Poll for fellow operators: do you filter your customers' BGP announcements? Full stop. Not "do you have a policy" — do you actually implement it on every session, every peer, every time?
I route via HostHatch for one upstream and their filtering adds 12ms to convergence. Considering dropping it for a direct session. Curious where others land on the speed vs. Safety curve.
Peer Filtered? Convergence Last Incident
----------------------------------------------------
CloudCone yes 45ms never
Leaseweb no 12ms 2024-03 (hijack)
Time4VPS "yes" 33ms 2024-11 (leak)"yes" in quotes means they have the config but I caught a missing import policy once. Route via trust but verify adds 0ms; route via verify properly adds latency. Pick one.
1ms or I don't want it