nanog mailing list archives

Re: Router modifications to deal with smurf


From: Karl Denninger <karl () mcs net>
Date: Sun, 26 Apr 1998 19:26:53 -0500

Lucent/Livingston has pointedly ignored just this RFE request for over a year.

--
-- 
Karl Denninger (karl () MCS Net)| MCSNet - Serving Chicagoland and Wisconsin
http://www.mcs.net/          | T1's from $600 monthly / All Lines K56Flex/DOV
                             | NEW! Corporate ISDN Prices dropped by up to 50%!
Voice: [+1 312 803-MCS1 x219]| EXCLUSIVE NEW FEATURE ON ALL PERSONAL ACCOUNTS
Fax:   [+1 312 803-4929]     | *SPAMBLOCK* Technology now included at no cost

On Sat, Apr 25, 1998 at 05:29:02PM -0400, Rusty Zickefoose wrote:
-----BEGIN PGP SIGNED MESSAGE-----

Fun with my mailor, let me try this again.

        So, if someone, or possibly a group of someones, were to make the
following request to the various router vendors, would they be met with
approval by most of the readers? 

        We requests that your routers be configurable, at the interface
level, to prevent the forwarding of an ICMP echo-request packet through an
interface that has a broadcast or wire address that matches the
destination address of that packet.  We also request that the default
configurations of your routers be modified to prevent said forwarding.

        We request that your routers be configurable, both globally and
and the interface level, with the interface configuration overiding the
global configuration, to prevent the forwarding of an IP packet with a
source network address different from the network address of the interface
on which it was received.  We also request that the default configurations
of your routers be modified to prevent, globally, said forwarding. 


- -- 
Rusty Zickefoose  |  The most exciting phrase to hear in science,
rusty () mci net     |  the one that heralds new discoveries, is not
                  |  "Eureka!", but "That's funny ..."
                  |  -- Isaac Asimov

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAwUBNUJVpe4+ch/bGDylAQH3uAP/ZHRdlufm9gbTUalVC9ax0H/nK7W/4S9r
QLuSEfh9N8nHTbd4wSllB2GorzM46A0XFZCKAmUWzc5wFKL5lfjGbbu6Tfd8UUOF
lxTQJYdda2ikmbLLBr8p+cUnb6BQLsA81Tst2twDc2BCf8GQsjxZvrCwh8sLCACe
q47YHAChVLk=
=htio
-----END PGP SIGNATURE-----



Current thread: