nanog mailing list archives

Re: Internet SYN Flooding, spoofing attacks


From: Vijay Gill <wrath () cs umbc edu>
Date: Fri, 11 Feb 2000 22:44:59 -0500 (EST)


On Fri, 11 Feb 2000, Paul Ferguson wrote:

Unicast RPF where appropriate and filters where appropriate, life would
become better.  -- exhibit [a]

C might have some problems doing Unicast RPF, but it certainly
wouldn't have problems doing RFC2267-style filtering on it's
access link to D; likewise ther might be many "mini" connections
from C to other smaller downstream customers. THAT is where this
filtering needs to occur.

I suspect we are in violent agreement here. See exhibit [a]


/vijay





Current thread: