong. I recently completed the BGP Security course from the RIPE NCC…

  • When most people hear the term cybersecurity, they immediately think about firewalls, antivirus software, or intrusion prevention systems. While these technologies are important, security architecture is much broader than individual security products. As part of Cisco U’s “Designing Cisco Security Infrastructure (SDSI)” learning path, I recently completed the Security Architecture Design Fundamentals module. The course…

  • When enterprises start scaling DMVPN deployments, a single hub or a single transport quickly becomes a limitation. The Dual Hub + Dual cloud design provides: while still keeping the overlay scalable with DMVPN Phase 3. Topology Overview We have two independent DMVPN clouds: MPLS Cloud Internet Cloud Each spoke connects to both hubs: This creates:…