nanog mailing list archives

Re: Cisco says attacks are due to operational practices


From: "Majdi S. Abbas" <msa () samurai sfo dead-dog com>
Date: Thu, 10 Feb 2000 18:22:43 -0800 (PST)


Filtering incoming our outgoing ports for anybody's network but your own (not
your customer's) is wrong.  You know specifically what apps you are running.  
How can you know what your customer is running or what they want to do ?

If the customer is aware this is happening or even requests this type of
firewall service, that's great.  But to filter ports on backbone routers is
stupid.

        In the context of martian filtering, I'd assume he's referring to
daytime/echo/chargen/etc.  And filtering those is understandable.

        --msa



Current thread: