nanog mailing list archives
Re: Todd Underwood was a little late
From: William Herrin <bill () herrin us>
Date: Fri, 18 Jun 2010 11:27:57 -0400
On Fri, Jun 18, 2010 at 9:21 AM, Steve Bertrand <steve () ipv6canada com> wrote:
On 2010.06.18 09:06, William Herrin wrote:On Fri, Jun 18, 2010 at 8:37 AM, Steve Bertrand <steve () ipv6canada com> wrote:I'm not sure what that accomplishes. It doesn't close any doors. With loose-mode RPF he can still forge packets from any address actually in use.What it does, is prevents packets with the illegal IP address from actually being delivered to the intended destination within your network preserving some (perhaps a very small amount) of bandwidth/router resources.
Right, but to save that fractional bit of bandwidth you pay for an extra TCAM or radix tree hit impacting every single packet entering your system on your very expensive upstream border routers -- a significant reduction in your hardware's capacity. I get strict RPF - if you can guarantee symmetric routing (which you often can in single-homed scenarios) it offers a meaningful improvement in your network's security without configuration management challenges at the cost of extra processing. But the cost/benefit to loose RPF doesn't seem to come close to adding up in any scenario that occurs to me. Regards, Bill Herrin -- William D. Herrin ................ herrin () dirtside com bill () herrin us 3005 Crane Dr. ...................... Web: <http://bill.herrin.us/> Falls Church, VA 22042-3004
Current thread:
- Re: Todd Underwood was a little late, (continued)
- Re: Todd Underwood was a little late Mark Andrews (Jun 16)
- Re: Todd Underwood was a little late Roy (Jun 16)
- Re: Todd Underwood was a little late Garrett Skjelstad (Jun 16)
- Re: Todd Underwood was a little late Brian Feeny (Jun 17)
- Re: Todd Underwood was a little late William Herrin (Jun 17)
- Re: Todd Underwood was a little late Steve Bertrand (Jun 18)
- Re: Todd Underwood was a little late Chris Adams (Jun 18)
- Re: Todd Underwood was a little late Steve Bertrand (Jun 18)
- Re: Todd Underwood was a little late William Herrin (Jun 18)
- Re: Todd Underwood was a little late Steve Bertrand (Jun 18)
- Re: Todd Underwood was a little late William Herrin (Jun 18)
- Re: Todd Underwood was a little late Owen DeLong (Jun 17)
- Re: Todd Underwood was a little late Frank Habicht (Jun 18)
- Re: Todd Underwood was a little late Christopher Morrow (Jun 17)
- Re: Todd Underwood was a little late Todd Underwood (Jun 17)
- RE: Todd Underwood was a little late Lee Howard (Jun 18)
- Re: Todd Underwood was a little late Michael Dillon (Jun 19)
- Re: Todd Underwood was a little late deleskie (Jun 19)
- Re: Todd Underwood was a little late bmanning (Jun 19)